<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-3987411906174108596</id><updated>2008-07-04T05:46:05.982+01:00</updated><title type='text'>DISOG</title><link rel='alternate' type='text/html' href='http://www.disog.org/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default?start-index=26&amp;max-results=25'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.disog.org/rss.xml'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>80</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-2506063087943848036</id><published>2008-07-04T05:10:00.006+01:00</published><updated>2008-07-04T05:46:06.055+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='Stormworm'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Codec'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>Storm - Fourth of July run</title><summary type='text'>Stormworm (aka CME711/Peed/Peacomm), has recently modified their spam run to play on US Independence Day - July 4th.

The site offers fireworks.exe, and forces a binary download using some malicious javascript. Users should be cautioned to watch for pages that look similar to this:




Instead of the typical "you need to download the codec to play this video", the storm authors have decided to </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/07/storm-fourth-of-july-run.html' title='Storm - Fourth of July run'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=2506063087943848036' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2506063087943848036'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2506063087943848036'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-8740420840065364456</id><published>2008-06-20T04:02:00.004+01:00</published><updated>2008-06-20T04:08:38.241+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Backtrack'/><title type='text'>BackTrack 3 Final - Released</title><summary type='text'>Remote Exploit has just released the final version of BackTrack 3 - the screwdriver of the penetration testers toolbox. I am a big fan of BackTrack.

From the site:

 Currently BackTrack consists of more than 300 different up-to-date tools which are logically structured according to the work flow of security professionals. This structure allows even newcomers to find the related tools to a </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/06/backtrack-3-final-released.html' title='BackTrack 3 Final - Released'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=8740420840065364456' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8740420840065364456'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8740420840065364456'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-4630689512037047526</id><published>2008-06-20T00:56:00.011+01:00</published><updated>2008-06-20T05:07:44.284+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Codec'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='illegal porn'/><title type='text'>Fake Porntube site -&gt; r.html -&gt; video.exe</title><summary type='text'>I recently received an email:

Delivered-To: (REDACTED)
Received: by 10.114.197.7 with SMTP id u7cs66501waf;
  Thu, 19 Jun 2008 07:06:35 -0700 (PDT)
Received: by 10.210.46.12 with SMTP id t12mr1910940ebt.23.1213884394448;
  Thu, 19 Jun 2008 07:06:34 -0700 (PDT)
Return-Path: 
Received: from ?88.251.149.76? ([88.251.202.216])
  Thu, 19 Jun 2008 07:06:34 -0700 (PDT)
client-ip=88.251.202.216;
(</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/06/fake-porntube-site-rhtml-videoexe.html' title='Fake Porntube site -&gt; r.html -&gt; video.exe'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=4630689512037047526' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4630689512037047526'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4630689512037047526'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-8804660822821812597</id><published>2008-06-19T01:47:00.005+01:00</published><updated>2008-06-19T04:17:13.539+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Codec'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnets'/><category scheme='http://www.blogger.com/atom/ns#' term='fastflux'/><title type='text'>CME711's latest SE Spam</title><summary type='text'>

The Stormworm operators have recently updated their spam and web content. The webpage (capture to the right) is shown in its entirety. Users are then given the opportunity to download and run a malicious file, beijing.exe.

For the last couple months the Storm domains have been less fastfluxy - they change every 60 seconds instead of with every request. Perhaps this is because they simply are </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/06/cme711s-latest-se-spam.html' title='CME711&apos;s latest SE Spam'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=8804660822821812597' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8804660822821812597'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8804660822821812597'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-716786496031020119</id><published>2008-05-16T04:17:00.005+01:00</published><updated>2008-05-16T05:07:38.473+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google Dorks'/><category scheme='http://www.blogger.com/atom/ns#' term='Penetration Testing'/><category scheme='http://www.blogger.com/atom/ns#' term='Website Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Network Security'/><title type='text'>Penetration testing and site security</title><summary type='text'>Greetings everyone!

While botnet research is fun and rewarding, it doesn't always pay the mortgage. Those who pay well don't enjoy having research aired in public - hence the lack of postings lately.

