<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Vulnerabilities, viruses and exploits, Fraudware</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/Fraudware/default.aspx</link><description>Tags: Vulnerabilities, viruses and exploits, Fraudware</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>ALERT: Please treat content from aegadvancedmedia.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2010/07/29/1774915.aspx</link><pubDate>Thu, 29 Jul 2010 10:05:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1774915</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1774915</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2010/07/29/1774915.aspx#comments</comments><description>&lt;p&gt;Nokia Theatre L.A. Live (nokiatheatrelalive.com) is serving exploits via aegadvancedmedia.com&lt;/p&gt;  &lt;p&gt;Historical badness at aegadvancedmedia.com (btw, homedepotcenter.com is still serving exploits – stay away from there too):   &lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=aegadvancedmedia.com" target="_blank"&gt;http://www.google.com/safebrowsing/diagnostic?site=aegadvancedmedia.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="exploit" alt="exploit" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8030.exploit_5F00_6AC2D72F.jpg" width="1024" height="640" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Malicious content (note the 1x1 iframe):&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3250.image_5F00_138F6FA9.png" width="1024" height="619" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Analysis of content from the IP address 85.234.190.13:   &lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=63e7a8a467205c6c2d6c078de506b30c&amp;amp;t=1280392935&amp;amp;type=js" target="_blank"&gt;http://wepawet.cs.ucsb.edu/view.php?hash=63e7a8a467205c6c2d6c078de506b30c&amp;amp;t=1280392935&amp;amp;type=js&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Historical badness at 85.234.190.13:   &lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=85.234.190.13" target="_blank"&gt;http://www.google.com/safebrowsing/diagnostic?site=85.234.190.13&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Other bad stuff in the IP range:   &lt;br /&gt;&lt;a href="http://www.malwaredomainlist.com/mdl.php?search=85.234.190&amp;amp;colsearch=All&amp;amp;quantity=50" target="_blank"&gt;http://www.malwaredomainlist.com/mdl.php?search=85.234.190&amp;amp;colsearch=All&amp;amp;quantity=50&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;85.234.190.13 is in Latvia - Latvia Riga Docsis Ip Pool For Cable Customers   &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;Other bad stuff is seen coming from 194.8.250.227 (Paraguay Donstroy Ltd) – historical badness there too:   &lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=194.8.250.227" target="_blank"&gt;http://www.google.com/safebrowsing/diagnostic?site=194.8.250.227&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Interestingly, an analysis of the content loaded from 194.8.250.227 points to fake AV:   &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/b0becacf524a1d04943007da7284bc419245bf26a411a1667df06e647eabadc6-1280394361" target="_blank"&gt;http://www.virustotal.com/analisis/b0becacf524a1d04943007da7284bc419245bf26a411a1667df06e647eabadc6-1280394361&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Not surprising considering the IP range history:   &lt;br /&gt;&lt;a href="http://www.malwaredomainlist.com/mdl.php?search=194.8.250&amp;amp;colsearch=All&amp;amp;quantity=50" target="_blank"&gt;http://www.malwaredomainlist.com/mdl.php?search=194.8.250&amp;amp;colsearch=All&amp;amp;quantity=50&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;There is also an attempt to infect systems using a vulnerability in Adobe Reader and Acrobat 8.0 through 9.2 (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4324" target="_blank"&gt;Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009&lt;/a&gt;)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1774915" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>ALERT: Please treat the domain statisticsishere.com and measurehits.