<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-26869207</id><updated>2011-04-21T22:38:25.119+02:00</updated><title type='text'>Cut the crap</title><subtitle type='html'>All your malware are belong to us</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>15</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-26869207.post-116018351542289118</id><published>2006-10-07T02:56:00.000+02:00</published><updated>2006-10-07T03:14:13.953+02:00</updated><title type='text'>Adware vendor gets MVP</title><content type='html'>&lt;img src="http://img208.imageshack.us/img208/4227/headupassac1.jpg" height="135" width="120" align="right" alt=""&gt; Yeah, you heard me right. Patchou AKA Cyril Paciullo, the creator of Messenger Plus, a notorious program containing adware (&lt;a href="http://en.wikipedia.org/wiki/C2.LOP"&gt;LOP&lt;/a&gt;) has been rewarded with a Most Valued Professional award. Now, I've never been very kind to Microsoft's policies, but this one really takes the cake. It this Ballmer's "&lt;a href="http://www.youtube.com/watch?v=fj3FOHc-fgA"&gt;advertisers advertisers advertisers&lt;/a&gt;" upcoming nightmare? What in the hell are they thinking?&lt;br /&gt;&lt;br /&gt;Anyway, more &lt;a href="http://temerc.blogspot.com/2006/10/adware-vendor-now-ms-mvp.html"&gt;here&lt;/a&gt;, &lt;a href="http://sunbeltblog.blogspot.com/2006/10/is-this-freshly-minted-microsoft-mvp.html"&gt;here&lt;/a&gt;,  &lt;a href="http://www.vitalsecurity.org/2006/10/microsoft-give-mvp-award-to-adware.html"&gt;here&lt;/a&gt;, &lt;a href="http://certifiedbug.com/blog/?p=140"&gt;here&lt;/a&gt; and a bunch of other links you'll find there.&lt;br /&gt;&lt;br /&gt;As you can see, they are all really happy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-116018351542289118?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/116018351542289118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=116018351542289118' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/116018351542289118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/116018351542289118'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/10/adware-vendor-gets-mvp.html' title='Adware vendor gets MVP'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-115706101901425913</id><published>2006-08-31T21:50:00.000+02:00</published><updated>2006-09-01T03:33:58.956+02:00</updated><title type='text'>Stats, dialers, and hilariously bad products</title><content type='html'>People complaining about dialer requests, puzzled surfers, strange requests of installation of suspicious software on otherwise clean sites; welcome to Netvision's latest scam: "free" stats with hidden dialer installation.&lt;br /&gt;&lt;br /&gt;It all starts with people looking for "free" stats for their website; since many do not have the possibility to install a server-side visitor statistics for their web page, they look for free alternatives. Never mind that these are always hideously inaccurate, unreliable, and often come with ugly logos to boot: people want statistics. Some services, such as Shinystat, have been around for many years; although this service represent a minor annoyance with its tracking cookies, it's nothing compared to the crap that comes with freestat.ws, mystat.ws, puntostat.com, and all the other creations of Netvision/Carima, one of the worst trojan/dialer pushers in the world.&lt;br /&gt;&lt;br /&gt;"Freestat.ws" claims to offer free statistics with no limitations: all you need to do is publish the code that they give you on your web page. But let's take a look at an example this so-called code:&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;&amp;lt;script type="text/javascript" language="JavaScript" src="http://www.freestat.ws/logo.asp?utente=17166"&amp;gt;&amp;lt;/script&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This is a simple JavaScript that we can download and analyze:&lt;br /&gt;&lt;br /&gt;&lt;kbd&gt;$ wget --user-agent="Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" http://www.freestat.ws/logo.asp?utente=17166&lt;/kbd&gt;&lt;br /&gt;&lt;br /&gt;The first thing we notice is an iframe with zero height and width. Now, anybody who has ever seen malware installations knows how much these scammers love small iframes. This one from the page also points to a site with a moronic name, also a bad sign:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img507.imageshack.us/img507/5871/immaginezj2.gif" height="146" width="594" alt=""&gt;&lt;br /&gt;&lt;br /&gt;So let's see what that is:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img477.imageshack.us/img477/166/immagine2lk5.gif" height="355" width="594" alt=""&gt;&lt;br /&gt;&lt;br /&gt;The JavaScript function location.search returns the parameters in the querystring, in this case st=1&amp;amp;p=2, so we can replace location.search with "st=1&amp;amp;p=2", remove the first "if", turn the document.write into an alert and see what the page calls. Which turns to be:&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;http://http-ssl256-number-secure-systemiiieifuf666777lliiiiiliiili-com.net/winsc1/script-2.asp?st=1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;And there already we spot the first dialer:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img347.imageshack.us/img347/7978/immagine3hs6.gif" width="600" height="71" alt=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img401.imageshack.us/img401/4027/immagine4xk9.gif" width="427" height="252" alt=""&gt;&lt;br /&gt;&lt;br /&gt;We can also note that in the same page, the page checks the response timings of the JavaScript, avoiding loading the dialer if the user has adsl or faster connection. Also, it just won't give up: if you say "no" to the installation, it will prompt you again to install their so-called "100% virus free" (yeah, right) crap. And again. And again.