<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Database &#187; Thoughts</title>
	<atom:link href="http://malwaredatabase.net/blog/index.php/cat/thoughts/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwaredatabase.net/blog</link>
	<description>Malware Database is a group of security professionals and a few hobbyists who each contribute to a private distributed database of malicious binaries while raising awareness on current malware trends through our website.</description>
	<lastBuildDate>Fri, 16 Jul 2010 07:11:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Voting Machines</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/15/voting-machines/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/15/voting-machines/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 10:26:09 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[Thoughts]]></category>
		<category><![CDATA[xkcd]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=171</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a title="Voting Machines" rel="lightbox[pics171]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/voting_machines.png"><img class="attachment wp-att-172 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/voting_machines.png" alt="Voting Machines" width="565" height="204" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/15/voting-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CNN &amp; MSNBC Attack &#8211; Where is it all coming from?</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/15/cnn-msnbc-attack-where-is-it-all-coming-from/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/15/cnn-msnbc-attack-where-is-it-all-coming-from/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 09:04:56 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Thoughts]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=166</guid>
		<description><![CDATA[My e-mail inbox has been flooded since breaking the CNN malspam story.  Everyone wants to know where this attack is coming from and how it&#8217;s releasing itself into the wild so quickly.  I&#8217;m sorry to say that I do not have the answer yet&#8230; but I do have a hypothesis.
I believe the attack [...]]]></description>
			<content:encoded><![CDATA[<p>My e-mail inbox has been flooded since breaking the CNN malspam story.  Everyone wants to know where this attack is coming from and how it&#8217;s releasing itself into the wild so quickly.  I&#8217;m sorry to say that I do not have the answer yet&#8230; but I do have a hypothesis.</p>
<p>I believe the attack is exploited 100% through hacked/infected computers.  We know that the e-mails are being distributed by infected computers as we can tell from the e-mail headers, most of the e-mails come from private ADSL or cable lines.  One question remains&#8230; how are the websites getting owned?   Take a second to consider the following possibility&#8230;</p>
<p>I own domain.com and I don&#8217;t know a whole lot about HTML.  I want a flashy website so I go out and buy &#8220;Build Your Own Website Software 1.0&#8243;.  This type of software has several useful features such as a WYSIWYG editor, scripts, images, templates, and <strong><span style="text-decoration: underline;"> automatic FTP upload features.</span></strong></p>
<p>If my machine is infected with malware it will most definitely search for FTP credentials.  If the hackers spent a long enough time harvesting the FTP credentials all they needed to do is write software to upload their malicious pages to each site and then direct their botnet to start spamming the links at the same time.  </p>
<p>Let&#8217;s look at one of the e-mails we received:<br />
Header:</p>
<blockquote><p>Received: from *.adsl.alicedsl.de (*.adsl.alicedsl.de [78.4*.15*.28*])</p></blockquote>
<p>This header shows us that the mail was sent from a private ADSL line on the de TLD.</p>
<p>Body:</p>
<blockquote><p>Girl trains monkey to give tongue service video hxxp://download.german-railroads.eu/start.html</p></blockquote>
<p> The body of the e-mail contains a link to a German railroads site.  Is this a coincidence?</p>
<p>I feel that my hypothesis is fairly obvious but I have not seen much speculation about the attack vector and I would like some input from our readers.  What do you think?  </p>
<p>If anyone reading this post has had their website compromised by this attack, please contact me at lithium@malwaredatabase.net as I would like to perform a post-mortem analysis to identify the attack vector.  </p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/15/cnn-msnbc-attack-where-is-it-all-coming-from/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New site distributing Antivirus2009 Rogue</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/07/31/new-site-distributing-antivirus2009-rogue/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/07/31/new-site-distributing-antivirus2009-rogue/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 10:25:17 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Thoughts]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=77</guid>
		<description><![CDATA[We found a new site distributing the Antivirus 2009 rogue software today.
**Proceed at your own risk**
Site:  hxxp://antivirus-2009pro.com
File: hxxp://antivirus-2009pro.com/2009/download/77001106/AV2009Install.exe

Results for antivirus-2009pro.com:

Domain Name: ANTIVIRUS-2009PRO.COM

Creation Date: 30-Jul-2008
Expiration Date: 30-Jul-2009

Domain servers in listed order:
ns4.mynick.name
ns3.mynick.name
ns2.mynick.name
ns1.mynick.name

Registrant:
PrivacyProtect.org
Domain Admin        (contact@privacyprotect.org)
P.O. Box 97
Note - All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676


