<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-804714437673009003</id><updated>2010-02-05T17:14:54.093Z</updated><title type='text'>Dynamoo's Blog</title><subtitle type='html'>Spam, security, scams, spin and stuff.</subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/index.htm'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default?start-index=26&amp;max-results=25'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.dynamoo.com/blog/atom.xml'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>408</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-3680114505796105366</id><published>2010-02-05T17:03:00.002Z</published><updated>2010-02-05T17:14:54.103Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malvertising'/><title type='text'>More fake ad networks</title><content type='html'>The German news site Handelsblatt was recently the &lt;a href="https://www.spk-ostunterfranken.de/privatkunden/onlinebanking/warnungen/aktuelle_warnungen/index.php?IFLBSERVERID=IF@@061@@IF"&gt;victim of a malvertising campaign&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;02.02.2010 Handelsblatt malware on Web site&lt;br /&gt;&lt;br /&gt;Update: Infection banners confirmed!&lt;br /&gt;&lt;br /&gt;The S-CERT was able to reproduce the infection in its test laboratory on the IHT website. Infection occurs through an advertising banner, which is from "Doubleclick.net. This will in turn include advertisements from the domain "muentely.com" in the Handelsblatt-page insert. The latter site is obviously manipulated and contains malicious JavaScript code.&lt;br /&gt;&lt;br /&gt;Further investigations in the S-CERT laboratory testing have confirmed that will be used including a PDF vulnerability to the spread of malware. The studies also show that there is an alternative to the vulnerability, attempts to exploit gaps by further appropriate attack code to install a malware onto vulnerable PCs.&lt;br /&gt;&lt;br /&gt;According to the investigations of the S-CERT is the malware with the accessing PCs will eventually become infected, a so-called Scareware: Users are informed by insertion of appropriate dialogue, that their PC is infected with malware wide area. To remove this malware, an appropriate protective software is available for purchase. To give emphasis to the malware message that ensures Scareware that can be started on any new applications over infected PCs. Relevant information of users may also indicate an infection. &lt;/blockquote&gt;The malware campaign was running via Doubleclick and Nuggad.net, directing through a bunch of domains that &lt;span style="font-style: italic;"&gt;look &lt;/span&gt;like ad agencies but aren't before ending up in a server in Panama.&lt;br /&gt;&lt;br /&gt;The fake ad agencies are in the 213.163.75.x range, all recently registered through BIZCN.COM in China, a fairly well known black hat registrar.&lt;br /&gt;&lt;br /&gt;Note that while the domains appear to be fake, the registration data may include the details of innocent third parties, so I have not published it here. I would recommend avoiding doing business with them unless you can absolutely verify their credentials.&lt;br /&gt;Synopsystd.com&lt;ul&gt;&lt;li&gt;Namdoline.com&lt;/li&gt;&lt;li&gt;Quintat.com&lt;/li&gt;&lt;li&gt;Bradfortnd.com&lt;/li&gt;&lt;li&gt;Ealana.com&lt;/li&gt;&lt;li&gt;Rovitalt.com&lt;/li&gt;&lt;li&gt;Favorti.com&lt;/li&gt;&lt;li&gt;Muentely.com&lt;/li&gt;&lt;li&gt;Briarmod.com&lt;/li&gt;&lt;li&gt;Deltamsc.com&lt;/li&gt;&lt;li&gt;Jessiereet.com&lt;/li&gt;&lt;li&gt;Startrailrs.com&lt;/li&gt;&lt;li&gt;Connata.com&lt;/li&gt;&lt;li&gt;Vehiced.com&lt;/li&gt;&lt;li&gt;Essiell.com&lt;/li&gt;&lt;li&gt;Holdrism.com&lt;/li&gt;&lt;li&gt;Bellwaynetworks.com&lt;/li&gt;&lt;li&gt;Forlifemedia.com&lt;/li&gt;&lt;li&gt;Revoltechmarketing.com&lt;/li&gt;&lt;li&gt;Hickoryhs.com&lt;/li&gt;&lt;li&gt;Ingramctc.com&lt;/li&gt;&lt;li&gt;Luxortd.com&lt;/li&gt;&lt;li&gt;Morrelmedia.com&lt;/li&gt;&lt;li&gt;Gappion.com&lt;/li&gt;&lt;li&gt;Savoyee.com&lt;/li&gt;&lt;li&gt;Goldbaynetwork.com&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-3680114505796105366?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/3680114505796105366/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=3680114505796105366' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3680114505796105366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3680114505796105366'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/02/more-fake-ad-networks.html' title='More fake ad networks'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-7106144325225578263</id><published>2010-02-04T19:33:00.003Z</published><updated>2010-02-04T19:44:56.877Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Stupidity'/><title type='text'>"Hello, this is Icon calling on behalf of BT.."</title><content type='html'>The phone rings from an undisclosed International number.. an automated voice say "Hello, this is Icon calling on behalf of BT.." and it then goes on to explain that there's nobody to talk to me and I should call back on 0800 980 0127 to unsubscribe. Except of course that I'm bloody on &lt;a href="http://www.mpsonline.org.uk/tps/"&gt;TPS&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So who are they? Icon Communications Centers are based in Prague and have a website at www.icon-cc.com (no, I'm not giving them a link). In fact, the crummy job is advertised &lt;a href="http://www.expats.cz/prague/czech-job-server/your-english-is-worth-more-than-you-imagine--no-czech-required/"&gt;right here&lt;/a&gt;. OK, I say crummy.. the good thing is that Prague is a very nice place, but you probably won't see to much of it in a call centre.&lt;br /&gt;&lt;br /&gt;In the important spirit of pissing cold callers off, here are a couple of contact email addresses you can use to tell them where to go: &lt;span style="font-weight: bold;"&gt;helen.hickin@icon-cc.com&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;moses.velasco@icon-cc.com&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Enjoy.&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7106144325225578263?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/7106144325225578263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=7106144325225578263' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7106144325225578263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7106144325225578263'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/02/hello-this-is-icon-calling-on-behalf-of.html' title='&quot;Hello, this is Icon calling on behalf of BT..&quot;'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-3726247525630772090</id><published>2010-02-04T15:32:00.003Z</published><updated>2010-02-04T15:50:33.417Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Click arbitrage'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Injection Attacks'/><category scheme='http://www.blogger.com/atom/ns#' term='PPC'/><title type='text'>Sergey Ryabov / director@climbing-games.com strikes again</title><content type='html'>There's a somewhat unusual spate of injection attacks doing the rounds, code is being injected into the middle of victim pages through an unknown flaw, starting &lt;span style="font-style: italic;"&gt;document.write(unescape('%3C%73%63%72%69%70%74%20%6C%61%6E%67%75%61%67%65%3D&lt;/span&gt; and then going on for a bit.. deobfuscating the code actually leads to a second layer of obfuscation, but once that is decoded it becomes clearer.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/obfus2-763125.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 153px;" src="http://www.dynamoo.com/blog/uploaded_images/obfus2-763123.png" alt="" border="0" /&gt;&lt;/a&gt;The injected code points to &lt;span style="font-weight: bold;"&gt;itsallbreaksoft.net&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/obfus3-706262.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 144px;" src="http://www.dynamoo.com/blog/uploaded_images/obfus3-706260.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This then bounces through &lt;span style="font-weight: bold;"&gt;paymoneysystem.info/in.cgi?michaeleknowlton&lt;/span&gt; before hitting a seemingly random PPC search engine site hosted on 95.211.27.154, for example &lt;span style="font-weight: bold;"&gt;sdeh.net/iframe.html&lt;/span&gt;. Sophos have an excellent write-up of the anatomyof the injection attack &lt;a href="http://www.sophos.com/blogs/sophoslabs/v/post/8498"&gt;here&lt;/a&gt;, and it's pretty clear that somebody is ripping somebody else off for PPC traffic.. its hard to say who the victims actually are.&lt;br /&gt;&lt;br /&gt;The domains &lt;span style="font-weight: bold;"&gt;itsallbreaksoft.net &lt;/span&gt;and &lt;span style="font-weight: bold;"&gt;paymoneysystem.info&lt;/span&gt; belong to the same person, these are interesting because of the registration details:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;   Nexton Limited&lt;br /&gt;   Ryabov Sergey (director@climbing-games.com)&lt;br /&gt;   +79219270961&lt;br /&gt;   Fax: +79219270961&lt;br /&gt;   Scherbakova st., 6-38&lt;br /&gt;   Saint-Petersburg,  197375&lt;br /&gt;   RU&lt;/blockquote&gt;These contact details are &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=malware+OR+virus+OR+trojan+%22director%40climbing-games.com+%22&amp;amp;btnG=Search&amp;amp;meta=&amp;amp;aq=f&amp;amp;oq="&gt;very well known&lt;/a&gt; for very bad things. Incidentally, the registrar is &lt;span style="font-weight: bold;"&gt;ruler-domains.com&lt;/span&gt;, also an enterprise registered to "Sergey Ryabov" (if that's a real person).&lt;br /&gt;&lt;br /&gt;It's all kind of strange as there doesn't appear to be a malware payload, which is good. But because of the way click arbitrage works, finding the real victims and villains is tricky, although interested researchers may want to have a poke around.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-3726247525630772090?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/3726247525630772090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=3726247525630772090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3726247525630772090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/3726247525630772090'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/02/sergey-ryabov-directorclimbing-gamescom.html' title='Sergey Ryabov / director@climbing-games.com strikes again'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-6835145697327296982</id><published>2010-02-04T15:19:00.002Z</published><updated>2010-02-04T15:21:54.406Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>Using Google Images to fight fraud</title><content type='html'>A great post from the guys at F-Secure about how an employee used &lt;a href="http://www.f-secure.com/weblog/archives/00001873.html"&gt;Google Images to stop being ripped off&lt;/a&gt;. Probably a good tip to stop getting defrauded at auction sites.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-6835145697327296982?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/6835145697327296982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=6835145697327296982' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6835145697327296982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6835145697327296982'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/02/using-google-images-to-fight-fraud.html' title='Using Google Images to fight fraud'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-6764767131484491159</id><published>2010-02-02T22:20:00.002Z</published><updated>2010-02-02T22:32:40.324Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Blogger'/><category scheme='http://www.blogger.com/atom/ns#' term='Blogging'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><title type='text'>Pathetic</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/89323386-754045.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 131px; height: 200px;" src="http://www.dynamoo.com/blog/uploaded_images/89323386-753962.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;A multibillion dollar company operated by a &lt;a href="http://buzz.blogger.com/2010/01/important-note-to-ftp-users.html"&gt;bunch of f*cking amateurs&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In particular.. the bit that says "&lt;span style="font-style: italic;"&gt;We are building a migration tool&lt;/span&gt;", but for some unfathomable reason we have decided to kick off this change before it's ready. Sure, Blogger is a free platform and I could always ask for my money back.&lt;br /&gt;&lt;br /&gt;Another favourite is: "&lt;span style="font-style: italic;"&gt;only .5% of active blogs are published via FTP&lt;/span&gt;".. and the reason for this is that for the past couple of years Blogger's FTP service has become increasingly unreliable for no particular reason.&lt;br /&gt;&lt;br /&gt;Unfortunately, anyone who had business dealings with Google that involve real money will know that the the &lt;span style="font-style: italic;"&gt;f*ck you&lt;/span&gt; attitude to customer service is very much ingrained in Google. To a certain extent, being jerked around when you are not paying for the service is one thing.. but business partners in things like advertising, YouTube and enterprise applications also suffer the same thing.