&lt;br /&gt;&lt;br /&gt;But let's go back for a while. Now, the first page also contained a commented-out link to another page on another domain:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img341.imageshack.us/img341/8614/immagine5ll9.gif" width="594" height="60" alt=""&gt;&lt;br /&gt;&lt;br /&gt;Which turns to be this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img312.imageshack.us/img312/3803/immagine6vz1.gif" height="513" width="651" alt=""&gt;&lt;br /&gt;&lt;br /&gt;"Protected with Web Encrypt 2.4"? Uhhhh... color me scared.&lt;br /&gt;&lt;br /&gt;Please. This kind of protection is trivial to break. The grammatically-challenged &lt;a href="http://www.design.co.yu/webencrypt/"&gt;homepage&lt;/a&gt; for Web Encrypt says "ultimate HTML &amp; Javascript code protection". Give me a break. Not only this thing breaks &lt;a href="http://www.w3.org/WAI/"&gt;accessibility&lt;/a&gt;, slows down web pages, and gives a totally false sense of security, it's also the favorite tool by scammers in their stupid attempts at hiding malware installations.&lt;br /&gt;&lt;br /&gt;By the way, just how hard is it to break this so-called "encryption"? It took me about 6 minutes, and I'm actually ashamed it took me so long:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img395.imageshack.us/img395/8665/immagine7ry0.gif" height="297" width="585" alt=""&gt;&lt;br /&gt;&lt;br /&gt;The linked page, &lt;br /&gt;&lt;span style="color:#FF3333"&gt;http://software-free.org/winupg/script.asp?id=2&amp;wm=17166&lt;/span&gt; calls another trojan/dialer installation, this time on &lt;br /&gt;&lt;span style="color:#FF3333"&gt;http://deposito.hostance.net/dialer/605684.exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Like the one before, this page also checks the loading time (this time that of an image, on &lt;br /&gt;&lt;span style="color:#FF3333"&gt;http://138.188.193.166/adsl.jpg&lt;/span&gt;) and prompts the installation of the trojan only for modem-like timings.&lt;br /&gt;&lt;br /&gt;In the end, never &lt;span style="font-weight:bold;"&gt;ever&lt;/span&gt; put up a "free" web statistics on your web page if you are not sure what they provide. Also, block these domains as soon as possible, as they are all related to the ugly Netvision/Carima dialer crap:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;software-free.org&lt;/span&gt; (dialer loader pages)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;trafficredlight.net&lt;/span&gt; (trojan repository)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;hostance.net&lt;/span&gt; (trojan repository)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;138.188.193.166&lt;/span&gt; (trojan "loader checks")&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;freestat.ws&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;specialstat.com&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;statistiche.ws&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;webmobile.ws&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;superstat.info&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;megastat.net&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;puntostat.com&lt;/span&gt; (dialer scam stats)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;http-ssl256-number-secure-systemiiieifuf666777lliiiiiliiili-com.net&lt;/span&gt; (dialer loader pages)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;67.15.56.230&lt;/span&gt; (counter/trojan dialer starter)&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#FF3333"&gt;free-default-update-win-mac-free-antivirus-nospam-download.net&lt;/span&gt; (Netvision-related crap)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-115706101901425913?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/115706101901425913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=115706101901425913' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115706101901425913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115706101901425913'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/08/stats-dialers-and-hilariously-bad.html' title='Stats, dialers, and hilariously bad products'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-115658943055908138</id><published>2006-08-26T12:28:00.000+02:00</published><updated>2006-08-26T13:35:50.980+02:00</updated><title type='text'>Gromozon: all you need to know</title><content type='html'>&lt;img src="http://img174.imageshack.us/img174/3743/immaginetg2.jpg" height="160" width="200" align="right" alt="" style="padding-right:6px" /&gt;After some sleepless nights, and after quite &lt;a href="http://www.wilderssecurity.com/showthread.php?t=136452"&gt;a few warnings&lt;/a&gt; on my part about the nastiness, it seems something is definitely moving.&lt;br /&gt;&lt;br /&gt;The merit goes to Marco Giuliani of PrevX, who collected collected a few of the discoverings by me and other researches, but most importantly all his own discoverings (which are very detailed, and include great behavior analysis of the threat on an infected system).&lt;br /&gt;&lt;br /&gt;Head on to Marco's pdf &lt;a href="http://www.pcalsicuro.com/gromozon.pdf" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Use &lt;a href="http://rapidshare.de/files/30707949/gromozon.pdf.html"&gt;this link&lt;/a&gt; if you have problems with the one above.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-115658943055908138?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/115658943055908138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=115658943055908138' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115658943055908138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115658943055908138'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/08/gromozon-all-you-need-to-know.html' title='Gromozon: all you need to know'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-115136272487347039</id><published>2006-06-27T00:44:00.000+02:00</published><updated>2006-08-13T20:24:53.640+02:00</updated><title type='text'>My blocklist</title><content type='html'>In September 2005, I posted this message on the &lt;a href="http://www.wilderssecurity.com/showthread.php?t=122665"&gt;Wilders Security Forums&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;Ok, since some of you use block lists, this is a block list I compiled in some time (I use this on web sites at work, where content managers can insert links: these are banned, so these are all forbidden to link anywhere on sites); please note that the list does not really include subdomains: an entry for "[site name].biz" automatically means than any subdomain entry should be automatically banned, so for instance "[example].