<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Spyware Sucks : Vulnerabilities, viruses and exploits, Malvertizing</title><link>http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/Malvertizing/default.aspx</link><description>Tags: Vulnerabilities, viruses and exploits, Malvertizing</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>“Wire Transfer Confirmation” spam</title><link>http://msmvps.com/blogs/spywaresucks/archive/2012/06/02/1810528.aspx</link><pubDate>Sat, 02 Jun 2012 02:57:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810528</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1810528</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2012/06/02/1810528.aspx#comments</comments><description>&lt;p&gt;It’s not real – honest.&amp;#160; And the email isn’t from LinkedIn.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3515.image_5F00_528FFE7C.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4034.image_5F00_thumb_5F00_45497569.png" width="1375" height="438" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810528" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Fake Linked In emails</title><link>http://msmvps.com/blogs/spywaresucks/archive/2012/06/02/1810527.aspx</link><pubDate>Sat, 02 Jun 2012 02:55:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810527</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1810527</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2012/06/02/1810527.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8535.image_5F00_20F96AEF.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5314.image_5F00_thumb_5F00_780E55E5.png" width="790" height="250" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5658.image_5F00_7C382DAA.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5008.image_5F00_thumb_5F00_410451DF.png" width="649" height="630" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810527" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>That which is old is new again–Ecard spam</title><link>http://msmvps.com/blogs/spywaresucks/archive/2012/05/31/1810456.aspx</link><pubDate>Thu, 31 May 2012 05:21:57 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810456</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1810456</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2012/05/31/1810456.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0574.image_5F00_07F6EF05.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6648.image_5F00_thumb_5F00_45A3D6C1.png" width="786" height="349" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;You don’t really have a secret admirer, honest…&amp;#160; &lt;strong&gt;&lt;em&gt;don’t try this at home unless you have a sandboxed VM that you can trash at will.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5557.image_5F00_42423F19.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4807.image_5F00_thumb_5F00_4D1F2061.png" width="786" height="434" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7457.image_5F00_3B12DCD4.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0880.image_5F00_thumb_5F00_04750BC3.png" width="786" height="548" /&gt;&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7266.image_5F00_7E1E0F67.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7608.image_5F00_thumb_5F00_09274E18.png" width="793" height="506" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810456" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>A sophisticated, and detailed (but fake) Amazon Kindle purchase spam</title><link>http://msmvps.com/blogs/spywaresucks/archive/2012/05/26/1810319.aspx</link><pubDate>Sat, 26 May 2012 01:59:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1810319</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1810319</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2012/05/26/1810319.aspx#comments</comments><description>&lt;p&gt;Check it out at the bottom of this post.&lt;/p&gt;  &lt;p&gt;Interestingly, several different URLs are used in the spam email, scattered around several countries – somebody’s put a nice bit of effort into this one…&lt;/p&gt;  &lt;table border="0" cellspacing="0" cellpadding="2" width="400"&gt;&lt;tbody&gt;     &lt;tr&gt;       &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0412.image_5F00_271CC5F0.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0550.image_5F00_thumb_5F00_37488DE9.png" width="406" height="173" /&gt;&lt;/a&gt;&lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8741.image_5F00_5BF9A560.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3513.image_5F00_thumb_5F00_681B1F87.png" width="375" height="175" /&gt;&lt;/a&gt;&lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4861.image_5F00_25C80744.