&lt;br /&gt;&lt;br /&gt;Yes, Google is still often awesome. But sometimes, like this time, it's just pathetic.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-6764767131484491159?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/6764767131484491159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=6764767131484491159' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6764767131484491159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6764767131484491159'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/02/pathetic.html' title='Pathetic'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8295535659452382892</id><published>2010-01-20T15:19:00.002Z</published><updated>2010-01-20T16:00:03.108Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Malvertising'/><category scheme='http://www.blogger.com/atom/ns#' term='AdSlash.com'/><title type='text'>AdSlash.com is a bogus ad network</title><content type='html'>We've seen a number of ads being punted through &lt;span style="font-weight: bold;"&gt;AdSlash.com&lt;/span&gt; to legitimate ad networks, but it appears that these are leading to a PDF Exploit (don't visit these sites, obviously!).&lt;br /&gt;&lt;br /&gt;For example:&lt;br /&gt;fwlink.nx7.zedo.com.adslash.com/?alx=a27131939386&amp;amp;td=qcbp71pz=42834&amp;amp;sz=728x90&amp;amp;_zm=359161&amp;amp;st=n1n4&amp;amp;id=131939386&amp;amp;zcw=gh17chl277&amp;amp;xryr=3913771&amp;amp;mp=1460h1&lt;br /&gt;fwlink.nx7.zedo.com.adslash.com/stats_js_e.php?id=131939386 &lt;br /&gt;fwlink.nx7.zedo.com.adslash.com/bdb/Health/banner_728.gif &lt;br /&gt;fridayalways.com/kven/index.php &lt;br /&gt;fridayalways.com/kven/js/common.js&lt;br /&gt;fridayalways.com/kven/pdfadmnplay.php&lt;br /&gt;fridayalways.com/kven/files/backoutblack.pdf&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;fwlink.nx7.zedo.com.adslash.com/?alx=a27131959519&amp;amp;td=qcbp71pz=42834&amp;amp;sz=120x600&amp;amp;_zm=359161&amp;amp;st=n1n4&amp;amp;id=131959519&amp;amp;zcw=gh17chl277&amp;amp;xryr=3913771&amp;amp;mp=1460h1&lt;br /&gt;uparms.com/uparmglde/index.php&lt;br /&gt;uparms.com/uparmglde/js/zingvaz.js&lt;br /&gt;uparms.com/uparmglde/sexxhsdtk.php&lt;br /&gt;which then loads a PDF exploit&lt;br /&gt;&lt;br /&gt;or&lt;br /&gt;&lt;br /&gt;fwlink.nx7.zedo.com.adslash.com/?alx=a27131958218&amp;amp;td=qcbp71pz=42834&amp;amp;sz=300x250&amp;amp;_zm=359161&amp;amp;st=n1n4&amp;amp;id=131958218&amp;amp;zcw=gh17chl277&amp;amp;xryr=3913771&amp;amp;mp=1460h1&lt;br /&gt;setsup.com/setglde/index.php&lt;br /&gt;setsup.com/setglde/js/common.js&lt;br /&gt;setsup.com/setglde/ffcollab.php&lt;br /&gt;setsup.com/setglde/files/slob.pdf&lt;br /&gt;&lt;br /&gt;Despite the use of "zedo.com" in the subdomain, there is no evidence that these are being syndicated through Zedo.&lt;br /&gt;&lt;br /&gt;Let's look at the WHOIS entry for AdSlash.com first:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Domain name: adslash.com&lt;br /&gt;&lt;br /&gt;Registrant Contact:&lt;br /&gt;   PublishingAlert&lt;br /&gt;   Vivian Mitchell jacksosomands@gmail.com&lt;br /&gt;   650-887-5087 fax:&lt;br /&gt;   2069 Duck Creek Road&lt;br /&gt;   Oakland CA 94612&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;   Vivian Mitchell jacksosomands@gmail.com&lt;br /&gt;   650-887-5087 fax:&lt;br /&gt;   2069 Duck Creek Road&lt;br /&gt;   Oakland CA 94612&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;   Vivian Mitchell jacksosomands@gmail.com&lt;br /&gt;   650-887-5087 fax:&lt;br /&gt;   2069 Duck Creek Road&lt;br /&gt;   Oakland CA 94612&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;Billing Contact:&lt;br /&gt;   Vivian Mitchell jacksosomands@gmail.com&lt;br /&gt;   650-887-5087 fax:&lt;br /&gt;   2069 Duck Creek Road&lt;br /&gt;   Oakland CA 94612&lt;br /&gt;   us&lt;br /&gt;&lt;br /&gt;DNS:&lt;br /&gt;ns1.everydns.net&lt;br /&gt;ns2.everydns.net&lt;br /&gt;&lt;br /&gt;Created: 2010-01-04&lt;br /&gt;Expires: 2011-01-04&lt;/blockquote&gt;&lt;br /&gt;The address looks kind of legitimate, but there's no Duck Creek Road in Oakland and the phone number is most likely Los Altos, not Oakland. Also the fact that it has been registered just days ago is a clue.. and it turns out that the registrar is BIZCN.COM of China which is an odd choice for a California company.. in other words, the domain registration details are fake.&lt;br /&gt;&lt;br /&gt;AdSlash.com is hosted on          217.23.7.6        which is reportedly a Worldstream Data Center in Faro, Portugal. There's a cluster of servers with fake registration details which are probably related:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;217.23.7.6&lt;/span&gt;&lt;br /&gt;Adslash.com&lt;br /&gt;Dc2way.com&lt;br /&gt;Ispmns.com&lt;br /&gt;Rtcohost.com&lt;br /&gt;Vpsroll.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;217.23.7.7&lt;/span&gt;&lt;br /&gt;Net-wisp.com&lt;br /&gt;Realhgost.com&lt;br /&gt;Slhoste.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;217.23.7.8&lt;/span&gt;&lt;br /&gt;Inhostin.com&lt;br /&gt;Nx7tech.com&lt;br /&gt;Vpbyte.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;217.23.7.9&lt;/span&gt;&lt;br /&gt;Eywtech.com&lt;br /&gt;Qhostin.com&lt;br /&gt;Sslcode.com&lt;br /&gt;&lt;br /&gt;Blocking the entire &lt;span style="font-weight: bold;"&gt;217.23.7.x&lt;/span&gt; range will probably do no harm at all, it is full of typosquatting domains and other crap.&lt;br /&gt;&lt;br /&gt;The PDF exploit itself is hosted in Russia on &lt;a href="http://www.robtex.com/ip/213.108.56.18.html"&gt;213.108.56.18&lt;/a&gt; at Infoteh Ltd (UNNET-LINER), there are a bunch of domains serving these exploits up:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;alwaysinwork.com&lt;/li&gt;&lt;li&gt;fridayalways.com&lt;/li&gt;&lt;li&gt;runsup.com&lt;/li&gt;&lt;li&gt;uparms.com&lt;/li&gt;&lt;li&gt;upmostly.com&lt;/li&gt;&lt;/ul&gt;WHOIS details show the &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=%22moldavimo%40safe-mail.net%22&amp;amp;aq=f&amp;amp;aql=&amp;amp;aqi=&amp;amp;oq="&gt;infamous moldavimo@safe-mail.net email address.&lt;/a&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;&lt;br /&gt;Registrant:&lt;br /&gt;Name: dannis&lt;br /&gt;Address: Moskow&lt;br /&gt;City: Moskow&lt;br /&gt;Province/state: MSK&lt;br /&gt;Country: RU&lt;br /&gt;Postal Code: 130610&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;Name: dannis&lt;br /&gt;Organization: privat  person&lt;br /&gt;Address: Moskow&lt;br /&gt;City: Moskow&lt;br /&gt;Province/state: MSK&lt;br /&gt;Country: RU&lt;br /&gt;Postal Code: 130610&lt;br /&gt;Phone: +7.9957737737&lt;br /&gt;Fax: +7.9957737737&lt;br /&gt;Email: moldavimo@safe-mail.net&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;Name: dannis&lt;br /&gt;Organization: privat  person&lt;br /&gt;Address: Moskow&lt;br /&gt;City: Moskow&lt;br /&gt;Province/state: MSK&lt;br /&gt;Country: RU&lt;br /&gt;Postal Code: 130610&lt;/blockquote&gt;The whole UNNET-LINER netblock of 213.108.56.0 - 213.108.63.255 looks fairly sordid, blocking access to it will probably do no harm.&lt;br /&gt;&lt;br /&gt;As a side note, AdSlash.com &lt;span style="font-style: italic;"&gt;did&lt;/span&gt; used to be owned by a hosting company called RackSlash, but it expired and was re-registered.&lt;br /&gt;&lt;br /&gt;If you are accepting new ad banners - always remember to look closely at WHOIS details and other credentials to ensure that you are dealing with who you think you are.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-8295535659452382892?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8295535659452382892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8295535659452382892' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8295535659452382892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8295535659452382892'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/adslashcom-is-bogus-ad-network.html' title='AdSlash.com is a bogus ad network'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8829863363111202424</id><published>2010-01-18T18:30:00.005Z</published><updated>2010-01-18T19:02:45.824Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dating Scams'/><category scheme='http://www.blogger.com/atom/ns#' term='Q-Dating.com'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><title type='text'>Is Q-dating.com a fake?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/qdating-794057.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 146px; height: 200px;" src="http://www.dynamoo.com/blog/uploaded_images/qdating-794001.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;At first this looks like some random spam:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Subject:       Find a sexdate - Free registration!&lt;br /&gt;From:       "Q-dating" &amp;lt;info@qdates.net&amp;gt;&lt;br /&gt;Date:       Mon, January 18, 2010 3:19 pm&lt;br /&gt;&lt;br /&gt;Having trouble reading this email?&lt;br /&gt;&lt;br /&gt;FIND A SEXDATE IN YOUR OWN AREA?&lt;br /&gt;&lt;br /&gt;www.Q-Dating.com&lt;br /&gt;[http://mailings.email-pro.net/link.php?M=000&amp;amp;N=143&amp;amp;L=118&amp;amp;F=T]&lt;br /&gt;&lt;br /&gt;Chantal 24 jaaronline&lt;br /&gt;&lt;br /&gt;Single, searching for sexdate!&lt;br /&gt;I'm not ready to settle down&lt;br /&gt;and looking for a sexbuddy&lt;br /&gt;Irene 34 jaaronline&lt;br /&gt;&lt;br /&gt;Married, looking for date.&lt;br /&gt;I am a loving wife of 34 years looking for a nice man.&lt;br /&gt;The best dating site of the UK. Advanced searching, Instant chat, test it&lt;br /&gt;now FREE! Click here&lt;br /&gt;&lt;br /&gt;Click here to unsubscribe&lt;br /&gt;[http://mailings.email-pro.net/unsubscribe.php?M=000&amp;amp;C=00000&amp;amp;L=7&amp;amp;N=143]&lt;/blockquote&gt;After a bit of "wtf" I decided to check out the WHOIS details to see who was spamming:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Company: Realcom Limited&lt;br /&gt;Name: Andy Ling&lt;br /&gt;Address: 33, Throgmorton street&lt;br /&gt;City: LONDON&lt;br /&gt;Country: UNITED KINGDOM&lt;br /&gt;Postal Code: EC2N 2BR&lt;br /&gt;Phone: +44 7937 082 210&lt;br /&gt;Fax:&lt;br /&gt;Email: realcomltd@hotmail.com&lt;/blockquote&gt;Oh, well that's kind interesting.. they appear to be based in the UK. A quick check at Companies House &lt;span style="font-style: italic;"&gt;does&lt;/span&gt; come up with a Realcom Ltd.. but it's a wholly innocent and unconnected company in Oxfordshire.&lt;br /&gt;&lt;br /&gt;There's not much of a web presence about from this &lt;a href="http://www.datingwebsites.nl/reviews/q-dating.com/6323-endelijk-eens-resultaat.php"&gt;Dutch-language review&lt;/a&gt; [&lt;a href="http://translate.google.com/translate?sourceid=mozclient&amp;amp;u=http%3A//www.datingwebsites.nl/reviews/q-dating.com/6323-endelijk-eens-resultaat.php"&gt;autotranslated&lt;/a&gt;] which also complains that the site is a fake and that unauthorised credit card transactions have been made.&lt;br /&gt;&lt;br /&gt;A bit of searching around finds some related domains:&lt;br /&gt;Q-dating.com [94.229.169.102]&lt;br /&gt;Q-dating.eu [78.109.162.121]&lt;br /&gt;Qdates.net [78.109.162.122]&lt;br /&gt;Q-dating.be  [78.109.162.119]&lt;br /&gt;Q-dating.de  [78.109.162.119]&lt;br /&gt;Q-dating.net  [78.109.162.119]&lt;br /&gt;Credifact.net [94.229.169.102]&lt;br /&gt;Megacasting.eu [94.229.169.102]&lt;br /&gt;Email-pro.net [Parked].. mailings.email-pro.net is on 78.109.162.119&lt;br /&gt;&lt;br /&gt;All infrastructure is supplied by UKFast (abuse -at- ukfast.co.uk)&lt;br /&gt;&lt;br /&gt;There are plenty of other dating sites to choose from.. some of them may even be genuine. But given the complaints and the questionable WHOIS details, then probably best to avoid this one.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-8829863363111202424?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8829863363111202424/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8829863363111202424' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8829863363111202424'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8829863363111202424'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/is-q-datingcom-fake.html' title='Is Q-dating.com a fake?'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-2997137836362963459</id><published>2010-01-18T14:41:00.004Z</published><updated>2010-01-18T16:10:41.813Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Bryan Hunter'/><category scheme='http://www.blogger.com/atom/ns#' term='trafficbuyer'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Modena Inc'/><title type='text'>Is trafficbuyer@gmail.com Bryan Hunter of Modena, Inc?