[site name].biz" is not included in the list but should actually be blocked (this is implemented code-wise on sites, feel free to implement this your own way).&lt;br /&gt;&lt;br /&gt;The list includes entries from various existing block lists, plus:&lt;br /&gt;&lt;br /&gt;- link spam and blog spam sites (sites that were found in guestbooks and forums around the web and which were CLEARLY only used to increase search engine rankings)&lt;br /&gt;&lt;br /&gt;- malware-hosting sites (excuding sites that host malware while CLEARLY specifying it is malware)&lt;br /&gt;&lt;br /&gt;- sites using exploits&lt;br /&gt;&lt;br /&gt;- sites related to known spammers&lt;br /&gt;&lt;br /&gt;- some "tracking-cookie" sites (not many)&lt;br /&gt;&lt;br /&gt;There are no IPs in the list (I personally forbid to link to IPs without a hostname).&lt;br /&gt;&lt;br /&gt;There are more than a few that I personally didn't find on other block lists. I personally checked all of those and they are ALL questionable sites for the reasons specified above.&lt;br /&gt;&lt;br /&gt;The list is a simple .txt file with a domain on each line.&lt;br /&gt;&lt;br /&gt;Maybe some of you will find it useful. If not, then well, too bad.&lt;/blockquote&gt;&lt;br /&gt;Now since this list has become quite a big one and one that took me a long time to create and maintain, I am going to put a permanent link to it (it's on rapidshare). You can find the link on the links section of the blog (under "Malware block list") along with the sha-1 hash of the .txt file. By the way, the latest one can be found here http://rapidshare.de/files/24217548/banned.zip.html (NB: old link. See below).&lt;br /&gt;&lt;br /&gt;SHA1(banned.txt)= 14e12e151311cf96916e76e085a7f4b256d609bf&lt;br /&gt;&lt;br /&gt;Everyone is welcome to test this (such as adding these domains to his own IE "restricted" zone) and give his own impression, and &lt;i&gt;especially&lt;/i&gt; everyone is welcome contributing to this list (frankly, I found both IE-SpyAd and Spywareblaster's restricted domains lists to be somewhat limited, that's why I started this thing).&lt;br /&gt;&lt;br /&gt;By the way, recently I started adding IPs as well. So you will find some, but really only a few.&lt;br /&gt;&lt;br /&gt;Edit August 13, 2006: updated blocklist at &lt;a href="http://rapidshare.de/files/29269253/banned.zip.html"&gt;http://rapidshare.de/files/29269253/banned.zip.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-115136272487347039?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/115136272487347039/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=115136272487347039' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115136272487347039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115136272487347039'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/06/my-blocklist.html' title='My blocklist'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-115049110927145164</id><published>2006-06-16T22:10:00.000+02:00</published><updated>2006-08-13T20:02:20.646+02:00</updated><title type='text'>Is the AV industry failing?</title><content type='html'>Well, it's been a while since my last posting on this blog. In the meanwhile, it seems that the sleazebags described &lt;a href="http://cut-thecrap.blogspot.com/2006/05/what-to-donet.html"&gt;here&lt;/a&gt; have been quite busy. First of all, they have been putting their trash all over the place in Google by spamming blog comments, putting fake referers, etc. Second, their latest infection method involves a little bit of social engineering technique as well. And third, they have been making sure that antivirus applications miss their newest trojans, or at least some of them (and by the way, most antivirus engines are slipping lately, I've seen even the best of them -- KAV and NOD32, of course -- missing dozens of threats... I'll send you the samples, but get you acts together, please).&lt;br /&gt;&lt;br /&gt;Anyway, here's what I found on a new page of theirs while searching for malware in Google (by the way, the sentence "clicca su si", Italian for "click on yes", yelds dozens of malware sites... these people are so damn predictable...)&lt;br /&gt;&lt;br /&gt;The page (horus.dnshighspeed.com/~liberaco/2/temisvoltiolocausto.html... do NOT open if you don't know what you're doing) shows graphics like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img126.imageshack.us/img126/108/immagine9wu.gif" height="411" width="514" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;Soon to be followed by a WMF exploit (pic.tiff) and a funny-named executable (www.google.com... clever, huh?). The www.google.com executable has, of course, nothing to do with the domain, but it's a COM command.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img71.imageshack.us/img71/3732/immagine20nx.gif" height="418" width="488" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;When launched, the www.google.com executable tries to contact first 195.225.177.22 on port 80, then 195.225.177.145 on port 80 and will stay active unless you terminate it. Both those IPs correspond to servers in the Ukraine. See a pattern here? Oh, yes... &lt;a href="http://www.bleedingsnort.com/forum/viewtopic.php?forum=11&amp;showtopic=1460"&gt;you guessed right&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;And so, what do have antivirus applications have to say about that &amp;quot;nice&amp;quot; piece of executable code? This:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img364.imageshack.us/img364/1726/immagine32ul.gif" height="548" width="696" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;You're not doing very good, guys. So being me overly curious, I'm trying to see what these scammers are up to this time, again. So I let my system try to see what kind of good stuff they have for people who try to execute this &amp;quot;www.google.com&amp;quot;.