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6153.image_5F00_thumb_5F00_4AE551B0.png" width="382" height="72" /&gt;&lt;/a&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1663.image_5F00_13BBC3B7.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1524.image_5F00_thumb_5F00_314D9EB6.png" width="404" height="87" /&gt;&lt;/a&gt;&lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6607.image_5F00_239AE2AE.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3426.image_5F00_thumb_5F00_258831B7.png" width="380" height="131" /&gt;&lt;/a&gt;&lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7288.image_5F00_2A8A6F66.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7043.image_5F00_thumb_5F00_5DE632C2.png" width="383" height="163" /&gt;&lt;/a&gt;&lt;/td&gt;     &lt;/tr&gt;      &lt;tr&gt;       &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8562.image_5F00_26BCA4C9.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8053.image_5F00_thumb_5F00_6BF4FBF2.png" width="406" height="153" /&gt;&lt;/a&gt;&lt;/td&gt;        &lt;td valign="top" width="133"&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3603.image_5F00_3B7E777C.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7776.image_5F00_thumb_5F00_7A03C522.png" width="377" height="117" /&gt;&lt;/a&gt;&lt;/td&gt;        &lt;td valign="top" width="133"&gt;&amp;nbsp;&lt;/td&gt;     &lt;/tr&gt;   &lt;/tbody&gt;&lt;/table&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0576.image_5F00_57CBB99C.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8422.image_5F00_thumb_5F00_68EF7172.png" width="1209" height="667" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1810319" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Problems at metacafe.com?</title><link>http://msmvps.com/blogs/spywaresucks/archive/2012/05/19/1809968.aspx</link><pubDate>Sat, 19 May 2012 02:43:51 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1809968</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1809968</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2012/05/19/1809968.aspx#comments</comments><description>&lt;p&gt;Cite: &lt;a href="http://www.google.com/safebrowsing/diagnostic?site=metacafe.com"&gt;http://www.google.com/safebrowsing/diagnostic?site=metacafe.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;“Of the 15199 pages we tested on the site over the past 90 days, 5944 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2012-05-18, and the last time suspicious content was found on this site was on 2012-05-17.”&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8546.image_5F00_1A7F4E10.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:10px 10px 0px 0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0755.image_5F00_thumb_5F00_71280611.png" width="1072" height="258" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;openx-master.info   &lt;br /&gt;ICANN Registrar: DomainContext Inc    &lt;br /&gt;Created 17 May 2012&lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;metaafe.info (t’s worrying that a malicious incident on metacafe.com involved a domain so similarly named – metaafe.info – that points to human managed attack, not just random scanning for and automated use of vulnerable OpenX installs)&lt;/p&gt;  &lt;p&gt;   &lt;br /&gt;ICANN Registrar: DomainContext Inc    &lt;br /&gt;Created 17 May 2012&lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;openxmasters.info   &lt;br /&gt;ICANN Registrar: DomainContext Inc    &lt;br /&gt;Created 17 May 2012&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Some other recently reported bad domains have been:&lt;/p&gt;  &lt;p&gt;ptsector.com   &lt;br /&gt;ICANN Registrar: Register.com, Inc    &lt;br /&gt;Created 8 May 2012&lt;/p&gt;  &lt;p&gt;Registrant: Jacob Hayes, hiltonparis390@yahoo.com&lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;MULTIPLEXTENT.COM (&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=multiplextent.com"&gt;http://www.google.com/safebrowsing/diagnostic?site=multiplextent.com&lt;/a&gt;)    &lt;br /&gt;ICANN Registrar: Register.com, Inc    &lt;br /&gt;Created 15 May 2012&lt;/p&gt;  &lt;p&gt;Registrant: Jacob Hayes, hiltonparis390@yahoo.com&lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;WEBEXPERTEST.COM (&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=WEBEXPERTEST.COM"&gt;http://www.google.com/safebrowsing/diagnostic?site=WEBEXPERTEST.COM&lt;/a&gt;)    &lt;br /&gt;ICANN Registrar: Register.com, Inc    &lt;br /&gt;Created 15 May 2012&lt;/p&gt;  &lt;p&gt;Registrant: Jacob Hayes, hiltonparis390@yahoo.com   &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1809968" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Users of OpenX versions 2.8.0 - 2.8.8–please read!!