</title><content type='html'>We have seen quite a lot of the domain registrant &lt;span style="font-weight: bold;"&gt;trafficbuyer@gmail.com&lt;/span&gt; lately &lt;a href="http://www.dynamoo.com/blog/2009/10/suspect-ad-network-leads-to-pdf-exploit.html"&gt;[1]&lt;/a&gt; &lt;a href="http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html"&gt;[2]&lt;/a&gt; &lt;a href="http://www.dynamoo.com/blog/2010/01/zoombannercom-yieldmanager.html"&gt;[3]&lt;/a&gt; and it would be fair to say that this email address has been connected with malware domains for a few months &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx"&gt;[4]&lt;/a&gt; &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx"&gt;[5]&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Domains operated by trafficbuyer@gmail.com appear to be part of the routing mechanism to bad sites, but there's no indication of who the email address actually belongs to. Is it an ad network, or is it the bad guys themselves.. and if it's an ad network, why are they hiding their name?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2010/01/18/1752182.aspx"&gt;This post at Spyware Sucks&lt;/a&gt; gave a clue. There are several domains which are interesting because they have changed hands during their lifetime from a firm called Modena Inc (modenainc.com) owned by one Bryan Hunter of Oregon and are now in the hands of "trafficbuyer".&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;banner0609.com&lt;br /&gt;&lt;/li&gt;&lt;li&gt;banner0709.com &lt;a href="http://www.siteadvisor.com/sites/banner0709.com"&gt;[6]&lt;/a&gt;  &lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=240"&gt;[7]&lt;/a&gt;  &lt;a href="http://who-is-who-in-gpt.com/forum/viewtopic.php?f=188&amp;amp;t=11024"&gt;[8]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;banner07092.com&lt;/li&gt;&lt;li&gt;banner08091.com&lt;br /&gt;&lt;/li&gt;&lt;li&gt;banner08092.com &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx"&gt;[9]&lt;/a&gt;&lt;/li&gt;&lt;li&gt;banner08093.com &lt;a href="http://www.malwaredomainlist.com/forums/index.php?topic=3190.195"&gt;[10]&lt;/a&gt;&lt;/li&gt;&lt;li&gt;bannersulike.com &lt;a href="http://www.mywot.com/en/scorecard/bannersulike.com"&gt;[11]&lt;/a&gt;  &lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=240&amp;amp;p=91839&amp;amp;#"&gt;[12]&lt;/a&gt;   &lt;a href="http://www.bluetack.co.uk/forums/lofiversion/index.php/t18064-250.html"&gt;[13]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;extrabanner.com &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx"&gt;[14]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;islandbanner.com&lt;/li&gt;&lt;li&gt;foobanner.com&lt;/li&gt;&lt;li&gt;greenlightbanner.com &lt;a href="http://forums.explosm.net/showthread.php?t=41189&amp;amp;page=8"&gt;[15]&lt;/a&gt;  &lt;a href="http://www.bluetack.co.uk/forums/lofiversion/index.php/t18064-250.html"&gt;[16]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;more-banners.com &lt;a href="http://www.google.com/safebrowsing/diagnostic?site=http://more-banners.com/&amp;amp;hl=en"&gt;[17]&lt;/a&gt;  &lt;a href="http://www.mywot.com/en/scorecard/more-banners.com"&gt;[18]&lt;/a&gt;  &lt;a href="http://www.facebook.com/topic.php?uid=20737309912&amp;amp;topic=41457"&gt;[19]&lt;/a&gt;  &lt;a href="http://blog.pause4tc.info/2009/05/malware-warning.html"&gt;[20]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;paperbanner.com&lt;br /&gt;&lt;/li&gt;&lt;li&gt;trendbanner.com  &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx"&gt;[21]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;yellowlinebanner.com  &lt;a href="http://www.mywot.com/en/scorecard/yellowlinebanner.com"&gt;[22]&lt;/a&gt;  &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700082.aspx"&gt;[23]&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;zoombanner.com  &lt;a href="http://www.dynamoo.com/blog/2010/01/zoombannercom-yieldmanager.html"&gt;[24]&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;In July 2009, these domains were registered to:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;Manager, Domain  domains@modenainc.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Modena Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;921 SW Washington ST&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Suite 228&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Portland, Oregon 97205&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;United States&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;(503) 241-1091      Fax -- &lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;By September 2009 they had all changed to:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Owner, Domain  trafficbuyer@gmail.com&lt;br /&gt;15156 SW 5th&lt;br /&gt;Scottsdale, Arizona 85260&lt;br /&gt;United States&lt;br /&gt;+1.8005551212      Fax -- &lt;/blockquote&gt;So, who are Modena Inc of Oregon? &lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=1161229&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;According to the State of Oregon&lt;/a&gt;, the two key people here are Bryan Hunter and Andrew Vilcauskas, although Mr Hunter's name is most often associated with Modena, Inc. The official status for Modena, Inc shows "Administrative Dissolution" which means that the state dissolved the company for non-filing of paperwork.. this seems to be a common issue. If we look at &lt;a href="http://egov.sos.state.or.us/br/pkg_br_web_assoc_name_srch.do_name_srch?p_first_name=BRYAN&amp;amp;p_last_name=HUNTER&amp;amp;p_middle_name=&amp;amp;p_name_suffix=&amp;amp;p_srch=ALL&amp;amp;p_act=ACTINA&amp;amp;p_print=FALSE"&gt;businesses related to Bryan Hunter&lt;/a&gt; then we see:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=912696&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Big Truck Autobody&lt;/a&gt; (dissolved, failed to renew in 2004)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=1071484&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;CreditYes, Inc&lt;/a&gt; (administrative dissolution in 2008, though still trading at &lt;span style="font-weight: bold;"&gt;CreditYes.com&lt;/span&gt;)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=1357308&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Diminished Value, Inc&lt;/a&gt; (filings overdue as of November 2009, trading at &lt;span style="font-weight: bold;"&gt;DiminishedValue.com&lt;/span&gt;)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=282093&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;ExitExchange Corporation&lt;/a&gt; (still active, although check the &lt;a href="http://www.mywot.com/en/scorecard/exitexchange.com"&gt;rating at WOT&lt;/a&gt; for &lt;span style="font-weight: bold;"&gt;ExitExchange.com&lt;/span&gt; or simple &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=exitexchange.com&amp;amp;btnG=Search&amp;amp;meta=&amp;amp;aq=f&amp;amp;oq="&gt;Google it)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=1130255&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Modena Homes, Inc&lt;/a&gt; (administrative dissolution in 2008)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=1161229&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Modena, Inc&lt;/a&gt; (administrative dissolution in 2009)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=981568&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Modena, Inc&lt;/a&gt; (older incorporation, administrative dissolution in 2004)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=156191&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Pro Web Design LLC&lt;/a&gt; (administrative dissolution in 2004)&lt;br /&gt;&lt;a href="http://egov.sos.state.or.us/br/pkg_web_name_srch_inq.show_detl?p_be_rsn=1236486&amp;amp;p_srce=BR_INQ&amp;amp;p_print=FALSE"&gt;Wind Song Creek Estates LLC&lt;/a&gt; (administrative dissolution in 2009)&lt;br /&gt;&lt;br /&gt;Now, given the WHOIS history of these domains we would suggest that either Bryan Hunter &lt;span style="font-style: italic;"&gt;is&lt;/span&gt; trafficbuyer@gmail.com or he sold the domains on to this person. If they are the same person, then perhaps he would like to review his business relationships and clean them up...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2997137836362963459?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/2997137836362963459/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=2997137836362963459' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2997137836362963459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2997137836362963459'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/is-trafficbuyergmailcom-bryan-hunter-of.html' title='Is trafficbuyer@gmail.com Bryan Hunter of Modena, Inc?'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-405123529787356339</id><published>2010-01-15T15:53:00.003Z</published><updated>2010-01-15T16:22:41.345Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='Malvertising'/><title type='text'>zoombanner.com / YieldManager malvertisement on ebuddy.com</title><content type='html'>&lt;span style="font-weight: bold;"&gt;ebuddy.com&lt;/span&gt; is running a malicious ad on the &lt;span style="font-weight: bold;"&gt;zoombanner.com&lt;/span&gt; domain, apparently managed by Yieldmanager.&lt;br /&gt;&lt;br /&gt;First, the "legitimate" end of the malware chain loads at &lt;span style="font-weight: bold;"&gt;ad.zoombanner.com/content?campaign=1171557&amp;amp;sz=6&lt;br /&gt;&lt;/span&gt;This forwards to &lt;span style="font-weight: bold;"&gt;deliver.commismanderakis.com&lt;/span&gt;/rotate?m=2;b=6;c=1;z=585778&lt;br /&gt;Which goes to &lt;span style="font-weight: bold;"&gt;content.fishpotboutademalled.com&lt;/span&gt;/track/3388182/S_IT?[snip]&lt;br /&gt;Then &lt;span style="font-weight: bold;"&gt;img.commismanderakis.com&lt;/span&gt;/img?XAhIPWtICDkJX0FVHXUDKFoRYhYlRxFCNlsBGEhLBEtVdRdiCRYKBA8kKV9RHBEaXFJfXFMHAQ&lt;br /&gt;Followed by the payload domain at &lt;span style="font-weight: bold;"&gt;jduvazuc.info&lt;/span&gt;/cgi-bin/dep&lt;br /&gt;then &lt;span style="font-weight: bold;"&gt;jduvazuc.info&lt;/span&gt;/cgi-bin/dep/j006102Hd793447cR55e239b8T9cc338b5V0100f060203L69740000000000000000&lt;br /&gt;then &lt;span style="font-weight: bold;"&gt;jduvazuc.info&lt;/span&gt;/cgi-bin/dep/o006102203317l0010Hd793447cR55e239b8T9cc338b6V0100f060&lt;br /&gt;Finally &lt;span style="font-weight: bold;"&gt;jduvazuc.info&lt;/span&gt;/cgi-bin/dep/e006102203318l0010Hd793447cJ0d000601R55e239b8T9cc338a4U0ec2fc77V0100f0600&lt;br /&gt;&lt;br /&gt;This last hop tries to load an executable (and probably some other crap I haven't spotted), &lt;a href="http://www.virustotal.com/analisis/cc17309b48024e65148a07736507b5fd9c9516c76080eea46785845643160123-1263569761"&gt;not very well detected&lt;/a&gt; according to VirusTotal. Oh yes, there's a PDF exploit too.&lt;br /&gt;&lt;br /&gt;The malicious ad is an Italian language vacation banner in this case.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/img-716207.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 40px;" src="http://www.dynamoo.com/blog/uploaded_images/img-716203.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Most of the domains have anonymous registration details, except &lt;span style="font-weight: bold;"&gt;zoombanner.com&lt;/span&gt; which has the same details that were used in the malicous ads featured &lt;a href="http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html"&gt;here&lt;/a&gt; and &lt;a href="http://www.dynamoo.com/blog/2010/01/more-on-malvertisements-running-through.html"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;zoombanner.com&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;  Domain Owner&lt;br /&gt;  15156 SW 5th&lt;br /&gt;  Scottsdale, Arizona 85260&lt;br /&gt;  United States&lt;br /&gt;&lt;br /&gt;  Domain Name: ZOOMBANNER.COM&lt;br /&gt;     Created on: 24-Jul-09&lt;br /&gt;     Expires on: 24-Jul-10&lt;br /&gt;     Last Updated on: 24-Jul-09&lt;br /&gt;&lt;br /&gt;  Administrative Contact:&lt;br /&gt;     Owner, Domain  trafficbuyer@gmail.com&lt;br /&gt;     15156 SW 5th&lt;br /&gt;     Scottsdale, Arizona 85260&lt;br /&gt;     United States&lt;br /&gt;     +1.8005551212      Fax --&lt;br /&gt;&lt;br /&gt;  Technical Contact:&lt;br /&gt;     Owner, Domain  trafficbuyer@gmail.com&lt;br /&gt;     15156 SW 5th&lt;br /&gt;     Scottsdale, Arizona 85260&lt;br /&gt;     United States&lt;br /&gt;     +1.8005551212      Fax --&lt;br /&gt;&lt;br /&gt;  Domain servers in listed order:&lt;br /&gt;     NS45.DOMAINCONTROL.COM&lt;br /&gt;     NS46.DOMAINCONTROL.COM&lt;/blockquote&gt;&lt;br /&gt;A search for the IP addresses show Linode is providing most of the infrastructure (again) with ezzi.net providing the payload server.