I figured some regular readers might be interested in what I've been up to. At the same time, I hope to create a good set of notes for an educational presentation I hope to give in a few months. </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/05/penetration-testing-and-site-security.html' title='Penetration testing and site security'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=716786496031020119' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/716786496031020119'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/716786496031020119'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-2703570930728195520</id><published>2008-04-01T02:26:00.010+01:00</published><updated>2008-04-01T03:53:41.222+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='Stormworm'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><title type='text'>CME711 - April Fools</title><summary type='text'>I'm a bit late posting this one - I've been working on some penetration testing projects and have been unable to monitor my honeypots.

For those who have not yet noticed:

(image captured by DISOG staff on 2008/03/31)

5 second refresh downloads funny.exe, image click downloads kickme.exe and click here link is foolsday.exe - all of which are the same file.


The email:
    From: sauna@</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/04/cme711-april-fools.html' title='CME711 - April Fools'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=2703570930728195520' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2703570930728195520'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2703570930728195520'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-5069517304914443854</id><published>2008-03-10T12:15:00.003Z</published><updated>2008-03-10T12:29:58.259Z</updated><title type='text'>Excellent ISC diary entry</title><summary type='text'>I really enjoyed reading a recent ISC diary entry by Maarten Van Horenbeeck.

Its very important for malware researchers and forensics folks to expand their focus when dealing with intrusion incidents, regardless of if the attacker is white hat or black hat. The attacker knows you are watching, and they will try to hide in plain sight. This entry involves trickery on multiple fronts. If you don't</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/03/excellent-isc-diary-entry.html' title='Excellent ISC diary entry'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=5069517304914443854' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/5069517304914443854'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/5069517304914443854'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-5750016007186517535</id><published>2008-03-03T04:49:00.006Z</published><updated>2008-03-03T06:04:18.337Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='Stormworm'/><category scheme='http://www.blogger.com/atom/ns#' term='postcard'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='p2p botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Zhelatin'/><title type='text'>CME711 - Its a howl!</title><summary type='text'>Storm/CME711 is back to a 'funny greeting card' page.


(Note the "copyright error" in the image)

The file postcard.exe  is offered by clicking on the image. The file ecard.exe is offered when waiting 5 seconds. The file e-card.exe is offered when clicking the 'click here' link. 
Many people already watch for *card.exe with their IDS. I don't expect this to last long. Perhaps the next will be </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/03/cme711-its-howl.html' title='CME711 - Its a howl!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=5750016007186517535' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/5750016007186517535'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/5750016007186517535'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-2901442652702761473</id><published>2008-02-29T15:48:00.006Z</published><updated>2008-02-29T16:43:21.532Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='trickery'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='RFI'/><title type='text'>RFI's and Phishing Tricks</title><summary type='text'>Our Honeypots have been hit with a rash of RFI's lately - we count over 1600 attempts from Feb 20-Feb 29. Some of the higher numbered attempts are listed below.
(71) http://www[dot]gumgangfarm[dot]com/shop/data/id[dot]txt
(53) http://www[dot]geocities[dot]com/giwel/file/id[dot]txt
(48) http://www[dot]tuttoscemo[dot]com/administrator/components/com_juser/id[dot]txt
(44) http://www[dot]</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/02/rfis-and-phishing-tricks.html' title='RFI&apos;s and Phishing Tricks'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=2901442652702761473' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2901442652702761473'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2901442652702761473'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-3628781127044916528</id><published>2008-02-23T03:30:00.005Z</published><updated>2008-02-23T14:07:26.168Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='pharmacy spam'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711 Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='Zhelatin'/><title type='text'>Welcome to my homepage - CME711's latest run.</title><summary type='text'>While checking my Stormworm/CME711/Peed/Peacomm/Zhelatin honeypot I noticed a recent page in German - which was roughly translated to English using an online translation utility:

Patrick homepage
Hello everyone!
Welcome to my home page

Short about me:

I have thought a lot, and now decided that normal relations with the woman I am with is not acceptable. 
I am gay. My new life has changed a lot</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/02/welcome-to-my-homepage-cme711s-latest.html' title='Welcome to my homepage - CME711&apos;s latest run.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=3628781127044916528' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3628781127044916528'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3628781127044916528'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-8499743679600284866</id><published>2008-02-03T05:57:00.000Z</published><updated>2008-02-03T17:07:19.754Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Stormworm'/><category scheme='http://www.blogger.com/atom/ns#' term='supernodes'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet Task Force'/><category scheme='http://www.blogger.com/atom/ns#' term='SandboxIE'/><category scheme='http://www.blogger.com/atom/ns#' term='DC and C'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='p2p botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='Skype'/><category scheme='http://www.blogger.com/atom/ns#' term='Superbug'/><title type='text'>Botnet Distributed Command and Control. (DC&amp;C)</title><summary type='text'>Over the past four years we've seen a large number of law enforcement, ISPs, and hobbyists get involved with botnet monitoring. A side effect of the increased interest is that botnet operators will go to great lengths to keep their botnets hidden. That includes encryption, hiding in plain sight, use of undocumented/new protocols and distributed control structures. As law enforcement arrests more </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/02/botnet-distributed-command-and-control.html' title='Botnet Distributed Command and Control. (DC&amp;C)'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=8499743679600284866' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8499743679600284866'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8499743679600284866'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-1294525251092616578</id><published>2008-02-03T05:17:00.000Z</published><updated>2008-02-03T05:52:57.570Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anubis Sandbox'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='Computer Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Infiltrator'/><category scheme='http://www.blogger.com/atom/ns#' term='TOR'/><title type='text'>Researching your own botnets</title><summary type='text'>This post is mainly for people interested in researching botnets. Many people treat botnet monitoring as a hobby. In many ways, its almost as fun as people watching.

Section 1, the rules of behavior:

You will likely see information you should not normally be privy to. For example, keylogged data, passwords, IP's of vulnerable systems, instant messenger conversations, etc. You must not repeat </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/02/researching-your-own-botnets.html' title='Researching your own botnets'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=1294525251092616578' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/1294525251092616578'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/1294525251092616578'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-2746679488442731221</id><published>2008-01-31T02:41:00.000Z</published><updated>2008-01-31T03:01:37.926Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Botnet monitoring'/><category scheme='http://www.blogger.com/atom/ns#' term='Python'/><category scheme='http://www.blogger.com/atom/ns#' term='Infiltrator'/><title type='text'>Infiltrator Botnet Monitor</title><summary type='text'>Usually the first question asked by someone who is interested in botnet monitoring is, "What do you use to monitor botnets?"

New hunters tend to watch IRC networks, then move up to HTTP, P2P, etc. Many new hunters try to use off the shelf IRC clients, until they realize the bloat really isn't worth it, and monitoring more than a dozen nets is incredibly impossible. Furthermore, monitoring custom</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/01/infiltrator-botnet-monitor.html' title='Infiltrator Botnet Monitor'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=2746679488442731221' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2746679488442731221'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/2746679488442731221'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-3412417935696559444</id><published>2008-01-30T03:29:00.000Z</published><updated>2008-01-30T04:08:03.995Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='pharmacy spam'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='Websense'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711 Storm'/><title type='text'>Pharmacy related sites - the work of CME711?</title><summary type='text'>Over the last few months there has been a large number of domains registered for what appears to be pharmacy related sites.

Many of the sites are using 5 minute TTL's with multiple A records.

Possibly related, Websense posted this today: http://www.websense.com/securitylabs/blog/blog.php?BlogID=170

Websense believes the spam they have seen is related to Storm/CME711. Its very likely that these</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/01/pharmacy-related-sites-work-of-cme711.html' title='Pharmacy related sites - the work of CME711?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=3412417935696559444' title='4 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3412417935696559444'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3412417935696559444'/><author><name>Nicholas</name><uri>http://www.blogger.com/profile/15239725861413327682</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-4122277128473938080</id><published>2008-01-15T20:53:00.000Z</published><updated>2008-01-16T15:30:34.383Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><title type='text'>CME711: Happy Valentines Day and Halifax phish</title><summary type='text'>The CME711 gang has changed their tactics again. We've started seeing emails in our mail drops with pointers to nodes serving "withlove.exe" and "with_love.exe".

So far they have reverted back to sending IP's in the email body, which makes it easy for most spam filters to catch.

The website code looks the same as in previous runs, with false binaries in comments and the greeting:

Your download</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/01/cme711-happy-valentines-day-and-halifax.html' title='CME711: Happy Valentines Day and Halifax phish'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=4122277128473938080' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4122277128473938080'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4122277128473938080'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-4399584182657472244</id><published>2008-01-10T03:33:00.000Z</published><updated>2008-01-10T04:18:26.525Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='nuwar'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='Shadowserver'/><title type='text'>CME711 Domains offline.</title><summary type='text'>Steven Adair with Shadowserver is reporting that all the Stormworm domains have been marked NOT DELEGATED.