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676761.aspx</link><pubDate>Mon, 09 Mar 2009 01:04:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1676761</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1676761</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676761.aspx#comments</comments><description>&lt;p&gt;I received this email a short while ago:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;We have been getting a lot of ads accessing scripts from this domain statisticsishere.com. So far there is no malware redirect or download but this domain looks suspicious having been created less than a week.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I have to agree that the domain is suspicious.&amp;#160; &lt;/p&gt;  &lt;p&gt;Before we get started, it is important that I remind you that the fact that there is no suspicious behavior *at the moment* is of no comfort.&amp;#160; The crooks behind malvertizing have been known to establish a relationship with potential victims by running one or more “clean” campaigns, thereby building a level of trust between them and their victims, before hitting their victims with malvertizing.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Let’s look at the WHOIS information for statisticsishere.com:&lt;/p&gt;  &lt;p&gt;ICANN Registrar: YESNIC CO. LTD.   &lt;br /&gt;Created: 5 March 2009    &lt;br /&gt;NS1.STATISTICSISHERE.COM - IP 116.50.15.1 (HostFresh)    &lt;br /&gt;NS2.STATISTICSISHERE.COM - IP 116.50.15.1 (HostFresh)    &lt;br /&gt;NS3.STATISTICSISHERE.COM - IP 89.149.226.121 (Netdirekt)&lt;/p&gt;  &lt;p&gt;IP: 195.62.37.14 - Sardegna, Olbia, Geonic.net Ltd &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Gabriel Jenks (gabrielcjenks17@mail.com)    &lt;br /&gt;3515 Cooks Mine Road    &lt;br /&gt;88101    &lt;br /&gt;US    &lt;br /&gt;Tel: 1 505-763-5453 &lt;/p&gt;  &lt;p&gt;First of all, HostFresh and Netdirekt have both been problematic in the past but, more importantly, &lt;strong&gt;the postcode (88101) and phone number (505-763-5453) map to Clovis, New Mexico.&amp;#160; I cannot find a &amp;quot;Cooks Mine Road&amp;quot; in Clovis.&amp;#160; Not only that, the phone number listed in the WHOIS is apparently owned by a Brian A Jones and Delinda K Jones, not a Gabriel Jenks.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0E071297.png" width="663" height="256" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Now, let’s look at the NS for the domain statisticsishere.com: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP of NS1.STATISTICSISHERE.COM - 116.50.15.1     &lt;br /&gt;IP of NS2.STATISTICSISHERE.COM - 116.50.15.1&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A Records&lt;/strong&gt; - you will see some very familiar domains.... &lt;/p&gt;  &lt;p&gt;mail.xxx-online.in   &lt;br /&gt;ns2.02sta.com    &lt;br /&gt;&lt;strong&gt;ns2.admediastats.com     &lt;br /&gt;ns2.onlinestatsmanager.com      &lt;br /&gt;ns2.promorotation.com      &lt;br /&gt;ns2.securityclick.net      &lt;br /&gt;ns2.st-athome.net      &lt;br /&gt;ns2.st-aticglobalsources.com      &lt;br /&gt;ns2.statisticsishere.com      &lt;br /&gt;ns2.themonitoring.net      &lt;br /&gt;ns2.traffic-analytics.com      &lt;br /&gt;ns2.waytotheprofit.com      &lt;br /&gt;&lt;/strong&gt;www.xxx-online.in &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using NS1.STATISTICSISHERE.COM as nameserver&lt;/strong&gt;: statisticsishere.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using NS1.STATISTICSISHERE.COM as nameserver under another name&lt;/strong&gt; (again, you&amp;#39;re going to see some familiar names): &lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;statisticsishere.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Nameservers missing in zone: &lt;/p&gt;  &lt;p&gt;ns1.statisticsishere.com   &lt;br /&gt;ns2.statisticsishere.com    &lt;br /&gt;ns3.statisticsishere.com &lt;/p&gt;  &lt;p&gt;Used as nameserver but missing in zone: statisticsishere.com &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP of NS3.STATISTICSISHERE.COM - 89.149.226.121 &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;PTRS of IP numbers&lt;/strong&gt;: 89-149-226-121.internetserviceteam.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A Records&lt;/strong&gt; (again, lots of familiar names): &lt;/p&gt;  &lt;p&gt;89-149-226-121.internetserviceteam.com   &lt;br /&gt;ns3.02sta.com    &lt;br /&gt;&lt;strong&gt;ns3.admediastats.com     &lt;br /&gt;ns3.promorotation.com      &lt;br /&gt;ns3.securityclick.net      &lt;br /&gt;ns3.st-athome.net      &lt;br /&gt;ns3.st-aticglobalsources.com      &lt;br /&gt;ns3.themonitoring.net      &lt;br /&gt;ns3.traffic-analytics.com      &lt;br /&gt;ns3.waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver&lt;/strong&gt;:&amp;#160; statisticsishere.