&lt;br /&gt;&lt;br /&gt;Well, file downloaded from 195.225.177.22 is a random-named executable called &amp;quot;3e2a8d.exe&amp;quot;. Will this one be detected? Nope.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img365.imageshack.us/img365/7254/immagine45sb.gif" height="552" width="702" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;This is awful, just awful. Well, let's see what this &amp;quot;3e2a8d.exe&amp;quot; does. It extracts launches a &amp;quot;ptwx1.exe&amp;quot;:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img140.imageshack.us/img140/2765/immagine52an.gif" height="557" width="708" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;A little better. Of course, by this point, you'll likely have already your system infected and rootkited (some system errors that happened in the sandbox I used really seem to indicate that attempt).&lt;br /&gt;&lt;br /&gt;EDIT at 4.02: forwarded to a bunch of security sites and sent samples to a bunch of AV companies. KAV detects the first two trojans, now (after I sent them the samples).&lt;br /&gt;&lt;br /&gt;EDIT June 20, 3.09 PM: the main downloader is finally starting getting detected:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img212.imageshack.us/img212/9182/immagine1ng.gif" height="782" width="699" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;PS: also detected by BOClean (I contacted them).&lt;br /&gt;&lt;br /&gt;EDIT June 23, 0.28 PM: another one has appeared, and this one is YET AGAIN undetected by all the antivirus engines:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img145.imageshack.us/img145/1448/immagine9bw.gif" height="552" width="692" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;The original page was (DO NOT OPEN!) http://www2521.webattrezzi.com/hurghada/; many more domains linking to this malware have actually been created, I found them in link spammed pages. I'm going to post a list here soon.&lt;br /&gt;&lt;br /&gt;EDIT June 23, 0.51 PM: here's a (certainly partial) list of the domains to block. Please note that these are DOMAINS that should include all subdomains under them, you can't put them in your HOSTS file (and frankly, from what I've seen the subdomains are probably so many that you most probably won't be able to):&lt;br /&gt;&lt;br /&gt;accettazione.com&lt;br /&gt;adluvio.net&lt;br /&gt;allineare.com&lt;br /&gt;ambrato.com&lt;br /&gt;annuncitutti.com&lt;br /&gt;attesa.net&lt;br /&gt;attrezziutili.com&lt;br /&gt;azionamento.com&lt;br /&gt;bruciarsi.com&lt;br /&gt;buoncodice.com&lt;br /&gt;casadiarte.com&lt;br /&gt;codicecarta.com&lt;br /&gt;dannidicervello.com&lt;br /&gt;datiimportanti.com&lt;br /&gt;delsud.net&lt;br /&gt;devevedere.com&lt;br /&gt;eamicizia.com&lt;br /&gt;festaattuale.com&lt;br /&gt;gbeb.cc&lt;br /&gt;gromozon.com&lt;br /&gt;guerredellastella.com&lt;br /&gt;horus.dnshighspeed.com&lt;br /&gt;imparilo.com&lt;br /&gt;importanti.net&lt;br /&gt;lavostraricerca.com&lt;br /&gt;maniinsu.com&lt;br /&gt;nubibianche.com&lt;br /&gt;nuovoordine.com&lt;br /&gt;nuovosenso.com&lt;br /&gt;potetefarli.com&lt;br /&gt;sanguinante.com&lt;br /&gt;sededolce.com&lt;br /&gt;segualo.com&lt;br /&gt;soddisfare.com&lt;br /&gt;speziazona.com&lt;br /&gt;stampabile.net&lt;br /&gt;superaquota.com&lt;br /&gt;unanuovavolta.com&lt;br /&gt;unoprincipali.com&lt;br /&gt;uomodelferro.com&lt;br /&gt;webattrezzi.com&lt;br /&gt;&lt;br /&gt;It's quite obvious that these are targeting Italy. It's also obvious that the authors of these exploit/trojans can NOT speak Italian (some words don't make any sense and they clearly come from an automated traslator).&lt;br /&gt;&lt;br /&gt;EDIT June 23, 22.02: added gbeb.cc and gromozon.com to the "domains to block" list above, as I'm not sure it was clear (the previous article underlined that THOSE are respectively the javascript loader and the trojan repository, but it was written in Italian).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-115049110927145164?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/115049110927145164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=115049110927145164' title='19 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115049110927145164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/115049110927145164'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/06/is-av-industry-failing.html' title='Is the AV industry failing?'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>19</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114895244166555720</id><published>2006-05-30T01:49:00.000+02:00</published><updated>2006-05-30T03:40:03.703+02:00</updated><title type='text'>"what-to-do.net"</title><content type='html'>Il 29 Maggio 2006 su it.comp.sicurezza.virus è stato segnalato un sito contenente una grande (ma purtroppo, neanche troppo &amp;quot;insolita&amp;quot;) quantità di malware.&lt;br /&gt;&lt;br /&gt;Ne segue un'analisi.&lt;br /&gt;&lt;br /&gt;Il sito segnalato, http://virgilio.what-to-do.net/primisintomogravidanza/ (NON visitatelo se avete dei dubbi sull'efficacia delle vostre protezioni), contiene vari exploit e trojan, nonché una metodologia d'infezione che ricorda molto da vicino quella di iframecash/smitfraud.&lt;br /&gt;&lt;br /&gt;La pagina su virgilio.what-to-do.net non contiene malware, ma questo è richiamato da un sito esterno tramite un javascript nel body:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img168.imageshack.us/img168/6422/immagine23ro7fi.gif" height="387" width="405" alt=""&gt;&lt;br /&gt;&lt;br /&gt;Ormai pratica comune di questi script è quella di offuscarne i contenuti. Come da me precedentemente detto in questo blog, la &amp;quot;decodifica&amp;quot; risulta quasi sempre banale.