Randy V also performed some checks today and found the same thing. We're keeping a close eye on our honeypot to see if they change domains or if this is simply a smoke screen.

The authors were probably finished with the domains anyway, since its well passed the new year. The DISOG team is </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2008/01/cme711-domains-offline.html' title='CME711 Domains offline.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=4399584182657472244' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4399584182657472244'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4399584182657472244'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-7371365822723079423</id><published>2007-12-28T19:49:00.000Z</published><updated>2007-12-31T13:28:50.624Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='nuwar'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><title type='text'>New Year, Recycled Greeting Cards</title><summary type='text'>The storm authors have made up for their lack of creativity by registering a bunch of domains and quickly changing the filename. Additionally a false name has been added as a comment to the html source:
Your download should begin shortly. If your download does not start in
approximately 15 seconds,&lt;br&gt;
you can &lt;!-- a href="fck2008.exe" !--&gt;&lt;script language="javascript"&gt;
&lt;!-- a href="fck2009.exe" </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/new-year-recycled-greeting-cards.html' title='New Year, Recycled Greeting Cards'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=7371365822723079423' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/7371365822723079423'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/7371365822723079423'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-3481849350138491614</id><published>2007-12-26T16:13:00.001Z</published><updated>2007-12-26T16:18:31.105Z</updated><title type='text'>Bleeding Edge threats mirror</title><summary type='text'>For the last few days Bleeding Edge Threats (Sensory Networks) has had issues with their DNS and servers. Matt Jonkman let us know that his new home, Emerging Threats, will also act as a mirror for the Bleeding Edge rules.  An entry on the Emerging Threats website states: In light of the unavailability of the Bleeding Edge Rulesets we're mirroring them over here. Will be adding a number of rules </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/bleeding-edge-threats-mirror.html' title='Bleeding Edge threats mirror'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=3481849350138491614' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3481849350138491614'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3481849350138491614'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-6188705591819194566</id><published>2007-12-26T01:59:00.000Z</published><updated>2007-12-28T19:49:46.841Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='nuwar'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='egreeting'/><title type='text'>Bah, Storm.</title><summary type='text'>I'd like to thank everyone who wrote in with the updates, CME711 is now using a Happy New Year theme. I would have posted earlier, but I promised the family a full day of Non-Digital happiness and it was truly a white Christmas.

Nothing sexy about this latest run, pretty crappy workmanship. It was an obvious after thought. It probably pissed off the botrunner that so many people were able to </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/bah-storm.html' title='Bah, Storm.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=6188705591819194566' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/6188705591819194566'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/6188705591819194566'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-4457838244200562578</id><published>2007-12-24T01:54:00.000Z</published><updated>2007-12-26T17:41:56.687Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='neosploit'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Stormworm is back. - Have a Merry Christmas Dude, Mrs. Claus is kinky!</title><summary type='text'>
We just received a handful of these in our mail drops. Looks like the grinch still runs storm. Received: from odv ([129.65.118.202])
 by dxmbg (8.13.4/8.13.4) with SMTP id lBO3q3Xg061735;
 Sun, 23 Dec 2007 19:52:03 -0800
Message-ID: &lt;002601c845e0$2b459370$ca764181@odv&gt;
From: jyothi@acc.aon.com
To: Nicholas
Subject: Santa Said, HO HO HO
Date: Sun, 23 Dec 2007 19:50:48 -0800
MIME-Version: 1.0
</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/stormworm-is-back-have-merry-christmas.html' title='Stormworm is back. - Have a Merry Christmas Dude, Mrs. Claus is kinky!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=4457838244200562578' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4457838244200562578'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/4457838244200562578'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-7475158592947380233</id><published>2007-12-22T01:49:00.000Z</published><updated>2007-12-24T14:54:40.539Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='ISC'/><category scheme='http://www.blogger.com/atom/ns#' term='nuwar'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='requests'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><title type='text'>The silent Storm and Javascript Decoding</title><summary type='text'>Its been awhile since I've posted anything. I haven't lost touch, I've just been busy with the upcoming Holiday, and reserving myself for the next big Storm update.