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ad.zoombanner.com&lt;/span&gt;&lt;br /&gt;69.164.215.205, 69.164.215.204 [Linode]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;deliver.commismanderakis.com&lt;/span&gt;&lt;br /&gt;74.207.232.205, 74.207.232.206, 74.207.232.248, 74.207.232.249, 74.207.232.250, 74.207.232.25, 74.207.232.30, 74.207.232.31, 74.207.232.35, 74.207.232.39, 74.207.232.202, 74.207.232.203 [Linode]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;content.fishpotboutademalled.com&lt;/span&gt;&lt;br /&gt;69.164.196.55 [Linode]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;jduvazuc.info&lt;/span&gt;&lt;br /&gt;216.150.79.74 [AccessIT / ezzi.net]&lt;br /&gt;&lt;br /&gt;Incidentally, 69.164.196.55 also hosts a bunch of domains which are probably malicious:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Aspoutceringlapham.com&lt;/li&gt;&lt;li&gt;Baalcootymalachi.com&lt;/li&gt;&lt;li&gt;Bangywhoaswaikiki.com&lt;/li&gt;&lt;li&gt;Bertbleepedupsurge.com&lt;/li&gt;&lt;li&gt;Bluegumgodfulfrowzly.com&lt;/li&gt;&lt;li&gt;Bookletjigsawsenam.com&lt;/li&gt;&lt;li&gt;Boursesdeployporomas.com&lt;/li&gt;&lt;li&gt;Cabullacoexertstephen.com&lt;/li&gt;&lt;li&gt;Camastuthbroomer.com&lt;/li&gt;&lt;li&gt;Camocaexcidealaric.com&lt;/li&gt;&lt;li&gt;Cursarophitkamass.com&lt;/li&gt;&lt;li&gt;Dunnishbribesteen.com&lt;/li&gt;&lt;li&gt;Dusaexsurgeenzed.com&lt;/li&gt;&lt;li&gt;Eelfishminibusdaniel.com&lt;/li&gt;&lt;li&gt;Enyopensilflux.com&lt;/li&gt;&lt;li&gt;Fishpotboutademalled.com&lt;/li&gt;&lt;li&gt;Galasynjingkoendoss.com&lt;/li&gt;&lt;li&gt;Gombayuranidetripper.com&lt;/li&gt;&lt;li&gt;Haileschoralephydra.com&lt;/li&gt;&lt;li&gt;Haredjuvenalalkyds.com&lt;/li&gt;&lt;li&gt;Hoofishsmutsdela.com&lt;/li&gt;&lt;li&gt;Jigmenbrasschaves.com&lt;/li&gt;&lt;li&gt;Jumnamontanodillon.com&lt;/li&gt;&lt;li&gt;Limanadernaggly.com&lt;/li&gt;&lt;li&gt;Malabarvoiotiahsln.com&lt;/li&gt;&lt;li&gt;Mashlampeasewahima.com&lt;/li&gt;&lt;li&gt;Miauwbustianraynold.com&lt;/li&gt;&lt;li&gt;Mowewindsortejo.com&lt;/li&gt;&lt;li&gt;Nahshufrosterpappus.com&lt;/li&gt;&lt;li&gt;Negreetflurtagma.com&lt;/li&gt;&lt;li&gt;Nitrotowelvidovic.com&lt;/li&gt;&lt;li&gt;Oaterhabeasroyalet.com&lt;/li&gt;&lt;li&gt;Ospswraxledfummel.com&lt;/li&gt;&lt;li&gt;Oundycelticrecomb.com&lt;/li&gt;&lt;li&gt;Pcdosbahnerdalea.com&lt;/li&gt;&lt;li&gt;Pealedlupulicdunker.com&lt;/li&gt;&lt;li&gt;Polarlyfoetiskart.com&lt;/li&gt;&lt;li&gt;Potwareabipondeana.com&lt;/li&gt;&lt;li&gt;Psatchargeehewart.com&lt;/li&gt;&lt;li&gt;Puddyolderrippon.com&lt;/li&gt;&lt;li&gt;Sallierdiaushawed.com&lt;/li&gt;&lt;li&gt;Sarddieterchuted.com&lt;/li&gt;&lt;li&gt;Scullogmooerslarking.com&lt;/li&gt;&lt;li&gt;Siwardupttorntrib.com&lt;/li&gt;&lt;li&gt;Skouthlazordurning.com&lt;/li&gt;&lt;li&gt;Suttenbnetifla.com&lt;/li&gt;&lt;li&gt;Tacomanheathsdisodic.com&lt;/li&gt;&lt;li&gt;Temperabiceswayaka.com&lt;/li&gt;&lt;li&gt;Teughlyhesperegerek.com&lt;/li&gt;&lt;li&gt;Toterterrenobrasero.com&lt;/li&gt;&lt;li&gt;Vaccarykakkakcaddoan.com&lt;/li&gt;&lt;li&gt;Viperanmeatsoths.com&lt;/li&gt;&lt;li&gt;Viznomyboohoorigs.com&lt;/li&gt;&lt;li&gt;Voluntyseventechny.com&lt;/li&gt;&lt;li&gt;Wartedbiterhunter.com&lt;/li&gt;&lt;li&gt;Woodardvirgetoruli.com&lt;/li&gt;&lt;li&gt;Yawybottlersuccahs.com&lt;/li&gt;&lt;li&gt;Zirklehalavahhaunchy.com&lt;/li&gt;&lt;/ul&gt;I suspect that you probably wouldn't miss much by null-routing Linode completely at the moment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-405123529787356339?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/405123529787356339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=405123529787356339' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/405123529787356339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/405123529787356339'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/zoombannercom-yieldmanager.html' title='zoombanner.com / YieldManager malvertisement on ebuddy.com'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-6970233298128652146</id><published>2010-01-15T13:36:00.002Z</published><updated>2010-01-15T13:46:37.713Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Too Good To Be True'/><category scheme='http://www.blogger.com/atom/ns#' term='Money Mule'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>"Croft Pole Distributors Limited"  bogus job offer</title><content type='html'>&lt;a href="http://www.croftpoles.co.nz/"&gt;Croft Pole Distributors Ltd&lt;/a&gt; (www.croftpoles.co.nz) are a wholly legitimate business based in Whangarei, New Zealand. This is a fake offer that falsely used Croft Pole's name in order to recruit into a &lt;a href="http://www.dynamoo.com/blog/labels/Money%20Mule.html"&gt;money mule scam&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Subject:       Online Job Offer&lt;br /&gt;From:       "Croft Pole Distributors Limited" &amp;lt;croftpole.update@gmail.com&amp;gt;&lt;br /&gt;Date:       Fri, January 15, 2010 10:52 am&lt;br /&gt;&lt;br /&gt;Dear Sir/Ma,&lt;br /&gt;&lt;br /&gt;Croft Timber Company Limited is a family owned business that began in 1905 and is still in Croft family hands today.&lt;br /&gt;&lt;br /&gt;CTC moved more towards the specialised production of timber poles approximately 20 years ago and now trades locally as Croft Pole Distributors Limited with pole supply outlets in both Northland, Rodney and Auckland.&lt;br /&gt;&lt;br /&gt;Within the last ten years CTC has grown considerably with investments in a new and larger site, plant modernisation/expansion and the introduction of equipment such as the Bezner Rounding Machine, Fogarty Kiln, Automatic Stacker, Machine stress grader and edge tester, planer and dry-mill department as well as the constant replacement and upgrading of existing plant and machinery.&lt;br /&gt;&lt;br /&gt;The mill site is on about thirty acres of land with rail facilities adjacent and is approximately 25 minutes from the deep water port of Marsden Point. The plant ispresently capable of processing around 2,500-3,000 m3 per month.&lt;br /&gt;&lt;br /&gt;We are committed to customer service and our aim is to remain flexible to meet the ever changing market needs with product and service unparalleled in the timber pole industry to date..&lt;br /&gt;&lt;br /&gt;Most of our customers from Australia, Canada,United States &amp;amp; United Kingdom pay through various terms of payment which some are not negotiable here in New Zealand. This brings our quest to employ a credible and trustworthy fellow as our representative to coordinate our payments. This would not affect your present job but add more to your income.&lt;br /&gt;&lt;br /&gt;Being our representative and assisting us in processing the payments from our clients should earn you a commission of 10% of every payment you coordinate.&lt;br /&gt;&lt;br /&gt;Once we makes a sale we deliver the product to a customer (usually through UPS).The customer receives and check the products. After this has been done, the customer has to pay for the products. About 90 percent of our customers prefer to pay through Bank Wire Transfers or certified cheque. We have decided to open this new job position for solving this problem.&lt;br /&gt;&lt;br /&gt;Your tasks are;&lt;br /&gt;&lt;br /&gt;1. Receive payment from Customers through your Bank Accounts&lt;br /&gt;&lt;br /&gt;2. Deduct 10% which will be your percentage/pay on Payments processed&lt;br /&gt;&lt;br /&gt;3. Forward balance after deduction of percentage/pay to any of the offices you will be contacted to send payment to. (Payment is to forwarded by Local transfers (Western Union only). A local Money transfer takes barely hours, so it will give us a possibility to get customers payment almost immediately.&lt;br /&gt;&lt;br /&gt;For example you have got �50,000.00&lt;br /&gt;&lt;br /&gt;You take your income: �5,000.00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You will be able to operate with larger orders and you will be able to earn more.&lt;br /&gt;&lt;br /&gt;Our payments will be sent into your Bank account that you provided, deduct your 10%(Salary) and forward the balance to the company via Western Union only.&lt;br /&gt;&lt;br /&gt;We understand it is an unusual and incredible job position. This job takes only 3-7 hours per week.&lt;br /&gt;&lt;br /&gt;You Will have a lot of free time doing another job, you will get good income and regular job. But this job is very challenging and you should understand it. We are looking only for the worker who satisfies our requirements and will be an earnest assistant, We are glad to offer this job position to you. If you feel that you are serious about this and be an earnest worker, All we will need for recording you to our database is below:&lt;br /&gt;&lt;br /&gt;Full Name:-&lt;br /&gt;Address:- &lt;br /&gt;Age:-&lt;br /&gt;Your Phone Number(s):-&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Chris Moyle&lt;br /&gt;Branch Manager&lt;br /&gt;Croft Pole Distributors Limited&lt;br /&gt;www.croftpoles.co.nz&lt;/blockquote&gt;The reply-to address is croftpole.update@gmail.com rather than croftpoles.co.nz, originating IP is 213.132.197.149 in the Netherlands, which hosts three porn sites but has probably been compromised. It is nothing at all to do with Croft Poles.&lt;br /&gt;&lt;br /&gt;Of course, this 10% fee is a "too good to be true" scam which could well wind up with you going to prison, so it should be avoided at all costs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-6970233298128652146?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/6970233298128652146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=6970233298128652146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6970233298128652146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6970233298128652146'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/croft-pole-distributors-limited-bogus.html' title='&quot;Croft Pole Distributors Limited&quot;  bogus job offer'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-2301879304595633159</id><published>2010-01-15T00:11:00.003Z</published><updated>2010-01-15T00:27:48.262Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Aurora'/><title type='text'>Aurora</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/aurora-728789.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 150px;" src="http://www.dynamoo.com/blog/uploaded_images/aurora-728770.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;a href="http://siblog.mcafee.com/cto/operation-%E2%80%9Caurora%E2%80%9D-hit-google-others/"&gt;According to McAfee&lt;/a&gt;, the attack on Google and several other tech companies that led to the &lt;a href="http://www.dynamoo.com/blog/2010/01/google-to-quit-china.html"&gt;likelihood that Google will quit China&lt;/a&gt; was called "Aurora" by the bad guys.&lt;br /&gt;&lt;br /&gt;The cruiser "&lt;a href="http://en.wikipedia.org/wiki/Russian_cruiser_Aurora"&gt;Aurora&lt;/a&gt;" signalled the start of the Russian Revolution in St Petersburg in 1917.. I wonder if this name was chosen deliberately when the attackers targeted some of the West's biggest tech companies?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://en.wikipedia.org/wiki/File:Aurora_Cruiser_Museum_StPetersburg.JPG"&gt;Image source&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2301879304595633159?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/2301879304595633159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=2301879304595633159' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2301879304595633159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2301879304595633159'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/aurora.html' title='Aurora'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-6849601103915906672</id><published>2010-01-14T23:42:00.003Z</published><updated>2010-01-14T23:55:32.777Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='Malvertising'/><title type='text'>More malvertisment domains</title><content type='html'>The malicious ads were running through (and I understand now terminated by) bootcampmedia.com, related to &lt;a href="http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html"&gt;this post&lt;/a&gt;, according to commenter &lt;span style="font-weight: bold;"&gt;cerdo&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Blogger cerdo said...&lt;br /&gt;&lt;br /&gt;    bootcampmedia.com was also likely hosting a malicious campaign yesterday afternoon, and perhaps still ongoing. I'd contact you Jamie, but I don't have contact info for you. This all is clearly closely related to Dynamoo's post...&lt;br /&gt;&lt;br /&gt;    traffic.worldseescolor.com is an obvious bad actor. The other related domains:&lt;br /&gt;    deliver.bailagequinismregrow.com&lt;br /&gt;    img.bailagequinismregrow.com&lt;br /&gt;    content.cabullacoexertstephen.com&lt;br /&gt;&lt;br /&gt;    as well as:&lt;br /&gt;    aanserver88.com&lt;br /&gt;    bonnapet.com&lt;br /&gt;    afkenai.com&lt;br /&gt;    bfskul.com&lt;br /&gt;&lt;br /&gt;    14 January 2010 18:40&lt;br /&gt;     &lt;br /&gt;Blogger cerdo said...&lt;br /&gt;&lt;br /&gt;    Yep - saw traffic.worldseescolor.com via bootcamp again less than 30 minutes ago.