&lt;br /&gt;&lt;br /&gt;Il contenuto della pagina richiamata dal javascript è questo:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img222.imageshack.us/img222/3083/immagine36xx.gif" height="400" width="600" alt=""&gt;&lt;br /&gt;&lt;br /&gt;Per avere un'idea del contenuto effettivo (e cioè non &amp;quot;offuscato&amp;quot;) dello script, è bastato aggiungere un paio di tag html e sostituire l'istruzione &amp;quot;eval&amp;quot; nello script con un alert:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img128.imageshack.us/img128/3667/immagine43fc.gif" height="400" width="600" alt=""&gt;&lt;br /&gt;&lt;br /&gt;Il risultato è stato questo:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img112.imageshack.us/img112/948/immagine1jn.gif" height="302" width="569" alt=""&gt;&lt;br /&gt;&lt;br /&gt;A questo punto è stato possibile analizzare gli effettivi contenuti del malware. NB: Kaspersky 6 mi ha avvertito subito di due contenuti maligni (un exploit WMF ed un Trojan-Dropper.Win32.Small.aol) quando ho visitato la pagina sopra detta per la prima volta, ma dato ho già visto questo genere di pagine piene di exploit e mi rendo conto che gli antivirus per varie ragioni (prima fra tutte che non tutto ciò che è contenuto viene effettivamente caricato) segnalano solo una parte di ciò che è effettivamente contenuto.&lt;br /&gt;&lt;br /&gt;Ho proceduto a visitare il secondo link, un IFRAME: i malware segnalati dal Kaspersky erano su quel dominio, ed il primo è un noto &amp;quot;contatore&amp;quot; di accessi.&lt;br /&gt;&lt;br /&gt;Il suddetto IFRAME contiene altri 3 IFRAME, più un applet.&lt;br /&gt;&lt;br /&gt;Il primo è gromozon.com/b88db6cc/50300/2/pic.php; questo contiene un refresh sull'exploit WMF localizzato su gromozon.com/b88db6cc/50300/2/pic.tiff (l'immagine non è una tif o tiff, è una WMF, è Internet Explorer la riconoscerà come WMF indipendentemente dall'estensione, per cui in una versione non patchata l'exploit avrà successo comunque):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img144.imageshack.us/img144/2606/immagine57zp.gif" height="483" width="709" alt=""&gt;&lt;br /&gt;&lt;br /&gt;L'applet immediatamente seguente si trova su gromozon.com/b88db6cc/50300/8/stat.jar. Anche questo è un noto malware/exploit:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img188.imageshack.us/img188/3575/immagine69uq.gif" height="483" width="709" alt=""&gt;&lt;br /&gt;&lt;br /&gt;Il secondo iframe, su gromozon.com/b88db6cc/50300/5/ccr.htm, è anch'esso codificato. Usando una tecnica simile alla precedente (leggermente diversa, ma non starò qui a descriverla), ne salta fuori che contiene un probabilissimo createControlRange exploit:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img329.imageshack.us/img329/2039/immagine73mq.gif" height="400" width="600" alt=""&gt;&lt;br /&gt;&lt;br /&gt;Stranamente, l'upload su Virustotal ha dato il file .js come completamente pulito. &amp;Egrave; possibile che questo sia dovuto ad una mancata (e abbastanza comune) rilevazione dei javascript come file maligni, oppure questo è effettivamente un nuovo exploit (un exploit createControlRange è già stato segnalato più di un anno fa, vedi &lt;a href="http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0183.html"&gt;http://archives.neohapsis.com/archives/fulldisclosure/2005-02/0183.html&lt;/a&gt;). L'ho inviato a Kaspersky, staremo a vedere.&lt;br /&gt;&lt;br /&gt;Il terzo IFRAME fa un refresh su gromozon.com/be7cc983/50300/1/Microsoft.exe; su VirusTotal: &lt;br /&gt;&lt;br /&gt;&lt;img src="http://img149.imageshack.us/img149/2340/immagine88qd.gif" border="0" width="709" alt=""&gt;&lt;br /&gt;&lt;br /&gt;L'ipotesi più probabile è che il precedente createControlRange exploit (esecuzione di codice da remoto) si occupi di lanciare l'eseguibile qui sopra senza interazione dell'utente.&lt;br /&gt;&lt;br /&gt;Una delle cose più interessanti del sito è che i link cambiano in continuazione: tutti i link sopra descritti nel giro di mezz'ora non esistevano più. Una nuova visita al sito ha poi rivelato che i vari "b88db6cc" presenti nell'URL erano stati sostituiti con nuove stringhe pseudo/random. Probabilmente si tratta di un cron job automatico sul server che regolarmente cambia i link e il javascript che li carica.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114895244166555720?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114895244166555720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114895244166555720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114895244166555720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114895244166555720'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/05/what-to-donet.html' title='&quot;what-to-do.net&quot;'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114761091828112912</id><published>2006-05-14T14:45:00.000+02:00</published><updated>2006-05-14T14:48:38.286+02:00</updated><title type='text'>Again on the botnet I found</title><content type='html'>&lt;a href="http://isc.sans.org/diary.php?storyid=1334"&gt;SANS published&lt;/a&gt; the story about the botnet I found last night (they are between the first I contacted). I see they contacted Google about blocking all payments of the clicks. That's good.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114761091828112912?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114761091828112912/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114761091828112912' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114761091828112912'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114761091828112912'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/05/again-on-botnet-i-found.html' title='Again on the botnet I found'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114757131202692755</id><published>2006-05-14T03:31:00.000+02:00</published><updated>2006-05-14T03:58:45.353+02:00</updated><title type='text'>CWS... wide open?