A few of us were talking about Storm the other day, and Paul suggested that perhaps the authors have simply abandoned the current Storm botnet, in favor of laying low for a few months, and releasing a whole new version of the code, </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/silent-storm-and-javascript-decoding.html' title='The silent Storm and Javascript Decoding'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=7475158592947380233' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/7475158592947380233'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/7475158592947380233'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-259059484451475206</id><published>2007-12-06T04:14:00.000Z</published><updated>2007-12-06T04:58:02.738Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Sandbox'/><category scheme='http://www.blogger.com/atom/ns#' term='malware research'/><category scheme='http://www.blogger.com/atom/ns#' term='C and C'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco'/><title type='text'>Sandboxing and CSA Advisory</title><summary type='text'>I spent a few hours playing with my sandbox tonight, and found these C&amp;C's:

x.fuckunion.com  (GET /adswin//adsupdate.asp?ver=2007010300 HTTP/1.1)

http://208.72.169.22:4099 (GET /g/A39F4B-796773-3A00DD HTTP/1.1)

traff.justcount.net GET /t/d2hsdWF3OzJ0OHY5Oj0................cKEwkcVA8KCwEL/count.htm HTTP/1.1 

208.72.169.55 (POST /login.php HTTP/1.0) 

s2.truth-is-out-there.org (GET /?name= HTTP/</summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/sandboxing.html' title='Sandboxing and CSA Advisory'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=259059484451475206' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/259059484451475206'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/259059484451475206'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-8302701700269565852</id><published>2007-12-05T04:54:00.000Z</published><updated>2007-12-05T05:20:03.531Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Realplayer'/><category scheme='http://www.blogger.com/atom/ns#' term='peacomm'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='Iframes'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><category scheme='http://www.blogger.com/atom/ns#' term='CME711'/><category scheme='http://www.blogger.com/atom/ns#' term='peed'/><category scheme='http://www.blogger.com/atom/ns#' term='Quicktime'/><title type='text'>QuickTime and RealPlayer Exploits</title><summary type='text'>We're seeing lots of reports about Quicktime and RealPlayer exploits in the wild. Other security vendors are privately reporting an excess of 300 sites infected with these exploits. Most of them are iframes pointing to encoded Javascript. Of course users may never even know they've been infected.

Here is a partial snip of one exploit in human readable form:

function RealExploit()
{
        var </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/12/quicktime-and-realplayer-exploits.html' title='QuickTime and RealPlayer Exploits'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=8302701700269565852' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8302701700269565852'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/8302701700269565852'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-3644102126577996214</id><published>2007-11-19T00:34:00.000Z</published><updated>2007-11-19T01:34:01.014Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='CastleCops'/><category scheme='http://www.blogger.com/atom/ns#' term='Paros'/><category scheme='http://www.blogger.com/atom/ns#' term='TinyURL'/><title type='text'>Walking through a phish site.</title><summary type='text'>I just received this email in my inbox and figured some readers would enjoy some light reading.

Online Banking

Dear Regions Bank member,


We'd like to inform you that your Message Center has 1 new message. Please log in immediately and read the message. The Message Center contains only important information about your account and online banking.

Please follow this link in order to read your </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/11/walking-through-phish-site.html' title='Walking through a phish site.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=3644102126577996214' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3644102126577996214'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/3644102126577996214'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-3987411906174108596.post-7368490962278402161</id><published>2007-11-17T03:06:00.000Z</published><updated>2007-11-17T03:11:11.374Z</updated><title type='text'>Matt Jonkman is leaving Bleeding Threats</title><summary type='text'>After five years, Matt has decided it is best to leave Bleeding Threats. A message posted to several mailing lists said:

After nearly 5 years as the founder and admin of Bleeding Edge Threats I
must step out of the project.

Sensory Networks, as many of you know, has very generously provided the
financial support that's made it possible for me to keep Bleeding
Threats up and running over the </summary><link rel='alternate' type='text/html' href='http://www.disog.org/2007/11/matt-jonkman-is-leaving-bleeding.html' title='Matt Jonkman is leaving Bleeding Threats'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3987411906174108596&amp;postID=7368490962278402161' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.disog.org/rss.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/7368490962278402161'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3987411906174108596/posts/default/7368490962278402161'/><author><name>Nicholas</name><email>noreply@blogger.com</email></author></entry></feed>