Dynamoo's Blog

Malware, spam, scams and random stuff, by Conrad Longmore.

Wednesday, 30 July 2008

PestPatrol: Zuten detected in c:\windows\minidump

›
This one looks like a false positive.. CA PestPatrol with signature version 2008.7.29.15 seems to be detecting Zuten in the c:\windows\mini...
Tuesday, 29 July 2008

The SQL Injection war

›
Dancho Danchev had has some very good writeups on the current round of SQL injection attacks. This post on copycat attacks caught my eye, ...

Asprox domains: 29/7/08

›
These are this morning's active Asprox domains. New ones are in bold. b4so.ru bce8.ru bjxt.ru bnsr.ru bosf.ru bsko.ru ch35.ru gty5.ru ir...
Monday, 28 July 2008

Asprox domains: 28/7/08

›
These seem to be the current Asprox domains to block or check for. New ones are in bold. bs04.ru bce8.ru bjxt.ru bnsr.ru bosf.ru bsko.ru ch3...
Friday, 25 July 2008

Asprox domains: 25/7/08

›
These domains seem to be active today, new ones in bold. bce8.ru ch35.ru iroe.ru jve4.ru kjwd.ru kodj.ru kpo3.ru kr92.ru ncwc.ru nemr.ru nmr...
Thursday, 24 July 2008

Asprox: jve4.ru, nmr43.ru and po4c.ru

›
Three new Asprox domains that have gone live in the past few hours, probably some more on the way. Either block these or check your logs if ...

"ABT Solutions" scam email

›
Following on from the recent "Infopulse" scam , another Ukranian firm has been targeted by the money mule operators. ABT Solutions...
Wednesday, 23 July 2008

Asprox domains: 23/7/08 - Part II

›
Just a couple more to add: cgt4.ru kc43.ru

Asprox domains: 23/7/08

›
A shift in domains used by the Asprox crew - these new domains are all in the .ru TLD and are registered via NauNet (contact details here ...
Wednesday, 16 July 2008

"Infopulse Ukraine Ltd" Money Mule Scam

›
Infopulse Ukraine appears to be a legitimate software development company, but this email that claims to be from them is certainly not legi...
8 comments:

Asprox domains: 16/7/08

›
The following Asprox SQL Injection domains appear to be active today. New ones are in bold. adwnetw.com adpzo.com ausbnr.com brcporb.ru bt...
1 comment:
Tuesday, 15 July 2008

Asprox domains: 15/7/08

›
Another bunch of Asprox SQL Injection domains , new ones are in bold . adpzo.com adwnetw.com ausbnr.com bkpadd.mobi butdrv.com cdport.eu cd...
Friday, 11 July 2008

"I'm customer from Singapore.."

›
If you sell any kind of high-value goods (or even if you have a web site that just mentions them) then you probably get all sorts of fraudu...
Thursday, 10 July 2008

"Dibag Industries AG" money mule scam

›
A money mule scam pretending to come from Dibag Industries AG - clearly trying to pass itself off as the wholly legitimate Dibag Industrie...
1 comment:

Asprox domains: 10/7/08

›
These seem to be the currently active Asprox SQL Injection domains to block or check for. New ones are in bold. adwnetw.com ausadd.com ausbn...
4 comments:
Wednesday, 9 July 2008

ZoneAlarm: "The firewall has blocked Internet access to.."

›
If you have recently patched your Windows computer with KB951748 and have ZoneAlarm installed then you'll probably find that everything...
3 comments:

Asprox domains: 9/7/08

›
Another shift in the Asprox SQL Injection domains, still registered with Vivids Media GmbH. As ever, check your logs or block them. adwnetw...

"Ban Ki-moon / United Nations" scam

›
An almost laughable scam email claiming to be from Ban Ki-moon (the UN's Secretary General) offering to reward victims of scams with $25...
20 comments:
Monday, 7 July 2008

Who are Vivids Media GmbH?

›
If you have been tracking the latest round of SQL Injection domains, then you might be familiar with the name Vivids Media GMBH as being t...
1 comment:

Asprox domains: 7/7/08 and another SQL Injection mitigation article

›
Another batch of Asprox domains are active today - it also seems that those from 3rd July are still running too. I advise that you check yo...
‹
›
Home
View web version
Powered by Blogger.