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver under another name&lt;/strong&gt;: &lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Nameservers missing in zone: &lt;/p&gt;  &lt;p&gt;ns1.statisticsishere.com   &lt;br /&gt;ns2.statisticsishere.com    &lt;br /&gt;ns3.statisticsishere.com &lt;/p&gt;  &lt;p&gt;Used as nameserver but missing in zone: statisticsishere.com&lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;According to a Registrant search, “Gabriel Jenks” owns another domain, being &lt;strong&gt;measurehits.com&lt;/strong&gt;, which should also be treated with extreme caution.&lt;/p&gt;  &lt;p&gt;ICANN Registrar: YESNIC CO. LTD.   &lt;br /&gt;Created: 26 February 2009 &lt;/p&gt;  &lt;p&gt;NS1.MEASUREHITS.COM (116.50.15.1)   &lt;br /&gt;NS2.MEASUREHITS.COM (89.149.226.121 &lt;/p&gt;  &lt;p&gt;IP: 212.117.165.128 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Gabriel Jenks (gabrielcjenks17@mail.com)    &lt;br /&gt;3515 Cooks Mine Road    &lt;br /&gt;88101    &lt;br /&gt;US    &lt;br /&gt;Tel: 1 505-763-5453 &lt;/p&gt;  &lt;p&gt;Shares IP address with the following domains, all of which should be treated with extreme caution. &lt;/p&gt;  &lt;p&gt;advertpanda.com, clickanalytic.com, extrabigad.com, greatad.net, securityclick.net, waytotheprofit.com, whoisadvert.com &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;NS1.MEASUREHITS.COM &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A-Records: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;mail.xxx-online.in   &lt;br /&gt;ns1.statisticsishere.com    &lt;br /&gt;ns2.02sta.com    &lt;br /&gt;&lt;strong&gt;ns2.admediastats.com     &lt;br /&gt;ns2.onlinestatsmanager.com      &lt;br /&gt;ns2.promorotation.com      &lt;br /&gt;ns2.securityclick.net      &lt;br /&gt;ns2.st-athome.net      &lt;br /&gt;ns2.st-aticglobalsources.com      &lt;br /&gt;ns2.statisticsishere.com      &lt;br /&gt;ns2.themonitoring.net      &lt;br /&gt;ns2.traffic-analytics.com      &lt;br /&gt;ns2.waytotheprofit.com      &lt;br /&gt;&lt;/strong&gt;www.xxx-online.in &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver under another name: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;statisticsishere.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;NS2.MEASUREHITS.COM &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;PTRS of IP numbers&lt;/strong&gt; - 89-149-226-121.internetserviceteam.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A-Records: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;89-149-226-121.internetserviceteam.com   &lt;br /&gt;ns3.02sta.com    &lt;br /&gt;&lt;strong&gt;ns3.admediastats.com     &lt;br /&gt;ns3.promorotation.com      &lt;br /&gt;ns3.securityclick.net      &lt;br /&gt;ns3.st-athome.net      &lt;br /&gt;ns3.st-aticglobalsources.com      &lt;br /&gt;ns3.statisticsishere.com      &lt;br /&gt;ns3.themonitoring.net      &lt;br /&gt;ns3.traffic-analytics.com      &lt;br /&gt;ns3.waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver under another name: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;statisticsishere.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1676761" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Interesting comment – Best Western malvertizing</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/26/1674103.aspx</link><pubDate>Thu, 26 Feb 2009 15:46:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1674103</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1674103</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/26/1674103.aspx#comments</comments><description>&lt;p&gt;The comment was posted &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/11/1656447.aspx#1673880" target="_blank"&gt;here&lt;/a&gt;.&amp;#160; I quote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;My company was approached by a client claiming to represent Best Western with a lower tech version of this.&amp;#160; We were give a static JPG, third one from the top and instructions to paste some odd-looking Javascript with the image.