</title><content type='html'>It was bound to happen, I guess. While doing the usual research for in-the-wild malware samples to send to antivirus/antitrojan vendors (ok, shut up, some hobbies are even dumber than this) I stumbled upon the classic site that the stupid admin left &amp;quot;wide open&amp;quot;. The difference is, this was actually a Coolwebsearch hijacker remote admin site. Take at look at this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img159.imageshack.us/img159/3017/immagine7tq.gif" height="768" width="426" alt="" /&gt;&lt;br /&gt;&lt;br /&gt;This happens to ba remote console for the &amp;quot;hijacked&amp;quot; PCs, with IP, clicks, remote shutdown, etc. The page goes WAY down, in a few minutes I've seen this remote console reporting of 600-something hijacked PC online at the same time. Hum. Oh, yeah, the guys are so nice leaving everything wide open for us all to see. Thanks for your stupidity guys, now I've got:&lt;br /&gt;&lt;br /&gt;- the hijacker malware sample that's gonna be sent to ALL the Antivirus companies in the World (apart from your own &amp;quot;rogue&amp;quot; trash, of course)&lt;br /&gt;&lt;br /&gt;- a list of your sites that I didn't know of and that are gonna be added to my blocklist&lt;br /&gt;&lt;br /&gt;I forwarded this to people who might be interested, too.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114757131202692755?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114757131202692755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114757131202692755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114757131202692755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114757131202692755'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/05/cws-wide-open.html' title='CWS... wide open?'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114618427290661874</id><published>2006-04-28T02:22:00.000+02:00</published><updated>2006-04-28T03:35:49.103+02:00</updated><title type='text'>The 'hostance.net' dialers have a new home</title><content type='html'>Well, this &lt;span style="font-style:italic;"&gt;major&lt;/span&gt; repository (also known as TrafficAdvance and Carima Ltd), responsible of creating and hosting tens of thousands of repacked trojan/dialers, has a new home: traffic-advance.net (with dialers being typically pushed from deposito.traffic-advance.net).&lt;br /&gt;&lt;br /&gt;Here's the whois:&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;Domain Name: traffic-advance.net&lt;br /&gt;&lt;br /&gt;   Created on..............: 03 Apr 2006 12:55:10&lt;br /&gt;   Expires on..............: 03 Apr 2008 12:55:10&lt;br /&gt;&lt;br /&gt;Administrative Info:&lt;br /&gt;   CARIMA ENTERPRISES LIMITED&lt;br /&gt;   CARIMA ENTERPRISES&lt;br /&gt;   45 Welbeck Street&lt;br /&gt;   London, UK W1G 8DZ&lt;br /&gt;   GB&lt;br /&gt;   Phone: +1.2402555993&lt;br /&gt;   Fax..: +1.2402555993&lt;br /&gt;   Email: ******************@lycos.co.uk&lt;br /&gt;&lt;br /&gt;Technical Info:&lt;br /&gt;   CARIMA ENTERPRISES LIMITED&lt;br /&gt;   CARIMA ENTERPRISES&lt;br /&gt;   45 Welbeck Street&lt;br /&gt;   London, UK W1G 8DZ&lt;br /&gt;   GB&lt;br /&gt;   Phone: +1.2402555993&lt;br /&gt;   Fax..: +1.2402555993&lt;br /&gt;   Email: ******************@lycos.co.uk&lt;br /&gt;&lt;br /&gt;Registrant Info:&lt;br /&gt;   CARIMA ENTERPRISES LIMITED&lt;br /&gt;   CARIMA ENTERPRISES&lt;br /&gt;   45 Welbeck Street&lt;br /&gt;   London, UK W1G 8DZ&lt;br /&gt;   GB&lt;br /&gt;   Phone: +1.2402555993&lt;br /&gt;   Fax..: +1.2402555993&lt;br /&gt;   Email: ******************@lycos.co.uk&lt;br /&gt;&lt;br /&gt;Status: Locked&lt;/pre&gt;&lt;br /&gt;Put &amp;quot;traffic-advance.net&amp;quot; in your block lists as soon as possible. There are &lt;a href="http://groups.google.it/group/it.comp.sicurezza.virus/browse_thread/thread/6d9510df6b241d1d/62671d29b6b62f7b" target="_blank"&gt;reports of hijacks already&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;EDIT: please note that &amp;quot;hostance.net&amp;quot; is still up as well, and still hosting trojans. So don't remove that one.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114618427290661874?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114618427290661874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114618427290661874' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114618427290661874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114618427290661874'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/hostancenet-dialers-have-new-home.html' title='The &apos;hostance.net&apos; dialers have a new home'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114617633102772304</id><published>2006-04-28T00:14:00.000+02:00</published><updated>2006-04-28T00:19:21.096+02:00</updated><title type='text'>And another IE remote hole...</title><content type='html'>Well, remember that day when &lt;a href="http://cut-thecrap.blogspot.com/2006/04/yet-another-ie-remote-security-hole.html"&gt;the last IE remote hole&lt;/a&gt; was posted? Here's another one:&lt;br /&gt;&lt;br /&gt;&amp;quot;&lt;i&gt;A vulnerability has been identified in Microsoft Internet Explorer, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to a race condition in the processing of security dialogs when prompting a user to install/execute an ActiveX control, which could be exploited by remote attackers to manipulate the dialog box and remotely compromise a vulnerable system by convincing a user to visit a specially crafted Web page and perform certain actions (e.g. write a specific text in a text field) that will cause a malicious ActiveX control to be inadvertently installed and/or executed&lt;/i&gt;&amp;quot;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.frsirt.com/english/advisories/2006/1559"&gt;http://www.frsirt.com/english/advisories/2006/1559&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Yawn.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114617633102772304?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114617633102772304/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114617633102772304' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114617633102772304'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114617633102772304'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/and-another-ie-remote-hole.html' title='And another IE remote hole...'