</title><link>http://msmvps.com/blogs/spywaresucks/archive/2012/05/05/1809508.aspx</link><pubDate>Sat, 05 May 2012 06:13:52 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1809508</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1809508</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2012/05/05/1809508.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://blog.openx.org/05/security-update-for-openx-28-users/" target="_blank"&gt;http://blog.openx.org/05/security-update-for-openx-28-users/&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;“A recent security issue with OpenX versions 2.8.0 - 2.8.8 means users of these versions of the platform should take the following steps:&lt;/p&gt;  &lt;p&gt;1. Secure their servers by removing the files being exploited:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;www/admin/account-settings-debug.php &lt;/li&gt;    &lt;li&gt;www/admin/plugin-index.php &lt;/li&gt;    &lt;li&gt;www/admin/plugin-settings.php &lt;/li&gt;    &lt;li&gt;www/admin/admin-user.php&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;2. Removing these scripts will impact some of the user/plugin management systems, but will not affect existing users/plugins, and will not affect ad serving.&lt;/p&gt;  &lt;p&gt;3. Replace the www/admin/dashboard.php file with the one in &lt;a href="http://www.openx.com/downloads/dashboard.zip" target="_blank"&gt;this archive&lt;/a&gt; so as to not break the login process.&lt;/p&gt;  &lt;p&gt;Users can tell if they have been affected by this by checking for a rogue admin user named “openx-manager” in their UI at http://&amp;lt;your_admin_domain&amp;gt;/www/admin/admin-access.php&lt;/p&gt;  &lt;p&gt;If the above user is found, it should be removed, and a &lt;a href="http://blog.openx.org/09/security-update-how-to-secure-your-openx-installation/" target="_blank"&gt;full security audit&lt;/a&gt; should be performed.&lt;/p&gt;  &lt;p&gt;We strongly encourage users to lock down their config file. Additionally, users should notify &lt;a href="mailto:security@openx.com" target="_blank"&gt;security@openx.com&lt;/a&gt; if they ever become aware of a security matter.”&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1809508" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Security alert for visitors to SBS.COM.AU and HERALDSUN.COM.AU</title><link>http://msmvps.com/blogs/spywaresucks/archive/2011/07/19/1796412.aspx</link><pubDate>Tue, 19 Jul 2011 06:22:46 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1796412</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1796412</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2011/07/19/1796412.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 10px 10px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2845.image_5F00_12114B39.png" width="486" height="577" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;SBS Alert here:   &lt;br /&gt;&lt;a title="http://www.sbs.com.au/article/124519/SBS-website-statement-July-18-2011" href="http://www.sbs.com.au/article/124519/SBS-website-statement-July-18-2011" target="_blank"&gt;http://www.sbs.com.au/article/124519/SBS-website-statement-July-18-2011&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;Over the last 2 days, the SBS website has been the victim of a hacking attack. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;This is the first time that the SBS site has suffered any sort of attack, however unfortunately, this is a common occurrence for many websites and organisations around the world. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;While SBS has comprehensive safety measures in place across the site, this source has been able to enter the site on this occasion and has inserted a link to a third party ‘malware site’. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Users who may have inadvertently visited this third party malware site could then have had their machines infected with a virus depending on their security settings. SBS recommends that any site users who may be concerned about infection run a full security scan. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;SBS would like to apologise to any of our site users who may have been affected by a virus. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Our digital team has been working throughout the weekend to rectify the problem and have now resolved the problem. Investigations are ongoing regarding how this issue occurred and what steps can be taken to ensure it does not happen again. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;We will continue to keep you updated.