&lt;br /&gt;&lt;br /&gt;    Related sites, accessed immediately after traffic.worldseescolor.com:&lt;br /&gt;&lt;br /&gt;    deliver.boaterdunnagechicot.com&lt;br /&gt;    img.boaterdunnagechicot.com&lt;br /&gt;&lt;br /&gt;    14 January 2010 18:45&lt;/blockquote&gt;Worth checking your logs for and blocking in case they turn up on another network. Checking IPs comes up with:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;traffic.worldseescolor.com&lt;/span&gt;&lt;br /&gt;69.164.215.208, 69.164.215.210, 69.164.215.205, 69.164.215.207, 69.164.215.204 [Linode]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;deliver.bailagequinismregrow.com&lt;/span&gt;&lt;br /&gt;74.207.232.205, 74.207.232.250, 74.207.232.249, 74.207.232.248, 74.207.232.203, 74.207.232.30, 74.207.232.206, 74.207.232.31, 74.207.232.39, 74.207.232.25, 74.207.232.202, 74.207.232.35 [Linode]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;img.bailagequinismregrow.com&lt;/span&gt;&lt;br /&gt;174.143.243.220, 98.129.238.102, 98.129.238.106, 98.129.236.239, 174.143.245.236, 98.129.237.14, 174.143.242.109, 174.143.243.90, 98.129.236.154, 98.129.238.101, 98.129.238.112, 98.129.236.254, 174.143.241.174, 98.129.238.105, 98.129.238.103, 174.143.243.162, 174.143.242.58, 98.129.238.99&lt;br /&gt;[Slicehost / Rackspace]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;content.cabullacoexertstephen.com&lt;/span&gt;&lt;br /&gt;69.164.196.55 [Linode]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;aanserver88.com&lt;/span&gt;&lt;br /&gt;67.225.149.152 [Liquid Web]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;bonnapet.com&lt;/span&gt;&lt;br /&gt;Was 217.20.114.40 [Netdirekt / internetserviceteam.com] now appears to be down.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;afkenai.com&lt;/span&gt;&lt;br /&gt;195.2.253.93 [Madet Ltd, Moscow]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;bfskul.com&lt;/span&gt;&lt;br /&gt;195.2.253.93 [Madet Ltd, Moscow]&lt;br /&gt;&lt;br /&gt;I don't have the full trace of these, so it's not exactly clear what these domains are doing in the reported chain.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-6849601103915906672?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/6849601103915906672/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=6849601103915906672' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6849601103915906672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/6849601103915906672'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/more-malvertisment-domains.html' title='More malvertisment domains'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-717720218891892585</id><published>2010-01-14T16:29:00.001Z</published><updated>2010-01-14T16:31:15.521Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Zbot'/><title type='text'>More malicious OWA domains</title><content type='html'>In addition to &lt;a href="http://www.dynamoo.com/blog/2010/01/convincing-look-owa-fake-leads-to-pdf.html"&gt;these&lt;/a&gt; and &lt;a href="http://www.dynamoo.com/blog/2010/01/and-theres-more.html"&gt;these.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;yht30.net.pl&lt;/li&gt;&lt;li&gt;yht36.com.pl&lt;/li&gt;&lt;li&gt;yht37.com.pl&lt;/li&gt;&lt;li&gt;yht38.com.pl&lt;/li&gt;&lt;li&gt;yht39.net.pl&lt;/li&gt;&lt;li&gt;yht3e.net.pl&lt;/li&gt;&lt;li&gt;yht3q.net.pl&lt;/li&gt;&lt;li&gt;yht3r.pl&lt;/li&gt;&lt;li&gt;yht3t.pl&lt;/li&gt;&lt;li&gt;yht3w.net.pl&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-717720218891892585?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/717720218891892585/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=717720218891892585' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/717720218891892585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/717720218891892585'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/more-malicious-owa-domains.html' title='More malicious OWA domains'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-321881231200464895</id><published>2010-01-13T17:16:00.000Z</published><updated>2010-01-13T17:17:35.630Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Zbot'/><title type='text'>And there's more..</title><content type='html'>More domains relating to &lt;a href="http://www.dynamoo.com/blog/2010/01/convincing-look-owa-fake-leads-to-pdf.html"&gt;this Zbot attack&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;ui7772.co.kr&lt;/li&gt;&lt;li&gt;ui7772.kr&lt;/li&gt;&lt;li&gt;ui7772.ne.kr&lt;/li&gt;&lt;li&gt;ui7772.or.kr&lt;/li&gt;&lt;li&gt;ui7772co.kr&lt;/li&gt;&lt;li&gt;ui777f.kr&lt;/li&gt;&lt;li&gt;ui777f.ne.kr&lt;/li&gt;&lt;li&gt;ui777f.or.kr&lt;/li&gt;&lt;li&gt;ui777for.kr&lt;/li&gt;&lt;li&gt;ui777l.co.kr&lt;/li&gt;&lt;li&gt;ui777l.co.kr&lt;/li&gt;&lt;li&gt;ui777lco.kr&lt;/li&gt;&lt;li&gt;ui777p.co.kr&lt;/li&gt;&lt;li&gt;ui777p.kr&lt;/li&gt;&lt;li&gt;ui777p.or.kr&lt;/li&gt;&lt;li&gt;vcrtp.eu&lt;/li&gt;&lt;li&gt;vcrtp1.eu&lt;/li&gt;&lt;li&gt;vcrtp21.eu&lt;/li&gt;&lt;li&gt;vcrtprsa21.eu&lt;/li&gt;&lt;li&gt;vcrtps21.eu&lt;/li&gt;&lt;li&gt;vcrtpsa21.eu&lt;/li&gt;&lt;li&gt;vcrtrsa21.eu&lt;/li&gt;&lt;li&gt;vcrtrsr21.eu&lt;/li&gt;&lt;li&gt;vcrtrsrp2.eu&lt;/li&gt;&lt;li&gt;vcrtrsrp21.eu&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-321881231200464895?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/321881231200464895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=321881231200464895' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/321881231200464895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/321881231200464895'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/and-theres-more.html' title='And there&apos;s more..'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-1056829549572061358</id><published>2010-01-13T13:50:00.003Z</published><updated>2010-01-13T14:17:56.373Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='PDFs'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Zbot'/><category scheme='http://www.blogger.com/atom/ns#' term='OWA'/><title type='text'>Convincing look OWA fake leads to PDF exploit</title><content type='html'>There are getting spammed out at the moment:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;From: automailer@blahblah.blah [mailto:automailer@blahblah.blah]&lt;br /&gt;Sent: 13 January 2010 11:08&lt;br /&gt;To: Victim Username&lt;br /&gt;Subject: The settings for the username@blahblah.blah mailbox were changed&lt;br /&gt;&lt;br /&gt;Dear user of the blahblah.blah mailing service!&lt;br /&gt;&lt;br /&gt;We are informing you that because of the security upgrade of the mailing service your mailbox (username@blahblah.blah) settings were changed. In order to apply the new set of settings click on the following link:&lt;br /&gt;&lt;br /&gt;http://blahblah.blah/owa/service_directory/settings.php?email=username@blahblah.blah&amp;amp;from=blahblah.blah&amp;amp;fromname=username&lt;br /&gt;&lt;br /&gt;Best regards, blahblah.blah Technical Support.&lt;br /&gt;&lt;br /&gt;Letter ID#NGTS7OTY8XPZX8FEUYTTTZ1PF&lt;/blockquote&gt;&lt;br /&gt;The displayed link isn't the actual link, underneath it points to something like:&lt;br /&gt;http://blahblah.blah.vcrtp21.eu/owa/service_directory/settings.php?email=username@blahblah.bah&amp;amp;from=blahblah.blah&amp;amp;fromname=username&lt;br /&gt;&lt;br /&gt;Clicking through the link takes you to a convincing looking OWA (Outlook Web Access) forgery page, populated with the victim's domain name and email address.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/owa-fake-743453.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 269px; height: 320px;" src="http://www.dynamoo.com/blog/uploaded_images/owa-fake-743451.png" alt="" border="0" /&gt;&lt;/a&gt;There are two exploits on the page, the first one is a drive-by download of an infected PDF file called &lt;span style="font-weight: bold;"&gt;pdf.pdf&lt;/span&gt; for which VirusTotal detection is only &lt;a href="http://www.virustotal.com/analisis/8f15b24627621b74df7af103fe2fef9908728a3c0bd1a2afdf83947e980251cc-1263388778"&gt;10/41&lt;/a&gt;, detected by McAfee as Exploit-PDF.ac and various others. The executable file you are directed to download is also a &lt;a href="http://www.virustotal.com/analisis/d62d93ffa6f091db355e56b6db6bce9cdf683e34256d734b7c9ec6321ad917e8-1263391185"&gt;bit patchy on detections&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Sender names include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;operator@&lt;/li&gt;&lt;li&gt;support@&lt;/li&gt;&lt;li&gt;notifications@&lt;/li&gt;&lt;li&gt;no-reply@&lt;/li&gt;&lt;li&gt;system@&lt;/li&gt;&lt;li&gt;alert@&lt;/li&gt;&lt;li&gt;info@&lt;/li&gt;&lt;/ul&gt;..all on your local domain, obviously.&lt;br /&gt;&lt;br /&gt;Subjects include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The settings for the blah@blah.blah mailbox were changed&lt;/li&gt;&lt;li&gt;The settings for the blah@blah.blah were changed&lt;/li&gt;&lt;li&gt;A new settings file for the blah@blah.blah mailbox&lt;/li&gt;&lt;li&gt;A new settings file for the blah@blah.blah has just been released&lt;/li&gt;&lt;li&gt;For the owner of the blah@blah.blah e-mail account&lt;/li&gt;&lt;li&gt;For the owner of the blah@blah.blah mailbox&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Some domains in use on this are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;vcrtp1.eu&lt;/li&gt;&lt;li&gt;vcrtp21.eu&lt;/li&gt;&lt;li&gt;vcrtprsa21.eu&lt;/li&gt;&lt;li&gt;vcrtpsa21.eu&lt;/li&gt;&lt;li&gt;vcrtrsa21.eu&lt;/li&gt;&lt;li&gt;vcrtrsr21.eu&lt;/li&gt;&lt;li&gt;vcrtrsrp2.eu&lt;/li&gt;&lt;li&gt;vcrtrsrp21.eu&lt;/li&gt;&lt;/ul&gt;..there are probably many more of a similar pattern.&lt;br /&gt;&lt;br /&gt;WHOIS details are fake:&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Name:&lt;br /&gt;Quezada, Ramon&lt;br /&gt;Address:&lt;br /&gt;1800 N. Bayshore Drive&lt;br /&gt;33132 Roma&lt;br /&gt;Roma&lt;br /&gt;Italy&lt;br /&gt;Email:&lt;br /&gt;wawddhaepny@yahoo.com&lt;/blockquote&gt;Domains are on a fast flux botnet, so there's no point listing IPs. However, nameservers are as follows:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ns1.raddoor.com&lt;/span&gt;&lt;br /&gt;84.243.201.159 [Netrouting Data Facilities, Amsterdam]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ns2.raddoor.com&lt;/span&gt;&lt;br /&gt;71.123.51.158 [Verizon Internet Services Inc, Aston]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ns1.elkins-realty.net&lt;/span&gt;&lt;br /&gt;84.243.201.159 [Netrouting Data Facilities, Amsterdam]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ns2.elkins-realty.net&lt;/span&gt;&lt;br /&gt;71.123.17.61 [Verizon Internet Services Inc, Whitesboro]&lt;br /&gt;&lt;br /&gt;Registrant details for raddoor.com are probably bogus:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;        edmund pang figarro77@gmail.com&lt;br /&gt;        751 kinau st. #30&lt;br /&gt;        honolulu&lt;br /&gt;        HI&lt;br /&gt;        96813&lt;br /&gt;        US&lt;br /&gt;        Phone: +1.8085362450&lt;/blockquote&gt;Registration details for elkins-realty.net are DEFINITELY bogus:&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;  Name           : B O&lt;br /&gt;  Organization   : B O&lt;br /&gt;  Address        : 123 elm str.&lt;br /&gt;  City           : Los Angeles&lt;br /&gt;  Province/State : beijing&lt;br /&gt;  Country        :&lt;br /&gt;  Postal Code    : 23456&lt;br /&gt;  Phone Number   : 86--8586104812&lt;br /&gt;  Fax            : 86--8586104819&lt;br /&gt;  Email          : BO.la@yahoo.com&lt;/blockquote&gt;Once your machine is infected, it probably gets infected with a Zbot variant as in these two &lt;a href="http://www.dynamoo.com/blog/2009/11/please-update-your-blahblahblab-mailbox.html"&gt;previous&lt;/a&gt; &lt;a href="http://www.dynamoo.com/blog/2009/11/supportnachaorg-please-review.html"&gt;examples&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-1056829549572061358?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/1056829549572061358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=1056829549572061358' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1056829549572061358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1056829549572061358'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/convincing-look-owa-fake-leads-to-pdf.html' title='Convincing look OWA fake leads to PDF exploit'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-7438383861436542834</id><published>2010-01-13T10:06:00.002Z</published><updated>2010-01-13T10:24:02.858Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Bootcampmedia.com'/><category scheme='http://www.blogger.com/atom/ns#' term='Malvertising'/><category scheme='http://www.blogger.com/atom/ns#' term='netdirekt e.K.'/><category scheme='http://www.blogger.com/atom/ns#' term='internetserviceteam.com'/><title type='text'>More on malvertisements running through Bootcampmedia.com</title><content type='html'>Sandi at &lt;a href="http://msmvps.com/blogs/spywaresucks/Default.aspx"&gt;Spyware Sucks&lt;/a&gt; has &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2010/01/13/1751372.aspx"&gt;a closer look&lt;/a&gt; at the malvertisements running through Bootcampmedia.com and comes up with some more details, following up from &lt;a href="http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html"&gt;this post&lt;/a&gt;  yesterday.&lt;br /&gt;&lt;br /&gt;In this case the endpoint of the infection has switched to &lt;span style="font-weight: bold;"&gt;bonnapet.com&lt;/span&gt; hosted on          217.20.114.40        which is hosted by &lt;span style="font-weight: bold;"&gt;netdirekt e.K.&lt;/span&gt; / &lt;span style="font-weight: bold;"&gt;internetserviceteam.com&lt;/span&gt;, hardly surprising as they are one of the &lt;a href="http://www.google.com/cse?cx=002208759246055724436%3Aw7urz92c-5e&amp;amp;ie=UTF-8&amp;amp;q=netdirekt+e.K.