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114609772725491508</id><published>2006-04-27T02:21:00.000+02:00</published><updated>2006-04-27T02:36:33.873+02:00</updated><title type='text'>If you use Ethereal, update as soon as possible</title><content type='html'>From SANS: &amp;quot;&lt;i&gt;Yes, if you use Ethereal, it is time to upgrade. According an advisory posted by Frsirt, 28 vulnerabilities has been identified in Ethereal &amp;quot;which could be exploited by remote attackers to compromise a vulnerable system or cause a denial of service.&amp;quot;&lt;/i&gt;&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/diary.php?storyid=1288" target="_blank"&gt;http://isc.sans.org/diary.php?storyid=1288&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;28 vulnerabilities? Wow. Ethereal is a great program, but it's time they really think about security. OpenBSD even removed it from its ports as a consequence of its problems.&lt;br /&gt;&lt;br /&gt;Maybe I'll try to &amp;quot;sandbox&amp;quot; it through &lt;a href="http://force.coresecurity.com" target="_blank"&gt;Core Force&lt;/a&gt; and see what can be done, but still, it might be that because of Ethereal's inherent privileges it's not going to be enough.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114609772725491508?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114609772725491508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114609772725491508' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114609772725491508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114609772725491508'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/if-you-use-ethereal-update-as-soon-as.html' title='If you use Ethereal, update as soon as possible'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114608312697194148</id><published>2006-04-26T22:19:00.000+02:00</published><updated>2006-04-27T02:15:08.556+02:00</updated><title type='text'>Yet another IE remote security hole</title><content type='html'>&lt;img src="http://img244.imageshack.us/img244/1559/213rats25np3au.jpg" height="134" width="200" align="left" alt="" style="padding-right:6px" /&gt; From Secunia: &amp;quot;&lt;i&gt;Michal Zalewski has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system.&lt;br /&gt;&lt;br /&gt;The vulnerability is caused due to an error in the processing of certain sequences of nested "object" HTML tags. This can be exploited to corrupt memory by tricking a user into visiting a malicious web site.&lt;br /&gt;&lt;br /&gt;Successful exploitation allows execution of arbitrary code&lt;/i&gt;&amp;quot;.&lt;br /&gt;&lt;br /&gt;Sheesh. &amp;quot;Execution of arbitrary code&amp;quot;. And I thought this was serious *sarcasm*.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://secunia.com/advisories/19762"&gt;http://secunia.com/advisories/19762&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114608312697194148?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114608312697194148/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114608312697194148' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114608312697194148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114608312697194148'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/yet-another-ie-remote-security-hole.html' title='Yet another IE remote security hole'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114598133851466979</id><published>2006-04-25T18:03:00.000+02:00</published><updated>2006-04-26T22:33:59.366+02:00</updated><title type='text'>Name change</title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;Well, I changed the name of this blog, since I found out that the &amp;quot;Destroy All Malware&amp;quot; name &lt;a href="http://www.kbcafe.com/spam/"&gt;was already taken&lt;/a&gt;. Too bad, it was a nice name. Anyway, I didn't want to spend too much time thinking of a good name, so I just name it &amp;quot;Cut the Crap&amp;quot;. You don't like it? I don't care.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114598133851466979?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114598133851466979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114598133851466979' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114598133851466979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114598133851466979'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/name-change.html' title='Name change'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114596464419491695</id><published>2006-04-25T13:20:00.000+02:00</published><updated>2006-04-25T13:39:57.470+02:00</updated><title type='text'></title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;The guys at &lt;a href="http://sunbeltblog.blogspot.com/2006/04/happy-fun-exploit-party.html"&gt;Sunbelt&lt;/a&gt; found a fake Red Cross site that tries to exploit the browser's vulnerabilities.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img260.imageshack.us/img260/5046/exploitpent12123876mu.jpg" border="0" width="400" alt="Image Hosted by ImageShack.us" /&gt;&lt;br /&gt;&lt;br /&gt;The interesting thing is that this one exploits Firefox too. It works only on quite old versions, but still, this is the first Firefox exploit &amp;quot;in the wild&amp;quot; I've seen being used by actual malware distributors.&lt;br /&gt;&lt;br /&gt;So update your Firefox to the latest version if you haven't done it already.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114596464419491695?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114596464419491695/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114596464419491695' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114596464419491695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114596464419491695'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/guys-at-sunbelt-found-fake-red-cross.html' title=''/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26869207.post-114590677192167368</id><published>2006-04-24T19:25:00.000+02:00</published><updated>2006-05-02T02:07:08.543+02:00</updated><title type='text'>What's behind link spam</title><content type='html'>Chances are that if you ever created a weblog or a guestbook, you've come know that "nice" phenomenon known as &lt;a href="http://en.wikipedia.org/wiki/Blog_spam"&gt;link spam&lt;/a&gt;. I'll show you who the people behind this typically are, and they are not nice people.