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;According to &lt;a href="http://www.google.com/safebrowsing/diagnostic?site=sbs.com.au" target="_blank"&gt;Google Safe Browsing&lt;/a&gt;, the malicious domains implicated included&lt;strong&gt; manx.in, jongunn.gv.vg, sxkoubei.gv.vg, tppkuban.ru, zondgroup.com&lt;/strong&gt; and &lt;strong&gt;hiddenseo.ru&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;sbs.com.au are by no means the only victims. A bit of digging finds other sites affected by related malicious domains, including bestoftexas.com, dnronline.com, hdtvmagazine.com, mcleodgaming.com, rxmuscle.com, cyclilngcentralshop.com, theworldgame.com.au, obsessedwithfilm.com.&lt;/p&gt;  &lt;p&gt;I’ve been able to track down a blog entry describing what happened &lt;a href="http://ingramtech.com/?p=503" target="_blank"&gt;here&lt;/a&gt;.&amp;#160; I quote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;One of our computers was infected on Thursday night after visiting the Tour de France tracker page on the SBS website. The malware popped up an Adobe Flash upgrade box that was incredibly realistic. We both checked it and then clicked OK. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Things then went weird the following night when the tracker was revisited. The desktop disappeared and the computer opened random websites. I checked and there were strange processes. I tried to shut them down, but it didn’t work. The malware disabled the windows desktop and made all the files on the hard drive hidden, but didn’t actually delete them. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;This computer had an up to date enterprise-managed anti-virus program installed. Somehow the malware got passed this and then proceeded to cause us trouble.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Digging a little deeper, we find evidence that heraldsun.com.au was also affected by an attack on or about the 13th of July:   &lt;br /&gt;&lt;a href="http://www.smh.com.au/business/news-apologises-for-website-virus-after-hack-attack-20110713-1hdeh.html#ixzz1SNGFxxRq" target="_blank"&gt;http://www.smh.com.au/business/news-apologises-for-website-virus-after-hack-attack-20110713-1hdeh.html#ixzz1SNGFxxRq&lt;/a&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;The Herald &amp;amp; Weekly Times, publishers of heraldsun.com.au, can confirm that we did have a hacking attack on the Herald Sun web site on Monday July 11,&amp;quot; he said. &amp;quot;The attack attached malware on some files on the site. … We have since addressed the issue, but we are not in a position to release any further details on the basis that it may provide information for further attacks,&lt;/em&gt;&amp;quot;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;According to this &lt;a href="http://forums.whirlpool.net.au/forum-replies.cfm?t=1735472" target="_blank"&gt;forum conversation&lt;/a&gt;, Norton detected the heraldsun.com.au incident as Blackhole Toolkit.&amp;#160; Blackhole Toolkit is a nasty piece of work that takes advantage of various security exploits and can be tied in with fake security software (&lt;a href="http://www.symantec.com/connect/blogs/blackhole-theory" target="_blank"&gt;see here&lt;/a&gt;).&amp;#160; Interestingly, the Blackhole Toolkit has been implicated in the &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2011/07/14/1796179.aspx" target="_blank"&gt;LinkedIn Spam&lt;/a&gt; emails I mentioned the other day.&lt;/p&gt;  &lt;p&gt;It just goes to show, the miscreants behind all of these goings-on have their fingers in lots of different pies.&lt;/p&gt;  &lt;p&gt;Google Safe Browsing gives no indication that there has been trouble at smh.com.au or heraldsun.com.au.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1796412" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Please treat content from aegadvancedmedia.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2010/07/29/1774915.aspx</link><pubDate>Thu, 29 Jul 2010 10:05:13 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1774915</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1774915</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2010/07/29/1774915.aspx#comments</comments><description>&lt;p&gt;Nokia Theatre L.A. Live (nokiatheatrelalive.com) is serving exploits via aegadvancedmedia.com&lt;/p&gt;  &lt;p&gt;Historical badness at aegadvancedmedia.com (btw, homedepotcenter.com is still serving exploits – stay away from there too):   &lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=aegadvancedmedia.com" target="_blank"&gt;http://www.google.com/safebrowsing/diagnostic?site=aegadvancedmedia.