&amp;#160; &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I ran the code in AddOps tools and it did nothing.&amp;#160; Getting suspicious I checked the src URL for the Javascript which was &amp;quot;http:// st-aticglobalsources.com&amp;quot; and found a lot of trouble associated with it.&amp;#160; &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;We refused to run the ad with the code. Client claimed ignorance saying code came from their client and would provide new tags.&amp;#160; New tags arrived, similar to the first but sourcing the J-script from &amp;quot;http:// st-ation-appraisals.net&amp;quot; this time.&amp;#160; Running this code through AdOps tools at least generates a Best Western banner, but I ran the URL through search engines, found associated with ITmeter INC, and did not run the ad.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;As my regular readers will know, both of the URLs are well known to those of us who study malvertizing.&amp;#160; I hope that the commentator will tell us the name and email addresses used by the person who tried to sell them the malicious advertisement.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;st-aticglobalsources.com (79.135.187.86 - Istanbul - Istanbul - Serv2u.com International Backbone Tr)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Registrant Contact:   &lt;br /&gt;&amp;#160;&amp;#160; ITmeter INC    &lt;br /&gt;&amp;#160;&amp;#160; Sergey Belonozhko (sergbelo@gmail.com)    &lt;br /&gt;&amp;#160;&amp;#160; Fax:&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160; Dmitrienko 7    &lt;br /&gt;&amp;#160;&amp;#160; Odessa, State 65000    &lt;br /&gt;&amp;#160;&amp;#160; UA&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;st-ation-appraisals.net (79.135.187.89 - Istanbul - Istanbul - Serv2u.com International Backbone Tr)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Registrant Contact:   &lt;br /&gt;&amp;#160;&amp;#160; ITmeter INC    &lt;br /&gt;&amp;#160;&amp;#160; Sergey Belonozhko (sergbelo@gmail.com)    &lt;br /&gt;&amp;#160;&amp;#160; Fax:&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160; Dmitrienko 7    &lt;br /&gt;&amp;#160;&amp;#160; Odessa, State 65000    &lt;br /&gt;&amp;#160;&amp;#160; UA&lt;/p&gt;  &lt;p&gt;It is important to note that although both bad domains have “dedicated hosting” and unique IP addresses, they are both hosted by the same company, and are within the same IP range.&amp;#160; A check of the entire IP range, 79.135.187.% reveals 266 domains, all of which should be treated with extreme caution.&lt;/p&gt;  &lt;p&gt;1spam.ru | 1yandex.ru | Abusehost.ru | Abuzhost.ru | Advert1.ru | Aloincognito.ru | Buildhost.ru | Business-orders.ru | Cammin.ru | Compaq-hp-dv.ru | Cpammagazin4.ru | Detiamdo.ru | Email-s.ru | Email-spam.ru | Emailspam.ru | Enterboom.ru | Evroreklama.ru | Farma-reklama.ru | Flovermag.ru | Forum-it.ru | Generatorcompany.ru | Goohost.ru | Goosoft.ru | Gottobe.ru | Hotmailer.ru | Hrumer2007.ru | Igrushki-detiam.ru | Irkmailer.ru | Junar-trade.com | Kuklasex.ru | Magazinreklamy.ru | Mailadvertising.ru | Mnogonarodu.ru | Montenegrovilla.ru | Neintim.ru | Nochklub.ru | Notebook7.ru | O-la-la.ru | Online-email.ru | Online-mailer.ru | Online-master.ru | Online-standart.ru | Ppkurort.ru | Proektclty.ru | Reklamabiznesa.ru | Reklamict.ru | Reklmagazin.ru | Robotraff.ru | Rukinomania.ru | Saitbaz.ru | Seosuper.ru | Setevaya-reklama.ru | Shablon1.ru | Sitepostroim.ru | Spam502.ru | Spamarena.ru | Spamchik.ru | Spamim.ru | Spammagazin.ru | Spammagazine3.ru | Spammagazine5.ru | Spmagazin.ru | Starshe18.ru | Super-fuel-max.ru | Super-mailer.ru | Turistmag.ru | Wmir.biz | Wreklama.ru | Wsws.ru | Wtorg.ru | Xmailer.ru | Yandex1.ru | L-state.com | P-state.com | R-state.com | V-state.com | 4utraffic.cc | 4utraffic.net | Cashpopup.cc | Cashpopup.info | Newprogress.tv | Einrock.com | Makomset.com | Ribcot.com | Megavipsite.cn | Installing.cc | Loader.cc | Windowscentersite.com | Tgspk.com | Statbroun.com | Loots-leg.com | Newprogress.asia | Newprogress.biz | Alertplump.com | Bdgerggggs.com | Beatstrust.com | Chiefgracious.com | Circlesensational.com | Clearorganized.com | Eagermulti.com | Fizzpeak.com | Fizzslick.com | Hardyfab.com | Humbleoxygen.com | Notablebase.com | Proudlucky.com | Royalmeek.com | Rx13.com | Safetyunselfish.com | Sdggfdfgd.com | Serviceclear.com | Sfdgsvddsdfs.com | Sgdfgdfgdf.com | Sgdfgsdfsddfgdf.com | Sjbisdgergess.com | Stayunsurpassed.com | Thankfulmountain.com | Topseductive.com | Usdrugstorebest.com | Westcharming.com | Zestloyal.com | Zipbold.com | Skype-security.net | Afrogruster.com | Agiromentop.com | Agrostergio.com | Akierodentos.com | Aportobrasok.com | Atopresorgo.com | Aviorebato.com | Awrentoblasgo.com | Beshragos.com | Counterprise.com | Diomertona.com | Dresmondas.com | Equalcrowd.ru | Frododkoone.com | Frododkotwo.com | Hortesoda.com | Kioretions.com | Kordanoser.com | Krombustor.com | Massachuret.com | Notifisarto.com | Privatesecuritycenter.com | Rx-online-order.com | Twopgoslyso.com | Filarmon.info | Gvatemal.biz | Jumpingo.org | Grandtraf.com | Loaddasig.com | Zetross.com | 5traff.cn | Axa3.cn | Beencn.cn | Centerifart.cn | Ftalyl.cn | Londoncn.cn | Mostdey.cn | Originalcn.cn | Traxxk.cn | Typecn.cn | Hibucks.com | Moviesforall.info | Musicscollection.com | Welovemovie.com | Ds1ff.com | Googlesearchingweb.net | Index938.com | 2ndattempt.net | Angelok.org | Anxietypedia.net | Anxinews.org | Any-doctor.net | Availmeds.com | Balmpro.net | Balzaks.net | Bighealthy.net | Bigremedy.net | Caremedicals.net | Delivery-services.net | Discountmeds.name | Docclive.net | Doctor11.net | Doctor5.net | Doctor6.net | Doctorlive.net | Doctorr.org | Easy-meds.org | Fresh-infa.net | Generecs.net | Generikes.net | Generiks.net | Getphen.net | Gomedy.net | Healtn.net | Helth-life.net | Hotnewlette.net | Hotnewslette.net | Hotnewsletter.net | Hotnewsletter.ru | Hydrophen.com | Index333.com | Index345.com | Lodono.com | Medguide.in | Medicalaz.net | Medsizi.net | Most900.com | Mostsearch.net | My-order.org | Myangst.net | Myhomemed.net | Noconsult.net | Normalmed.net | Opapapa.net | Pharmaenergi.net | Phenhydro.net | Rx-free.net | Rxfair.net | Rxneds.com | Rxneds.net | Savehealth.net | Search-traffic.net | Seedeals.net | Singleslady.com | Suicide-forum.com | Theclinical.net | Track-order.com | Trialpack.net | Vicod.net | Vicodi.net | Webadvices.net | Webremedies.net | Winyourhealth.net | Wwwhotnewsletter.net | &lt;strong&gt;Officialstat.net | Ne-wstat.net | Of-ficialstat.com | Ourstats-online.com | Statgroup.net | St-at-diagnostic-imaging.net | St-atetstr.com | Stats-manager-online.com | St-atgroup.net | Staticglobalsources.net | Traffic-ad-manager.com | Station-appraisals.com | St-athisranch.com | St-athisranch.net | St-athome.net | St-aticglobalsources.com | St-aticglobalsources.net | St-ation-appraisals.com | St-ation-appraisals.net | S-tatetstr.com | S-tathisranch.com | S-tathisranch.net | Track-your-stats.com | S-tatgroup.net | Freegreenstats.com | Of-ficialstat.net | Themonitoring.net | Statstrackingmanager.com | Traffic-analytics.com&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1674103" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Lifestyles of the Rich and Infamous, and an update about the status of the FTC versus Innovative Marketing et al lawsuit</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx</link><pubDate>Tue, 10 Feb 2009 08:42:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1671117</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1671117</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;ll include some history of events so that you can get a sense of perspective with regards to the time frame around these events.&amp;#160;&amp;#160; It is especially important to note that the FTC lawsuit is not the only problem that Jain is facing.&amp;#160; He has been indicted in the State of California and is facing several criminal charges there, and there are pending charges against him in Illinois.&amp;#160; Events relevant to the California criminal charges and the Illinois investigation are highlighted.&lt;/p&gt;  &lt;p&gt;You’ll see that the lifestyle enjoyed by Kristy Ross as revealed by her credit card statements was nothing if not lavish.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Defendants Kristy Ross and Sam Jain (who were (are?) boyfriend and girlfriend): &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;26 March 2008&lt;/u&gt; - US District Court, San Jose, California: USA v Shaileshkumar Jain - four counts being criminal copyright infringement, trafficking in counterfeit goods, wire fraud and mail fraud (for activities that took place in 2003) (CR-08-00197-HRL) (charges relate to events on 12 and 26 January and the sale of fake Symantec software).