&amp;amp;sa=Search"&gt;more common havens for crimeware&lt;/a&gt;.  The internetserviceteam.com name appears to be a sub-brand used for &lt;a href="http://www.mywot.com/en/scorecard/internetserviceteam.com"&gt;black hat hosting&lt;/a&gt; .. perhaps it is time for a visit from the &lt;a href="http://www.bundespolizei.de/cln_109/DE/Home/home__node.html?__nnn=true"&gt;Bundespolizei&lt;/a&gt;?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7438383861436542834?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/7438383861436542834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=7438383861436542834' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7438383861436542834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7438383861436542834'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/more-on-malvertisements-running-through.html' title='More on malvertisements running through Bootcampmedia.com'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-9172778222827724603</id><published>2010-01-13T09:48:00.002Z</published><updated>2010-01-13T09:52:45.497Z</updated><title type='text'>Google to quit China?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://upload.wikimedia.org/wikipedia/en/a/a9/Network12.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 240px; height: 180px;" src="http://upload.wikimedia.org/wikipedia/en/a/a9/Network12.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;"We're mad as hell and we're not going to take this any more!"&lt;br /&gt;&lt;br /&gt;More &lt;a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html"&gt;here&lt;/a&gt; and &lt;a href="http://googleenterprise.blogspot.com/2010/01/keeping-your-data-safe.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 204, 204);font-size:85%;" &gt;&lt;a href="http://en.wikipedia.org/wiki/File:Network12.jpg"&gt;Image credit&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-9172778222827724603?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/9172778222827724603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=9172778222827724603' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/9172778222827724603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/9172778222827724603'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/google-to-quit-china.html' title='Google to quit China?'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-7956229381597188399</id><published>2010-01-12T10:53:00.005Z</published><updated>2010-01-12T12:33:50.101Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='firedogred.com'/><category scheme='http://www.blogger.com/atom/ns#' term='Boot Camp Media'/><category scheme='http://www.blogger.com/atom/ns#' term='Viruses'/><category scheme='http://www.blogger.com/atom/ns#' term='Malvertising'/><title type='text'>BoingBoing.net / Bootcampmedia.com ad leads to malware</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/img-754338.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 80px; height: 400px;" src="http://www.dynamoo.com/blog/uploaded_images/img-754336.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;A malicious ad running on&lt;span style="font-weight: bold;"&gt; BoingBoing.net&lt;/span&gt; is delivering visitors to a PDF exploit.&lt;br /&gt;&lt;br /&gt;Given the complicated state of advertising arbitrage, it is unlikely that BoingBoing.net have much control over it. The ad appears to be loading in from ad.yieldmanager.com (which is Yahoo!)  and/or ad.z5x.net (DSNR Media Group) both of which are hosted on the same multihomed IP addresses.&lt;br /&gt;&lt;br /&gt;The ad itself (pictured) appears to be some sort of get-rich-quick scheme or other.&lt;br /&gt;&lt;br /&gt;This ad then directs through &lt;span style="font-weight: bold;"&gt;ads.bootcampmedia.com&lt;/span&gt;/servlet/ajrotator/790744/0/vh?z=BootCamp&amp;amp;dim=335848 to &lt;span style="font-weight: bold;"&gt;traffic.firedogred.com&lt;/span&gt;/content?campaign=1219131&amp;amp;sz=2 (this combination of bootcampmedia.com and firedogred.com has been &lt;a href="http://www.dynamoo.com/blog/2009/10/suspect-ad-network-leads-to-pdf-exploit.html"&gt;noted before&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;The ad then hops to &lt;span style="font-weight: bold;"&gt;deliver.amerchibchapowered.com&lt;/span&gt;/rotate?m=5;b=2;c=1;z=243826 then &lt;span style="font-weight: bold;"&gt;content.baalcootymalachi.com&lt;/span&gt;/track/3388182/S_SE?&lt;span style="font-style: italic;"&gt;[snip]&lt;/span&gt; loading an image from &lt;span style="font-weight: bold;"&gt;img.amerchibchapowered.com&lt;/span&gt; along the way.&lt;br /&gt;&lt;br /&gt;Finally, the visitor is directed to &lt;span style="font-weight: bold;"&gt;chohivyb.info&lt;/span&gt;/cgi-bin/aer/&lt;span style="font-style: italic;"&gt;[snip]&lt;/span&gt; which contains an exploit detected as &lt;a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojpdfjsgi.html?_log_from=rss"&gt;Troj/PDFJs-GI&lt;/a&gt; by Sophos.&lt;br /&gt;&lt;br /&gt;"Boot Camp Media" is run by a guy called &lt;a href="http://twitter.com/jdalgetty"&gt;Jamie Dalgetty&lt;/a&gt; of Guelph, Ontario in Canada. It's unlikely that he's a bad guy, more likely that his ad network is being exploited by a malcious third party.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;traffic.firedogred.com&lt;/span&gt; is rather more interesting, multihomed on  69.164.215.204, 69.164.215.205,  69.164.215.207,  69.164.215.208 and 69.164.215.210 at Linode, New Jersey. The domain firedogred.com is slightly interesting:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Registrant:&lt;br /&gt;Domain Owner&lt;br /&gt;15156 SW 5th&lt;br /&gt;Scottsdale, Arizona 85260&lt;br /&gt;United States&lt;br /&gt;&lt;br /&gt;Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)&lt;br /&gt;&lt;br /&gt;Domain Name: FIREDOGRED.COM&lt;br /&gt;  Created on: 15-Sep-09&lt;br /&gt;  Expires on: 15-Sep-10&lt;br /&gt;  Last Updated on: 15-Sep-09&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;  Owner, Domain  trafficbuyer@gmail.com&lt;br /&gt;  15156 SW 5th&lt;br /&gt;  Scottsdale, Arizona 85260&lt;br /&gt;  United States&lt;br /&gt;  (800) 555-1212      Fax --&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;  Owner, Domain  trafficbuyer@gmail.com&lt;br /&gt;  15156 SW 5th&lt;br /&gt;  Scottsdale, Arizona 85260&lt;br /&gt;  United States&lt;br /&gt;  (800) 555-1212      Fax --&lt;br /&gt;&lt;br /&gt;Domain servers in listed order:&lt;br /&gt;  NS57.DOMAINCONTROL.COM&lt;br /&gt;  NS58.DOMAINCONTROL.COM&lt;/blockquote&gt;trafficbuyer@gmail.com has been used for these malicious domains for &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/09/20/1725131.aspx"&gt;some months&lt;/a&gt; and is &lt;a href="http://www.google.com/search?hl=en&amp;amp;q=%22trafficbuyer%40gmail.com%22&amp;amp;btnG=Search&amp;amp;meta=&amp;amp;aq=f&amp;amp;oq="&gt;well known&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;deliver.amerchibchapowered.com &lt;/span&gt;is also multihomed at Linode on  74.207.232.250, 74.207.232.25, 74.207.232.30, 74.207.232.31, 74.207.232.35, 74.207.232.39, 74.207.232.202, 74.207.232.203, 74.207.232.205, 74.207.232.206, 74.207.232.248 and 74.207.232.249. The domain was registered on 7th January 2010 and is hidden by DomainsByProxy.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;content.baalcootymalachi.com&lt;/span&gt; is hosted on 69.164.196.55 at Linode again, again registered on 7th January via DomainsByProxy.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;img.amerchibchapowered.com&lt;/span&gt; is hosted on a large number of servers at 174.143.243.90, 174.143.243.162, 174.143.243.220, 174.143.245.236, 98.129.236.154, 98.129.236.239, 98.129.236.254, 98.129.237.14, 98.129.238.99, 98.129.238.101, 98.129.238.102, 98.129.238.103, 98.129.238.105, 98.129.238.106, 98.129.238.112, 174.143.241.174, 174.143.242.58, 174.143.242.109 - these are all hosted at Slicehost.com which is a customer of Rackspace.&lt;br /&gt;&lt;br /&gt;Finally, &lt;span style="font-weight: bold;"&gt;chohivyb.info&lt;/span&gt; is hosted on 216.150.79.74 which is some outfit called ezzi.net of New York owned by another outfit called AccessIT. No prizes for guessing that chohivyb.info has been registered only very recently with anonymous details.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;216.150.79.74&lt;/span&gt; is a &lt;a href="http://www.google.com/search?&amp;amp;q=216.150.79.74"&gt;well-known malware server&lt;/a&gt;, and that hosts the following domains which you can assume are malicious:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Ablxsr.info&lt;/li&gt;&lt;li&gt;Ajgdrt.info&lt;/li&gt;&lt;li&gt;Alevfq.info&lt;/li&gt;&lt;li&gt;Alfwqr.info&lt;/li&gt;&lt;li&gt;Alrpsl.info&lt;/li&gt;&lt;li&gt;Ameronada.info&lt;/li&gt;&lt;li&gt;Bnzbfz.info&lt;/li&gt;&lt;li&gt;Bodxmt.info&lt;/li&gt;&lt;li&gt;Bplimo.info&lt;/li&gt;&lt;li&gt;Briliantio.info&lt;/li&gt;&lt;li&gt;Bvqlag.info&lt;/li&gt;&lt;li&gt;Bzjsqk.info&lt;/li&gt;&lt;li&gt;Ccwarj.info&lt;/li&gt;&lt;li&gt;Cityopicos.info&lt;/li&gt;&lt;li&gt;Clthth.info&lt;/li&gt;&lt;li&gt;Ctksji.info&lt;/li&gt;&lt;li&gt;Dasyxe.info&lt;/li&gt;&lt;li&gt;Dbivoh.info&lt;/li&gt;&lt;li&gt;Dgltup.info&lt;/li&gt;&lt;li&gt;Dpuefh.info&lt;/li&gt;&lt;li&gt;Dtjblp.info&lt;/li&gt;&lt;li&gt;Enhmqq.info&lt;/li&gt;&lt;li&gt;Enqpqk.info&lt;/li&gt;&lt;li&gt;Euespj.info&lt;/li&gt;&lt;li&gt;Exmxfd.info&lt;/li&gt;&lt;li&gt;Fblooe.info&lt;/li&gt;&lt;li&gt;Fdwghs.info&lt;/li&gt;&lt;li&gt;Fopqde.info&lt;/li&gt;&lt;li&gt;Fprvsu.info&lt;/li&gt;&lt;li&gt;Frgbat.info&lt;/li&gt;&lt;li&gt;Fymjjz.info&lt;/li&gt;&lt;li&gt;Gelvmf.info&lt;/li&gt;&lt;li&gt;Gnautw.info&lt;/li&gt;&lt;li&gt;Gnysgg.info&lt;/li&gt;&lt;li&gt;Gredotcom.info&lt;/li&gt;&lt;li&gt;Grupodanot.info&lt;/li&gt;&lt;li&gt;Grxqog.info&lt;/li&gt;&lt;li&gt;Gukuny.info&lt;/li&gt;&lt;li&gt;Gyckjq.info&lt;/li&gt;&lt;li&gt;Hagijd.info&lt;/li&gt;&lt;li&gt;Haqdsc.info&lt;/li&gt;&lt;li&gt;Hgtbng.info&lt;/li&gt;&lt;li&gt;Hjdnps.info&lt;/li&gt;&lt;li&gt;Hyiyyi.info&lt;/li&gt;&lt;li&gt;Iakecg.info&lt;/li&gt;&lt;li&gt;Iaoaxz.info&lt;/li&gt;&lt;li&gt;Iewwpn.info&lt;/li&gt;&lt;li&gt;Ijaflj.info&lt;/li&gt;&lt;li&gt;Iohbvo.info&lt;/li&gt;&lt;li&gt;Jhrubd.info&lt;/li&gt;&lt;li&gt;Jokirator.info&lt;/li&gt;&lt;li&gt;Kbwstb.info&lt;/li&gt;&lt;li&gt;Kibfsz.info&lt;/li&gt;&lt;li&gt;Klamniton.info&lt;/li&gt;&lt;li&gt;Ktebkx.info&lt;/li&gt;&lt;li&gt;Kxlglw.info&lt;/li&gt;&lt;li&gt;Leeloe.info&lt;/li&gt;&lt;li&gt;Lgcezx.info&lt;/li&gt;&lt;li&gt;Lkraat.info&lt;/li&gt;&lt;li&gt;Lktcaj.info&lt;/li&gt;&lt;li&gt;Llchqs.info&lt;/li&gt;&lt;li&gt;Lnmrjz.info&lt;/li&gt;&lt;li&gt;Lokitoreni.info&lt;/li&gt;&lt;li&gt;Lqhczk.info&lt;/li&gt;&lt;li&gt;Lywavy.info&lt;/li&gt;&lt;li&gt;Lyzocu.info&lt;/li&gt;&lt;li&gt;Mallstern.info&lt;/li&gt;&lt;li&gt;Manaratora.info&lt;/li&gt;&lt;li&gt;Megafrontan.info&lt;/li&gt;&lt;li&gt;Mesxql.info&lt;/li&gt;&lt;li&gt;Mngmjc.info&lt;/li&gt;&lt;li&gt;Monsatrik.info&lt;/li&gt;&lt;li&gt;Montrealt.info&lt;/li&gt;&lt;li&gt;Mruvienno.info&lt;/li&gt;&lt;li&gt;Mrvsnq.info&lt;/li&gt;&lt;li&gt;Nalszu.info&lt;/li&gt;&lt;li&gt;Ncnzfh.info&lt;/li&gt;&lt;li&gt;Neiaea.info&lt;/li&gt;&lt;li&gt;Nigrandara.info&lt;/li&gt;&lt;li&gt;Njcmug.info&lt;/li&gt;&lt;li&gt;Npmkrr.info&lt;/li&gt;&lt;li&gt;Ntaxkj.info&lt;/li&gt;&lt;li&gt;Obzdkn.info&lt;/li&gt;&lt;li&gt;Ocftfa.info&lt;/li&gt;&lt;li&gt;Optugj.info&lt;/li&gt;&lt;li&gt;Otfcco.info&lt;/li&gt;&lt;li&gt;Owpwhi.info&lt;/li&gt;&lt;li&gt;Pbrugb.info&lt;/li&gt;&lt;li&gt;Plxxii.info&lt;/li&gt;&lt;li&gt;Pncgfd.info&lt;/li&gt;&lt;li&gt;Ppusmb.info&lt;/li&gt;&lt;li&gt;Prbakn.info&lt;/li&gt;&lt;li&gt;Qdinql.info&lt;/li&gt;&lt;li&gt;Qgxelo.info&lt;/li&gt;&lt;li&gt;Qqtwft.info&lt;/li&gt;&lt;li&gt;Realuqitor.info&lt;/li&gt;&lt;li&gt;Refrentora.info&lt;/li&gt;&lt;li&gt;Retuvarot.info&lt;/li&gt;&lt;li&gt;Rfouce.info&lt;/li&gt;&lt;li&gt;Rljysj.info&lt;/li&gt;&lt;li&gt;Rocqdn.info&lt;/li&gt;&lt;li&gt;Roeaaj.info&lt;/li&gt;&lt;li&gt;Semqef.info&lt;/li&gt;&lt;li&gt;Snosrz.info&lt;/li&gt;&lt;li&gt;Spgsgh.info&lt;/li&gt;&lt;li&gt;Stqvqw.info&lt;/li&gt;&lt;li&gt;Swrapz.info&lt;/li&gt;&lt;li&gt;Tcoqgo.info&lt;/li&gt;&lt;li&gt;Tehfnn.info&lt;/li&gt;&lt;li&gt;Top-lister1.info&lt;/li&gt;&lt;li&gt;Transforltd.info&lt;/li&gt;&lt;li&gt;Tsfxzg.info&lt;/li&gt;&lt;li&gt;Tyenxv.info&lt;/li&gt;&lt;li&gt;Ugrdzf.info&lt;/li&gt;&lt;li&gt;Uliganoinc.info&lt;/li&gt;&lt;li&gt;Urupnk.info&lt;/li&gt;&lt;li&gt;Utpxno.info&lt;/li&gt;&lt;li&gt;Uyguau.info&lt;/li&gt;&lt;li&gt;Vbqfdm.info&lt;/li&gt;&lt;li&gt;Veqibp.info&lt;/li&gt;&lt;li&gt;Vkfaao.info&lt;/li&gt;&lt;li&gt;Vwwtlp.info&lt;/li&gt;&lt;li&gt;Wddifv.info&lt;/li&gt;&lt;li&gt;Wdhcvv.info&lt;/li&gt;&lt;li&gt;Wdokxd.info&lt;/li&gt;&lt;li&gt;Wevoratora.info&lt;/li&gt;&lt;li&gt;Wtstds.info&lt;/li&gt;&lt;li&gt;Wvkjxx.info&lt;/li&gt;&lt;li&gt;Wvlsam.info&lt;/li&gt;&lt;li&gt;Xbhmws.info&lt;/li&gt;&lt;li&gt;Xbxynl.info&lt;/li&gt;&lt;li&gt;Xcisup.info&lt;/li&gt;&lt;li&gt;Xxiyrv.info&lt;/li&gt;&lt;li&gt;Ybeaxd.info&lt;/li&gt;&lt;li&gt;Yfntrg.info&lt;/li&gt;&lt;li&gt;Yqjxkj.info&lt;/li&gt;&lt;li&gt;Ywbxen.info&lt;/li&gt;&lt;li&gt;Zdkaki.info&lt;/li&gt;&lt;li&gt;Zhwtqz.info&lt;/li&gt;&lt;li&gt;Zlpbha.info&lt;/li&gt;&lt;li&gt;Znkwjc.info&lt;/li&gt;&lt;li&gt;Zqpwco.info&lt;/li&gt;&lt;/ul&gt;Unlocker.org.uk is located on the same server, but it doesn't seem to fit in with the malware delivery and perhaps it is best to assume that it is a coincidence.