&lt;br /&gt;&lt;br /&gt;Here's an example:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img262.imageshack.us/img262/9540/immagine11lv.gif" alt="" height="242" width="410" /&gt;&lt;br /&gt;&lt;br /&gt;Lots of crappy links. Ever wondered what clicking on one does (note: DON'T). Well, it brings you to a page like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img188.imageshack.us/img188/3677/immagine20ac.gif" alt="" height="480" width="642" /&gt;&lt;br /&gt;&lt;br /&gt;Nothing but a bunch of nonsense and pasted text. So why would anyone bring anybody to a page like that? Unfortunately, there's more than meets the eye. Notice that red circle on the top-left. In the center, you can see a small square. That's an iframe, one of the two idiotic techniques that people behind malware use when trying not to be seen.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img271.imageshack.us/img271/7769/immagine30ro1za.gif" height="209" width="519" alt=""/&gt;&lt;br /&gt;&lt;br /&gt;The iframe itself, of course, uses the other idiotic technique: javascript obfuscation. Considering how easy it is to deobfuscate this things, I wonder why the bother in the first place. Oh, maybe because &lt;a href="http://www.wilderssecurity.com/showthread.php?t=128583"&gt;antivirus link checkers are completely fooled by something this simple&lt;/a&gt;. Heh.&lt;br /&gt;&lt;br /&gt;So what's in the iframe? Well, this one for instance has:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img171.imageshack.us/img171/8725/immagine57lm.gif" alt="" height="480" width="642" /&gt;&lt;br /&gt;&lt;br /&gt;That, in mechanism that took me the amazing incredible time of 2 minutes to decrypt, is something like this:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://img257.imageshack.us/my.php?image=immagine2py.gif"&gt;&lt;img src="http://img169.imageshack.us/img169/4364/immagine66ju.gif" alt="" height="514" width="642" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Note that I snipped the image, as the code extended way beyond: click to see the image with the whole code... and don't try that code at home... ;)&lt;br /&gt;&lt;br /&gt;And what's that? Nothing but a series of exploits that attempt to break the visitor's machine as much as possible. This is the what the whole scam tries to do:&lt;br /&gt;&lt;br /&gt;- determine whether you have Norton or McAfee antivirus through the use of an ActiveX object; if yes, they avoid loading some exploits that they know Norton and McAfee recognize; yes, IE, Norton and McAfee are such amazing products that they let the malware people directly manage what kind of exploits or malware it's safer to load. Wow&lt;br /&gt;&lt;br /&gt;- it might determine (server-side) whether you are using Internet Explorer (if not, some of these iframes won't load anything); I wouldn't visit any of these links with the swiss cheese known as IE if I were you (then again I wouldn't visit ANY site with that swiss cheese anyway). But if you want to explore the actual "full exploits" page you can always download these through wget with the --user-agent option; you don't know what wget is or how to set the --user-agent? Don't bother in the first place.&lt;br /&gt;&lt;br /&gt;- load, of course, a series of exploits and malware, such as this trojan (195.225.176.34/ad/0118/get.php?file=exe):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img177.imageshack.us/img177/4728/immagine70fu.gif" alt="" height="368" width="502" /&gt;&lt;br /&gt;&lt;br /&gt;and this (195.225.176.34/ad/0118/files/spl/Microsoft_Windows_Advanced_Upgrade_Wizard_Logo2______________________________________________________________________.emf):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img429.imageshack.us/img429/9375/immagine87ey.gif" alt="" height="368" width="502" /&gt;&lt;br /&gt;&lt;br /&gt;and this (195.225.176.34/ad/0118/files/spl/ani.anr):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img273.imageshack.us/img273/905/immagine95da.gif" alt="" height="368" width="502" /&gt;&lt;br /&gt;&lt;br /&gt;and this (195.225.176.34/ad/0118/files/spl/java/java.jar):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img289.imageshack.us/img289/6738/immagine107ye.gif" alt="" height="368" width="502" /&gt;&lt;br /&gt;&lt;br /&gt;and this (195.225.176.34/ad/0118/get.php?file=hta):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img288.imageshack.us/img288/2265/immagine113am.gif" alt="" height="368" width="502" /&gt;&lt;br /&gt;&lt;br /&gt;and this (195.225.176.34/ad/0118/files/spl/onload/fillmem.php):&lt;br /&gt;&lt;br /&gt;&lt;img src="http://img271.imageshack.us/img271/9677/immagine120jp.gif" alt="" height="368" width="502" /&gt;&lt;br /&gt;&lt;br /&gt;Weird, they didn't use the CreateTextRange exploit, maybe they're slipping, huh?&lt;br /&gt;&lt;br /&gt;And of course, who are these people? You guessed it, &lt;a href="http://www.spywareguide.com/product_show.php?id=599"&gt;Coolwebsearch&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So, for the love of God, fix your guestbooks and blogs. Please. Don't let this criminals make money by infecting more people.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26869207-114590677192167368?l=cut-thecrap.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://cut-thecrap.blogspot.com/feeds/114590677192167368/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26869207&amp;postID=114590677192167368' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114590677192167368'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26869207/posts/default/114590677192167368'/><link rel='alternate' type='text/html' href='http://cut-thecrap.blogspot.com/2006/04/whats-behind-link-spam.html' title='What&apos;s behind link spam'/><author><name>TNT</name><uri>http://www.blogger.com/profile/01252544602185283227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