&amp;#160; The Grand Jury indictment requests the forfeiture of &amp;quot;approximately $13,522,080 in United States currency or after acquired assets traceable thereto&amp;quot;.&amp;#160; Sam Jain&amp;#39;s full name is Shaileshkumar Jain.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&amp;quot;late September&amp;quot; 2008&lt;/u&gt; - Ted W Cassman (he and his firm Arguedas, Cassman &amp;amp; Headley LLP represent(ed) Jain in the ongoing California criminal proceedings and the ongoing investigation in Illinois) met with Assistant US Attorney and two agents of the FBI in Chicago, Illinois.&amp;#160; The Assistant US Attorney &amp;quot;unequivocally stated that Mr Jain will be indicted for wire fraud and computer fraud charges as a result of the Illinois Investigation &amp;#39;sooner rather than later.&amp;#39; &amp;quot; (cite: Declaration of Ted W Cassman dated 18 December 2008)&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;u&gt;2 December 2008&lt;/u&gt; - FTC requests and receives a temporary restraining order. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;12 December 2008&lt;/u&gt; - temporary restraining order expires.&amp;#160; The defendants did not turn up in Court and they failed to comply with the TRO.&amp;#160; Order to show cause issued. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;17 December 2008&lt;/u&gt; - appearances entered for Mark D&amp;#39;Souza and Sam Jain.&amp;#160; Joint response to order to show cause filed by Jain and Ross, promising to &amp;quot;fully comply with the terms of the TRO and PI by 23 December 2008&amp;quot;&amp;#160; Mark D&amp;#39;Souza also files a response, promising to comply with the requirements of the TRO and PI by 4.00pm on 23 December 2008.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;18 December 2008&lt;/u&gt; - Cassman declaration signed describing the events of &amp;quot;late September&amp;quot; 2008. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;u&gt;23 December 2008&lt;/u&gt; - a letter was sent to FTC on 23 December by the law firm Patton Boggs explaining that Jain had no intention of complying with the Court orders because to do so &amp;quot;&lt;em&gt;would require Jain to incriminate himself&lt;/em&gt;&amp;quot; (the letter stated that Jain &amp;quot;&lt;em&gt;is the target of a criminal investigation in the Northern District of Illinois covering the same conduct as the Commission&amp;#39;s suit&lt;/em&gt;&amp;quot; and claimed that Jain cannot take any steps in relation to the FTC lawsuit without &amp;quot;&lt;em&gt;waiving his Fifth Amendment privilege and making admissions that could be used against him in the criminal case&lt;/em&gt;&amp;quot;).&amp;#160; Kristy Ross made the same argument.&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: bearing in mind the events of &amp;quot;late September&amp;quot; 2008 as described by Ted Cassman and detailed in his declaration signed 18 December 2008, why did Jain promise to &amp;quot;fully comply with the terms of the TRO and PI by 23 December 2008” – he must have known about the Illinois investigation and the possibility of criminal charges?&amp;#160; I do not know if criminal charges have yet been laid in Illinois) &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;u&gt;29 January 2009&lt;/u&gt; - the FTC filed a &amp;quot;memorandum of points and authorities in support of its motion for an order holding defendants Sam Jain and Kristy Ross in contempt of Court and requiring the repatriation of their assets&amp;quot;.&amp;#160; I quote: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Defendant Ross, for example, spent the year 2008 visiting the world&amp;#39;s finest resorts (including multiple visits to the Four Seasons Resort in Nevis, as well as the British Colonial Hilton in the Bahamas, enjoying extravagant meals (including multiple $800+ meals), and gorging herself on luxury items from the world&amp;#39;s most exclusive retailers, including Harrods of London (nearly $30,000 spent in 2008), Louis Vuitton (more than $23,000 spent in 2008) and Dolce &amp;amp; Gabbana (more than $13,000 spent in 2008). &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;... &lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;To date, despite extensive efforts, the FTC has been unable to locate a single dollar of domestic assets held by either Jain or Ross.