&lt;br /&gt;&lt;br /&gt;Obviously block or null-route these destinations as you feel fit, and do not purchase any ads from&lt;span style="font-weight: bold;"&gt; firedogred.com&lt;/span&gt;!&lt;br /&gt;&lt;br /&gt;Added: You probably want to block these too..&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;216.150.79.76&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Cacorq.info&lt;/li&gt;&lt;li&gt;Clxhbz.info&lt;/li&gt;&lt;li&gt;Dgrxqh.info&lt;/li&gt;&lt;li&gt;Diwiowano.info&lt;/li&gt;&lt;li&gt;Dmdurz.info&lt;/li&gt;&lt;li&gt;Funkol.info&lt;/li&gt;&lt;li&gt;Geetol.info&lt;/li&gt;&lt;li&gt;Gitoer.info&lt;/li&gt;&lt;li&gt;Gondiroda.info&lt;/li&gt;&lt;li&gt;Gutrandin.info&lt;/li&gt;&lt;li&gt;Hizfek.info&lt;/li&gt;&lt;li&gt;Hopore.info&lt;/li&gt;&lt;li&gt;Ivgzda.info&lt;/li&gt;&lt;li&gt;Jopqae.info&lt;/li&gt;&lt;li&gt;Kolpao.info&lt;/li&gt;&lt;li&gt;Nadotraza.info&lt;/li&gt;&lt;li&gt;Niraynome.info&lt;/li&gt;&lt;li&gt;Ofahitino.info&lt;/li&gt;&lt;li&gt;Oirjsa.info&lt;/li&gt;&lt;li&gt;Ornotivec.info&lt;/li&gt;&lt;li&gt;Pirtaf.info&lt;/li&gt;&lt;li&gt;Popsto.info&lt;/li&gt;&lt;li&gt;Rellok.info&lt;/li&gt;&lt;li&gt;Ruhcsy.info&lt;/li&gt;&lt;li&gt;Sacmtf.info&lt;/li&gt;&lt;li&gt;Sdoras.info&lt;/li&gt;&lt;li&gt;Tapiroten.info&lt;/li&gt;&lt;li&gt;Tiizwb.info&lt;/li&gt;&lt;li&gt;Traxemere.info&lt;/li&gt;&lt;li&gt;Ulmqmq.info&lt;/li&gt;&lt;li&gt;Vivibt.info&lt;/li&gt;&lt;li&gt;Xsxydj.info&lt;/li&gt;&lt;li&gt;Yuncdjbiw.info&lt;/li&gt;&lt;li&gt;Yyoqny.info&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;216.150.79.77&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Bnodas.info&lt;/li&gt;&lt;li&gt;Brasilianstoree.info&lt;/li&gt;&lt;li&gt;Byzypub.info&lt;/li&gt;&lt;li&gt;Depahugu.info&lt;/li&gt;&lt;li&gt;Gionasodor.info&lt;/li&gt;&lt;li&gt;Giratunes.info&lt;/li&gt;&lt;li&gt;Gyreal.info&lt;/li&gt;&lt;li&gt;Hlopki.info&lt;/li&gt;&lt;li&gt;Huerin.info&lt;/li&gt;&lt;li&gt;Igerinsar.info&lt;/li&gt;&lt;li&gt;Jcafuzixa.info&lt;/li&gt;&lt;li&gt;Joketarona.info&lt;/li&gt;&lt;li&gt;Koevoru.info&lt;/li&gt;&lt;li&gt;L-iza.info&lt;/li&gt;&lt;li&gt;Laryju.info&lt;/li&gt;&lt;li&gt;Manocoraz.info&lt;/li&gt;&lt;li&gt;Nbuuf.info&lt;/li&gt;&lt;li&gt;Npefu.info&lt;/li&gt;&lt;li&gt;Nvihobepo.info&lt;/li&gt;&lt;li&gt;Pe-aqemop.info&lt;/li&gt;&lt;li&gt;Pyneh.info&lt;/li&gt;&lt;li&gt;Retiof.info&lt;/li&gt;&lt;li&gt;Rzajexu.info&lt;/li&gt;&lt;li&gt;Tolkienad.info&lt;/li&gt;&lt;li&gt;Tymane.info&lt;/li&gt;&lt;li&gt;Typolazu.info&lt;/li&gt;&lt;li&gt;Vfoxoe.info&lt;/li&gt;&lt;li&gt;Wanitale.info&lt;/li&gt;&lt;li&gt;Yawibyve.info&lt;/li&gt;&lt;li&gt;Ydiuvy.info&lt;/li&gt;&lt;li&gt;Zoimie.info&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7956229381597188399?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/7956229381597188399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=7956229381597188399' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7956229381597188399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7956229381597188399'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html' title='BoingBoing.net / Bootcampmedia.com ad leads to malware'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8291361401568814901</id><published>2010-01-07T13:22:00.002Z</published><updated>2010-01-07T13:26:46.448Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Job Offer Scams'/><category scheme='http://www.blogger.com/atom/ns#' term='German'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Mystery Shopper'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>"Testkauf" - German language "mystery shopper" scam</title><content type='html'>For some reason, I've been getting a lot of these German-language spams, mostly originating from Brazil..&lt;br /&gt;&lt;blockquote&gt;Subject: Testkauf&lt;br /&gt;&lt;br /&gt;Mitarbeiter fuer Testeinkauf bundesweit gesucht.&lt;br /&gt;Bewerbung bitte an blahblah@yahoo.de&lt;/blockquote&gt;This roughly translates as:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Subject: Test Shopping&lt;br /&gt;Searching nationwide for employees to do test purchasing.&lt;br /&gt;To apply, please contact blahblah@yahoo.de&lt;/blockquote&gt;In each case, the header contain a fake "from" address, the Yahoo! email address changes constantly.. and the mail seems to come from Brazil. This is most likely just a version of the &lt;a href="http://www.safefromscams.co.uk/MysteryShopperScam.html"&gt;mystery shopper scam&lt;/a&gt;, and should be avoided.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-8291361401568814901?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8291361401568814901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8291361401568814901' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8291361401568814901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8291361401568814901'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2010/01/testkauf-german-language-mystery.html' title='&quot;Testkauf&quot; - German language &quot;mystery shopper&quot; scam'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-7855330011785114247</id><published>2009-12-22T23:15:00.002Z</published><updated>2009-12-22T23:18:19.983Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dating Scams'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Pharma'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>mailbox-email.com scam</title><content type='html'>Part of a &lt;a href="http://www.dynamoo.com/blog/2009/12/freeemailnownet-scam.html"&gt;long running&lt;/a&gt; &lt;a href="http://www.dynamoo.com/blog/labels/Dating%20Scams.html"&gt;dating scam&lt;/a&gt;, mailbox-email.com looks like a free email service, but isn't. Hosted on 222.170.127.122  in China, the server also hosts various fake dating and prescription sites.&lt;br /&gt;&lt;br /&gt;All of these following sites are some scam or another, avoid them:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Adltfuntime.com&lt;/li&gt;&lt;li&gt;Adultmeetspot.com&lt;/li&gt;&lt;li&gt;Amazmail.com&lt;/li&gt;&lt;li&gt;Aprofilepage.com&lt;/li&gt;&lt;li&gt;Blowingawaytherestnow.com&lt;/li&gt;&lt;li&gt;Email-mailbox.com&lt;/li&gt;&lt;li&gt;Findallthebestherenow.com&lt;/li&gt;&lt;li&gt;Findnewfriend.net&lt;/li&gt;&lt;li&gt;Free-email-chat.com&lt;/li&gt;&lt;li&gt;Free-email-connect.com&lt;/li&gt;&lt;li&gt;Free-email-fun.com&lt;/li&gt;&lt;li&gt;Free-email-live.com&lt;/li&gt;&lt;li&gt;Freeextender.net&lt;/li&gt;&lt;li&gt;Freemailaccounts.net&lt;/li&gt;&lt;li&gt;Freemailnow.net&lt;/li&gt;&lt;li&gt;Getitatrxcenternow.com&lt;/li&gt;&lt;li&gt;Greatestofrxznow.com&lt;/li&gt;&lt;li&gt;Happeningrxcenternow.com&lt;/li&gt;&lt;li&gt;Hotlivemailchat.com&lt;/li&gt;&lt;li&gt;Kingofthekingofrxznow.com&lt;/li&gt;&lt;li&gt;Myemailhome.net&lt;/li&gt;&lt;li&gt;Netherlandsdns.com&lt;/li&gt;&lt;li&gt;Nodocneededforrxmedznow.com&lt;/li&gt;&lt;li&gt;Plygroundadlt.com&lt;/li&gt;&lt;li&gt;Realdealrxbrandnamesnow.com&lt;/li&gt;&lt;li&gt;Sexyhotlivechat.com&lt;/li&gt;&lt;li&gt;Skinny-me.info&lt;/li&gt;&lt;li&gt;Ysjhdfjd.com&lt;/li&gt;&lt;li&gt;Zeuhiuer.com&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7855330011785114247?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/7855330011785114247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=7855330011785114247' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7855330011785114247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7855330011785114247'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2009/12/mailbox-emailcom-scam.html' title='mailbox-email.com scam'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-1528781850454863802</id><published>2009-12-15T22:52:00.002Z</published><updated>2009-12-15T23:01:21.363Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Zero Day'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='Piradius.net'/><title type='text'>Piradius.Net / Adobe Zero-Day threat</title><content type='html'>Another good reason not to have Adobe Reader on your PC - the ISC is reporting yet another &lt;a href="http://isc.sans.org/diary.html?storyid=7747"&gt;zero-day threat&lt;/a&gt; being exploited by the bad guys, using the domain &lt;span style="font-weight: bold;"&gt;foruminspace.com.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;And guess who is hosting it.. yes, our old friends at &lt;a href="http://www.dynamoo.com/blog/labels/Piradius.net.html"&gt;Piradius.net&lt;/a&gt;, going to show just how dark grey their hat is and demonstrating another very good reason to block 124.217.224.0 - 124.217.255.255.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-1528781850454863802?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/1528781850454863802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=1528781850454863802' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1528781850454863802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/1528781850454863802'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2009/12/piradiusnet-adobe-zero-day-threat.html' title='Piradius.Net / Adobe Zero-Day threat'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-2853069941543166564</id><published>2009-12-05T13:32:00.002Z</published><updated>2009-12-05T13:55:10.543Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Dating Scams'/><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Fake Pharma'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>"freeemailnow.net" scam</title><content type='html'>The domain &lt;span style="font-weight: bold;"&gt;freeemailnow.net&lt;/span&gt; looks like.. well, it looks like a free e-mail provider. But it isn't, it's part of some sort of fraudulent scheme, most likely a &lt;a href="http://www.dynamoo.com/blog/labels/Dating%20Scams.html"&gt;dating scam&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The pitch arrives something like this:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Subject:       your profile&lt;br /&gt;From:       "Pasquale Clay"&lt;br /&gt;Date:       Fri, December 4, 2009 11:55 pm&lt;br /&gt;&lt;br /&gt;Hey!&lt;br /&gt;I know you dont know me, but I d like to get to know you.&lt;br /&gt;I stumbled upon your contact information, am looking for a chat friend and maybe more.&lt;br /&gt;Write me back at: snowfall1@freeemailnow.net&lt;br /&gt;&lt;br /&gt;i am anxious to talk with you&lt;/blockquote&gt;A look at the SOA records points to ns1.netherlandsdns.com and admin.affilnet.net - &lt;a href="http://www.dynamoo.com/blog/2009/11/warning-affilnetnet.html"&gt;affilnet.net is familiar&lt;/a&gt;, indicating that this is a re-run of the &lt;a href="http://www.dynamoo.com/blog/2009/11/warmfuzzylovecom-scam.html"&gt;warmfuzzylove.com scam&lt;/a&gt; but again annoyingly missing a picture of a &lt;a href="http://www.dynamoo.com/blog/2008/02/another-dating-scam.html"&gt;pretty Russian girl&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The registration details for &lt;span style="font-weight: bold;"&gt;freeemailnow.net&lt;/span&gt; are anonymous, nameservers are ns1.netherlandsdns.com and ns2.netherlandsdns.com, both on 222.170.127.122 in China along with freeemailnow.net itself.