]]></description>
			<content:encoded><![CDATA[<p>We found a new site distributing the Antivirus 2009 rogue software today.</p>
<p><strong>**Proceed at your own risk**</strong></p>
<p>Site:  hxxp://antivirus-2009pro.com</p>
<div>File: hxxp://antivirus-2009pro.com/2009/download/77001106/AV2009Install.exe</div>
<blockquote>
<pre><strong>Results for antivirus-2009pro.com:</strong>

Domain Name: ANTIVIRUS-2009PRO.COM

Creation Date: 30-Jul-2008
Expiration Date: 30-Jul-2009

Domain servers in listed order:
ns4.mynick.name
ns3.mynick.name
ns2.mynick.name
ns1.mynick.name

Registrant:
PrivacyProtect.org
Domain Admin        (<a href="mailto:contact@privacyprotect.org">contact@privacyprotect.org</a>)
P.O. Box 97
Note - All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676</pre>
</blockquote>
<p style="text-align: center;"><a title="Antivirus 2009 Rogue" rel="lightbox[pics-1217499418]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/screenhunter_15-jul-31-03141.gif"><img class="attachment wp-att-79 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/screenhunter_15-jul-31-03141.gif" alt="Antivirus 2009 Rogue" width="500" height="380" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/07/31/new-site-distributing-antivirus2009-rogue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hillary and Obama are gay. President Bush killed&#8230; What&#8217;s next?</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/07/24/hillary-and-obama-are-gay-whats-next/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/07/24/hillary-and-obama-are-gay-whats-next/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 03:38:30 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Thoughts]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=40</guid>
		<description><![CDATA[
Hillary and Obama are gay. President Bush killed in Afghan bombing&#8230;What&#8217;s Next?

We do not mean to bore you with the same old malspam posts every day but after viewing this last e-mail I got to thinking&#8230;
What will the next threat be once everyone realizes that almost all e-mail requesting the user to watch a video [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<p style="text-align: left;">Hillary and Obama are gay. President Bush killed in Afghan bombing&#8230;What&#8217;s Next?</p>
<p style="text-align: center;"><a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/hillary.jpg" rel="lightbox[40]"><img class="alignnone size-medium wp-image-41 aligncenter" title="Hillary is Gay" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/hillary-300x197.jpg" alt="" width="300" height="197" /></a></p>
<p>We do not mean to bore you with the same old malspam posts every day but after viewing this last e-mail I got to thinking&#8230;</p>
<p>What will the next threat be once everyone realizes that almost all e-mail requesting the user to watch a video is malware?  What is the next step for the malware creators? Will exploits increasingly become the delivery of choice? Will site hijacking move to the front of the line?  Will legitimate stories on social media sites like digg, reddit, or twitter compromise the users’ security unknowingly?</p>
<p>We are starting to see that in 2009 many security vendors are tightening the belt on the machine they once had control of 10 years ago.</p>
<ul>
<li><a href="https://www.trendbeta.com/index.php?get=358">https://www.trendbeta.com/index.php?get=358</a></li>
</ul>
<ul>
<li><a href="http://research.pandasecurity.com/archive/Panda-Internet-Security-2009-BETA.aspx">http://research.pandasecurity.com/archive/Panda-Internet-Security-2009-BETA.aspx</a></li>
</ul>
<ul>
<li><a href="http://www.symantec.com/norton-beta/internet-security/">http://www.symantec.com/norton-beta/internet-security</a></li>
</ul>
<p>Assuming that the industries effort in 2009 is not futile, what will the new pressure create?  My honest opinion is that the malware will continue to get smaller, more efficient, and even less intrusive than it already is.  Rogue Anti-Malware products replaced with stealthier cousins perhaps.</p>
<p>Only a few things remain certain.  The criminals still need our credit card numbers, social security numbers, and any other sensitive data that can be sold on the black market <em>and </em>social engineering with stealth malware will remain the easiest way to obtain such data.</p>
<blockquote><p>Hoaxes use weaknesses in human behaviour to ensure they are replicated and distributed. In other words, hoaxes prey on the Human Operating System.  -Stewart Kirkpatrick</p></blockquote>
<p>I am interested in hearing your opinion.  Leave me a message in the comments or just e-mail me at lithium@malwaredatabase.net and we can talk about it.</p>
<p><a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/hillary.jpg" rel="lightbox[40]"><br />
</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/07/24/hillary-and-obama-are-gay-whats-next/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