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The above information was taken from credit card statements for Kristy Ross that were submitted to the FTC by JP Morgan Chase and BMW Bank of North America - the &amp;quot;extravagant meals&amp;quot; included a series of meals totaling over $500 as well as at least two meals totaling more than $800.&amp;#160; The charges were incurred by Ross in locations all over the world including London, Toronto, Kiev, Brussels, Zurich, Nevis, Frankfurt and Montreal.&amp;#160; Ross stopped using the credit cards in or about September 2008. (cite: declaration of Sheryl Drexler dated 29 January 2009) &lt;/p&gt;  &lt;p&gt;Two credit card accounts held by Kristy Ross and a safe deposit box held by Sam Jain have been discovered but apart from that &amp;quot;&lt;em&gt;after weeks of searching, the FTC has located only $174,000 of the defendants&amp;#39; assets. ... The bulk of these funds belong to James Reno.&amp;#160; To date, the FTC has not located a single dollar of domestic assets held by either Jain or Ross.&lt;/em&gt;&amp;quot; (cite: Plaintiff&amp;#39;s memorandum of points and authorities in support of its motion for an order holding defendants Sam Jain and Kristy Ross in contempt of Court and requiring the repatriation of their assets filed 29 January 2009) &lt;/p&gt;  &lt;p&gt;According to documents filed in the Canadian litigation (the &amp;quot;Canadian litigation&amp;quot; being the lawsuit filed by Innovative Marketing against Marc D&amp;#39;Souza and Maurice D&amp;#39;Souza in the Ontario Superior Court of Justice), the defendants&amp;#39; income from the sale of their products between 2004-2006 totaled more than $74 million! (cite: Plaintiff&amp;#39;s memorandum of points and authorities in support of its motion for an order holding defendants Sam Jain and Kristy Ross in contempt of Court and requiring the repatriation of their assets filed 29 January 2009). &lt;/p&gt;  &lt;p&gt;The FTC have requested that &amp;quot;&lt;em&gt;this Court hold Jain and Ross in civil contempt, and order them incarcerated until such time as they comply with the PI...&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;5 January 2009&lt;/u&gt; - a completed Consent to Release of Financial Records form was finally received from Ross (the foreign account holders (ie overseas financial institutions) have not, as far as I know, supplied the requested information). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;12 January 2009&lt;/u&gt; - Jain failed to appear in court to face criminal charges (Criminal Minute Order, USA v Shaileshkumar Jain, CR-08-00197-RMW).&amp;#160; Bench Warrant issued, and stayed until 26 January 2009. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;u&gt;14 January 2009&lt;/u&gt; - a completed Consent to Release of Financial Records form was finally received from Jain (the foreign account holders (ie overseas financial institutions) have not, as far as I know, supplied the requested information). &lt;/p&gt;  &lt;p&gt;&lt;u&gt;26 January 2009&lt;/u&gt; - Jain requests a stay of the FTC proceedings because of the criminal proceedings in the Northern District of Illinois, until the criminal proceedings are resolved. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;26 January 2009&lt;/u&gt; - Sam Jain became a fugitive after the Bench Warrant stay was lifted.&amp;#160; Jain forfeited a $250,000 cash bond.&amp;#160; &lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: Bearing in mind the fact that the FTC claims that Jain/Ross were able to achieve revenues in excess of $100 million, the amount of $250,000 would seem a small price to pay (even after taking into consideration the fact that Ross was going through money hand over fist in 2008). &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;u&gt;29 January 2009&lt;/u&gt; - Ross requests a stay of the FTC proceedings because of the criminal proceedings in the Northern District of Illinois, until the criminal proceedings are resolved. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;5 February 2009&lt;/u&gt; - Ross files a &amp;quot;Motion to Strike or, in the alternative, for extension of time to respond&amp;quot;, moving for the Court to strike the FTC&amp;#39;s motion for an order holding Jain and Ross in contempt of court and requiring repatriation of their assets &amp;quot;as premature and procedurally improper&amp;quot;.