&lt;br /&gt;&lt;br /&gt;There's a bunch of fake pharma sites sharing the same server:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Acquireflowherenow.com&lt;/li&gt;&lt;li&gt;Acquirerxmedzherenow.com&lt;/li&gt;&lt;li&gt;Allthebestatyourfingertips.com&lt;/li&gt;&lt;li&gt;Alwaysbetterrx.com&lt;/li&gt;&lt;li&gt;Anyrxmedications.com&lt;/li&gt;&lt;li&gt;Beatingallcompetition.com&lt;/li&gt;&lt;li&gt;Besatifiedmedsnow.com&lt;/li&gt;&lt;li&gt;Bestrxbuyshere.com&lt;/li&gt;&lt;li&gt;Blowingawaytherestnow.com&lt;/li&gt;&lt;li&gt;Championrxsource.com&lt;/li&gt;&lt;li&gt;Cheapcodeines.com&lt;/li&gt;&lt;li&gt;Choosefr0mthebest.com&lt;/li&gt;&lt;li&gt;Codeineoffers.com&lt;/li&gt;&lt;li&gt;Codeinepromo.com&lt;/li&gt;&lt;li&gt;Crazymedsupplyforyou.com&lt;/li&gt;&lt;li&gt;Discount-codeine.com&lt;/li&gt;&lt;li&gt;Easyrxhere.com&lt;/li&gt;&lt;li&gt;Expressmedz4u.com&lt;/li&gt;&lt;li&gt;Findallthebestherenow.com&lt;/li&gt;&lt;li&gt;Fingtertiprxmedacces.com&lt;/li&gt;&lt;li&gt;Firerxmedication.com&lt;/li&gt;&lt;li&gt;Flowagerofgood.com&lt;/li&gt;&lt;li&gt;G00dsonline.com&lt;/li&gt;&lt;li&gt;Getallyourfavorites.com&lt;/li&gt;&lt;li&gt;Getitatrxcenternow.com&lt;/li&gt;&lt;li&gt;Getmedicatedonline.com&lt;/li&gt;&lt;li&gt;Getrxeasily.com&lt;/li&gt;&lt;li&gt;Getrxeasilyonline.com&lt;/li&gt;&lt;li&gt;Getrxmedicationsherenow.com&lt;/li&gt;&lt;li&gt;Goodzchoices.com&lt;/li&gt;&lt;li&gt;Greatestofrxznow.com&lt;/li&gt;&lt;li&gt;Greatmedicalshere.com&lt;/li&gt;&lt;li&gt;Greatrxdepot.com&lt;/li&gt;&lt;li&gt;Greatrxg00ds.com&lt;/li&gt;&lt;li&gt;Greatrxonline4u.com&lt;/li&gt;&lt;li&gt;Grillindealz4u.com&lt;/li&gt;&lt;li&gt;Happeninggoodtime.com&lt;/li&gt;&lt;li&gt;Happeningrxcenternow.com&lt;/li&gt;&lt;li&gt;Honorablechoice.com&lt;/li&gt;&lt;li&gt;Incrediblerx4u.com&lt;/li&gt;&lt;li&gt;Kingofthekingofrxznow.com&lt;/li&gt;&lt;li&gt;Maxsav3r.com&lt;/li&gt;&lt;li&gt;Maxsaverz.com&lt;/li&gt;&lt;li&gt;Meddiezcenter.com&lt;/li&gt;&lt;li&gt;Medzfromonlinetoyourhome.com&lt;/li&gt;&lt;li&gt;Mosthighlysoughtafter.com&lt;/li&gt;&lt;li&gt;Neverendingflowages.com&lt;/li&gt;&lt;li&gt;Neverwaitrx.com&lt;/li&gt;&lt;li&gt;Newrx4champions.com&lt;/li&gt;&lt;li&gt;Niceflowofmedz.com&lt;/li&gt;&lt;li&gt;Nodocneededforrxmedznow.com&lt;/li&gt;&lt;li&gt;Nomorewaitinginlinenow.com&lt;/li&gt;&lt;li&gt;Onpointflowage.com&lt;/li&gt;&lt;li&gt;Qualitycodeine.com&lt;/li&gt;&lt;li&gt;Quickrxmedications.com&lt;/li&gt;&lt;li&gt;Readysetgetmedz.com&lt;/li&gt;&lt;li&gt;Realdealrxbrandnames.com&lt;/li&gt;&lt;li&gt;Realdealrxbrandnamesnow.com&lt;/li&gt;&lt;li&gt;Realdealrxrefills.com&lt;/li&gt;&lt;li&gt;Refillrx-depot.com&lt;/li&gt;&lt;li&gt;Reliableflowagehere.com&lt;/li&gt;&lt;li&gt;Reliablemedsource4u.com&lt;/li&gt;&lt;li&gt;Reliablerx4uonline.com&lt;/li&gt;&lt;li&gt;Rightrxchoice.com&lt;/li&gt;&lt;li&gt;Rx-refilldepot.com&lt;/li&gt;&lt;li&gt;Rxmainsource.com&lt;/li&gt;&lt;li&gt;Rxmedsolution4unow.com&lt;/li&gt;&lt;li&gt;Rxmedzatthefingers.com&lt;/li&gt;&lt;li&gt;Rxmedzinnotime.com&lt;/li&gt;&lt;li&gt;Rxremedies4u.com&lt;/li&gt;&lt;li&gt;Rxthatbeatsallothers.com&lt;/li&gt;&lt;li&gt;Rxwindowonline.com&lt;/li&gt;&lt;li&gt;Rxsourceforwinners.com&lt;/li&gt;&lt;li&gt;Selectfromallthebestmeds.com&lt;/li&gt;&lt;li&gt;Selectionfromthebest.com&lt;/li&gt;&lt;li&gt;Simeplyarx.com&lt;/li&gt;&lt;li&gt;Smokingdealz4u.com&lt;/li&gt;&lt;li&gt;Swiftestmedz.com&lt;/li&gt;&lt;li&gt;Theeasyreliablesourcenow.com&lt;/li&gt;&lt;li&gt;Theflowageoccurshere.com&lt;/li&gt;&lt;li&gt;Themybetterrx.com&lt;/li&gt;&lt;li&gt;Toprxsuppliers.com&lt;/li&gt;&lt;li&gt;Toprxsupplierz.com&lt;/li&gt;&lt;li&gt;Uniqueflowagesnow.com&lt;/li&gt;&lt;li&gt;Wehaveallyourfavorites.com&lt;/li&gt;&lt;li&gt;Wehavethemforyou.com&lt;/li&gt;&lt;li&gt;Wehavewhaturlookingfornow.com&lt;/li&gt;&lt;li&gt;Wehavewhatyourlooking4.com&lt;/li&gt;&lt;li&gt;Your-rxs.com&lt;/li&gt;&lt;li&gt;Netherlandsdns.com&lt;/li&gt;&lt;/ul&gt;Anyway, this is the same old scam and it should be avoided along with the fake RX sites that go with it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2853069941543166564?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/2853069941543166564/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=2853069941543166564' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2853069941543166564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2853069941543166564'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2009/12/freeemailnownet-scam.html' title='&quot;freeemailnow.net&quot; scam'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-7440991569676163063</id><published>2009-12-03T22:39:00.002Z</published><updated>2009-12-03T22:44:03.802Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='Scams'/><title type='text'>"Bank of England" scam email</title><content type='html'>This is some sort of fraud or phishing attempt, the email originates from &lt;span style="font-weight: bold;"&gt;richardscott269@msn.com&lt;/span&gt; but solicits replies to &lt;span style="font-weight: bold;"&gt;richardscott555@rediffmail.com&lt;/span&gt; - both of these are free email providers, and I'm pretty sure that the Bank of England can afford its own email servers. Avoid.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;Subject:       Payment Notification&lt;br /&gt;From:       "Richard Scott" &amp;lt;richardscott269@msn.com&amp;gt;&lt;br /&gt;Date:       Thu, December 3, 2009 10:12 pm&lt;br /&gt;&lt;br /&gt;From: Richard Scott&lt;br /&gt;International Settlement Dept.&lt;br /&gt;Bank of England&lt;br /&gt;http://www.bankofengland.co.uk/&lt;br /&gt;Ref: BOE/ISD/ACD/4556/09&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ATTN :&lt;br /&gt;&lt;br /&gt;The International Settlement department of Bank of England is obligated to contact you for the immediate release of your fund whose account has be come dormant and subsequently transferred to this department as unclaimed fund.Our findings have revealed that the problem behind your inability to have received your fund from the corresponding bank resulted from lack of transparency, insincerity and incessant demand for money by your representative(s) for unusual payments. We have therefore decided to establish a direct transfer payment system (DIPS) with you for the prompt release of your funds without any hitch.&lt;br /&gt;&lt;br /&gt;We therefore request that you respond to this email immediately ( forwarding your direct contact telephone number) to enable us proceed with the release of your fund accordingly.&lt;br /&gt;&lt;br /&gt;Yours in service,&lt;br /&gt;Richard Scott.  &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-7440991569676163063?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/7440991569676163063/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=7440991569676163063' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7440991569676163063'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/7440991569676163063'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2009/12/bank-of-england-scam-email.html' title='&quot;Bank of England&quot; scam email'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-2031736005439189602</id><published>2009-12-02T22:15:00.002Z</published><updated>2009-12-02T22:55:07.211Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Spam'/><category scheme='http://www.blogger.com/atom/ns#' term='clickbank.eu'/><category scheme='http://www.blogger.com/atom/ns#' term='Incisive Media'/><title type='text'>Incisive Media / writeathomesystems.com spam</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Incisive Media&lt;/span&gt; is a little-known firm that comprises the rump of the much better known &lt;span style="font-weight: bold;"&gt;VNU Publications&lt;/span&gt; that was sold off into private equity a few years ago.&lt;br /&gt;&lt;br /&gt;You might know the name "Incisive Media" through their miserable failure to sustain &lt;a href="http://www.dynamoo.com/blog/2009/06/personal-computer-world-to-close.html"&gt;Personal Computer World&lt;/a&gt; which was one of the oldest computer magazines in the world, but they also own several other &lt;a href="http://en.wikipedia.org/wiki/Incisive_Media"&gt;professional publications&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So, I was a little surprised to see that Incisive now seems to be in the business of sending out get-rich-quick spam.&lt;br /&gt;&lt;blockquote&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;Subject:       Private Equity Europe&lt;br /&gt;From:       "Chesther Jane" &amp;lt;mcjane99@gmail.com&amp;gt;&lt;br /&gt;Date:       Wed, December 2, 2009 7:21 pm&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Respected Friends,&lt;br /&gt;“Who else wants to earn a full-time income writing on the INTERNET? You can start earning money writing online even if you have no prior experience.” If you can write at a 9th grade level, you could easily earn a full time income writing online.&lt;br /&gt;Companies are desperately looking for entry level writers. If you want to start&lt;br /&gt;earning money writing at home, this may be the most important page on the Internet you’ll read all year. Right now, you can make really good money, quickly and easily.&lt;br /&gt;http://miniurl.com/22939&lt;br /&gt;Chesther Jane&lt;br /&gt;to unsubscribe reply REMOVE&lt;br /&gt;&lt;br /&gt;Thank you for visiting my site!&lt;br /&gt;&lt;br /&gt;http://www.incisivemedia.com/public/showPage.html?page=330349&lt;br /&gt;&lt;br /&gt;DISCLAIMER&lt;br /&gt;Private Equity Europe and Incisive Media do not take any responsibility for the&lt;br /&gt;content of this email&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;The spam originates from 62.140.213.241 which is an Incisive Media IP address, and a close look at the mail headers shows more evidence:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Message-ID: &amp;lt;02 Dec 2009 19:21 IncisiveMailer@www.incisivemedia.com&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The URL &lt;span style="font-weight: bold;"&gt;miniurl.com/22939&lt;/span&gt; forwards to &lt;span style="font-weight: bold;"&gt;Caroline.mikepsanderswri.click2sell.eu&lt;/span&gt; which is a laughably pathetic work-at-home scheme on the click2sell.eu affiliate network. To give click2sell.eu some credit, they are pretty good at terminating spammers.. which is why spammers try to mask their affiliate URLs.&lt;br /&gt;&lt;br /&gt;I said "laughably pathetic", because you end up at &lt;span style="font-weight: bold;"&gt;writeathomesystems.com&lt;/span&gt; which attempts to recruit people to part with cold hard cash in order to learn how to write and market articles on the web.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/writeathomesystems-1-774814.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 364px; height: 400px;" src="http://www.dynamoo.com/blog/uploaded_images/writeathomesystems-1-774811.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Now, I'm not the best writer in the world.. and we all make tpyos now and again, but this one has a howler:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/writeathomesystems-2-724747.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 131px;" src="http://www.dynamoo.com/blog/uploaded_images/writeathomesystems-2-724745.png" alt="" border="0" /&gt;&lt;/a&gt;Yes, that says &lt;span style="font-style: italic;"&gt;"(Prize will be changed tomorrow from $34.95 to $64.95)"&lt;/span&gt; when I'm really pretty sure that they mean "price".&lt;br /&gt;&lt;br /&gt;Incidentally, a check of the Google cache shows that it was still referring to a price change "tomorrow" six days ago. I think there's a word for that.&lt;br /&gt;&lt;br /&gt;Anyway, despite writeathomesystems.com truly crappy ad copy and highly dubious marketing techniques, they are not responsible for the spam. And as already mentioned, I know that click2sell.eu are pretty good at terminating spammers... so who is responsible?&lt;br /&gt;&lt;br /&gt;Well, obviously the affiliate is responsible.. but also the people who strenuously deny responsibility are right in the frame.. remember the footer from the Incisive Media spam?&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;DISCLAIMER&lt;br /&gt;Private Equity Europe and Incisive Media do not take any responsibility for the&lt;br /&gt;content of this email&lt;/blockquote&gt;That's a bit like saying "I don't take any responsibility for taking a shit in your shoes" even though you have just left a big steaming turd in someone's footwear. And one vital question is.. where did the spammers get their email addresses from? Did Incisive sell them on? Or were they scraped?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-2031736005439189602?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/2031736005439189602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=2031736005439189602' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2031736005439189602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/2031736005439189602'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2009/12/incisive-media-writeathomesystemscom.html' title='Incisive Media / writeathomesystems.com spam'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-804714437673009003.post-8958134544766334903</id><published>2009-11-27T12:58:00.003Z</published><updated>2009-11-27T13:20:05.813Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Stupidity'/><category scheme='http://www.blogger.com/atom/ns#' term='Funny'/><title type='text'>"Please design a logo for me. With pie charts. For free."</title><content type='html'>&lt;a href="http://www.27bslash6.com/p2p.html"&gt;Classic&lt;/a&gt;.. but wait, there's &lt;a href="http://www.bloggerheads.com/archives/2009/11/simon_edhouse.asp"&gt;more to this story&lt;/a&gt; too! Language possibly NSFW.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.dynamoo.com/blog/uploaded_images/chart2-791756.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 228px; height: 140px;" src="http://www.dynamoo.com/blog/uploaded_images/chart2-791755.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;This is the guy who tried to &lt;a href="http://www.27bslash6.com/overdue.html"&gt;pay a bill with a drawing of a spider&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/804714437673009003-8958134544766334903?l=www.dynamoo.com%2Fblog%2Findex.htm' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/8958134544766334903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=804714437673009003&amp;postID=8958134544766334903' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8958134544766334903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/804714437673009003/posts/default/8958134544766334903'/><link rel='alternate' type='text/html' href='http://www.dynamoo.com/blog/2009/11/please-design-logo-for-me-with-pie.html' title='&quot;Please design a logo for me. With pie charts. For free.&quot;'/><author><name>Conrad Longmore</name><uri>http://www.blogger.com/profile/11751822299235747323</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='10879275814659618700'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>