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;u&gt;5 February 2009&lt;/u&gt; - Jain joins Ross&amp;#39;s motion to strike &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: Isn&amp;#39;t it interesting that Jain, who has been a fugitive since 26 January 2009 and whose whereabouts are apparently unknown (see FTC document filed 9 January 2009), was able to join Kristy Ross&amp;#39;s Motion to Strike on 5 February 2009?). &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;u&gt;9 January 2009&lt;/u&gt; - The FTC opposed the Motion to Strike, filing a &amp;quot;&lt;em&gt;consolidated opposition to motion of defendants Kristy Ross and Sam Jain to strike or in the alternative for an extension of time&lt;/em&gt;&amp;quot; on 9 January 2009.&amp;#160; The FTC notes in that document that &amp;quot;&lt;em&gt;to allow these defendants to flaunt the Court&amp;#39;s orders, and then escape the consequences of these actions by pointing to a possible criminal proceeding, would set bad precedent and invite similar conduct from future defendants.&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;The FTC document notes that Jain is a fugitive, and that his whereabouts are (were?) unknown. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Defendants: James Reno and Bytehosting Internet Services &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Bytehosting/Reno are now represented.&amp;#160; A further extension of time was granted, pushing out the deadline from 23 January to 30 January 2009. &lt;/p&gt;  &lt;p&gt;Reno/Bytehosting then filed a Motion to dismiss for lack of personal jurisdiction (claiming the court has no jurisdiction) on 30 January 2009.&amp;#160; Reno/Bytehosting claim to have been &amp;quot;&lt;em&gt;merely under contract to provide services, namely technical support and a call center, to Defendant Innovative Marketing&lt;/em&gt;&amp;quot;.&amp;#160; It is also claimed that their &amp;quot;&lt;em&gt;involvement with Innovative Marketing was limited to internal technical support and post-sale support for customers through a call center&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;Reno swore an affidavit which basically says the same thing on 30 January 2009. &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: Uh, yeah – where I come from being aware that something bad is going on via my business because of a rogue client and not doing anything about it is as bad as being the rogue client, and there’s no way Reno could NOT have known what Innovative Marketing et al were doing, especially after the Symantec lawsuit that Reno was a party to)      &lt;br /&gt;      &lt;br /&gt;BTW, I have come across the name eFront a few times in association with Reno and Jain – a couple of comments have been posted referring to them ... would anybody like to share what they know about *that* story?       &lt;br /&gt;&lt;a title="http://www.google.com/search?hl=en&amp;amp;q=efront+reno+jain" href="http://www.google.com/search?hl=en&amp;amp;q=efront+reno+jain" target="_blank"&gt;http://www.google.com/search?hl=en&amp;amp;q=efront+reno+jain&lt;/a&gt; (eFront CEO was Sam Jain, CTO was James Reno?)&amp;#160; Why do I get the feeling that the association between Reno and Jain is more than the typical “arms length, he just walked in off the street, wouldn’t know him from Adam” client/supplier relationship?&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Defendants: Daniel Sundin, Maurice D&amp;#39;Souza, Innovative Marketing Inc &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;These defendants are still unrepresented and silent in this action.&amp;#160; Also, I have found no evidence that Innovative Marketing has paid any of the $8,000 per day fine that was imposed after it failed to comply with the Temporary Restraining Order. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Upcoming deadlines: &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;12 February 2009 (Response)    &lt;br /&gt;17 February 2009 (Response x3)     &lt;br /&gt;23 February 2009 (Response x2 and reply x1) &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1671117" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item></channel></rss>