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="exploit" alt="exploit" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8030.exploit_5F00_6AC2D72F.jpg" width="1024" height="640" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Malicious content (note the 1x1 iframe):&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3250.image_5F00_138F6FA9.png" width="1024" height="619" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Analysis of content from the IP address 85.234.190.13:   &lt;br /&gt;&lt;a href="http://wepawet.cs.ucsb.edu/view.php?hash=63e7a8a467205c6c2d6c078de506b30c&amp;amp;t=1280392935&amp;amp;type=js" target="_blank"&gt;http://wepawet.cs.ucsb.edu/view.php?hash=63e7a8a467205c6c2d6c078de506b30c&amp;amp;t=1280392935&amp;amp;type=js&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Historical badness at 85.234.190.13:   &lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=85.234.190.13" target="_blank"&gt;http://www.google.com/safebrowsing/diagnostic?site=85.234.190.13&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Other bad stuff in the IP range:   &lt;br /&gt;&lt;a href="http://www.malwaredomainlist.com/mdl.php?search=85.234.190&amp;amp;colsearch=All&amp;amp;quantity=50" target="_blank"&gt;http://www.malwaredomainlist.com/mdl.php?search=85.234.190&amp;amp;colsearch=All&amp;amp;quantity=50&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;85.234.190.13 is in Latvia - Latvia Riga Docsis Ip Pool For Cable Customers   &lt;br /&gt;&lt;/p&gt;  &lt;p&gt;Other bad stuff is seen coming from 194.8.250.227 (Paraguay Donstroy Ltd) – historical badness there too:   &lt;br /&gt;&lt;a href="http://www.google.com/safebrowsing/diagnostic?site=194.8.250.227" target="_blank"&gt;http://www.google.com/safebrowsing/diagnostic?site=194.8.250.227&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Interestingly, an analysis of the content loaded from 194.8.250.227 points to fake AV:   &lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/b0becacf524a1d04943007da7284bc419245bf26a411a1667df06e647eabadc6-1280394361" target="_blank"&gt;http://www.virustotal.com/analisis/b0becacf524a1d04943007da7284bc419245bf26a411a1667df06e647eabadc6-1280394361&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Not surprising considering the IP range history:   &lt;br /&gt;&lt;a href="http://www.malwaredomainlist.com/mdl.php?search=194.8.250&amp;amp;colsearch=All&amp;amp;quantity=50" target="_blank"&gt;http://www.malwaredomainlist.com/mdl.php?search=194.8.250&amp;amp;colsearch=All&amp;amp;quantity=50&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;There is also an attempt to infect systems using a vulnerability in Adobe Reader and Acrobat 8.0 through 9.2 (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4324" target="_blank"&gt;Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009&lt;/a&gt;)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1774915" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Sometimes it isn’t malvertizing….</title><link>http://msmvps.com/blogs/spywaresucks/archive/2010/04/26/1764284.aspx</link><pubDate>Mon, 26 Apr 2010 09:54:11 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1764284</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1764284</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2010/04/26/1764284.aspx#comments</comments><description>&lt;p&gt;I’m still keeping an eye on the Farm Town forums, now that they’ve caught my eye because of the malvertizing incident and the &lt;a href="http://www.slashkey.com/forum/showthread.php?p=3451306#post3451306" target="_blank"&gt;amazing 30+ page complaint thread on their forums&lt;/a&gt; (all of the old posts were deleted from that thread on or close to the 20th of April, btw).&lt;/p&gt;  &lt;p&gt;Anyway, the complaint seen in the screenshot below is one of the few posts that remain in the thread, and I’ve been watching to see what sort of advice is proffered.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0508.image_5F00_3FD3F937.png" width="798" height="232" /&gt; &lt;/p&gt;  &lt;p&gt;One thing immediately jumps out at you, don’t it, that make you suspect that the problem is *NOT* a bad advertisement, but rather &lt;u&gt;a virus alert triggered by content from the Farm Town application itself&lt;/u&gt;:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;The alert was triggered by “&lt;strong&gt;poppy[1].swf&lt;/strong&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The Farm Town application uses a “poppy.swf” as well as myriad other “SWF” to display various farm assets:&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4237.image_5F00_12E3B7BE.png" width="419" height="293" /&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Ok, so what about “bloodhound.exploit.52” – what is that?   &lt;br /&gt;&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2005-111115-4810-99" target="_blank"&gt;http://www.symantec.com/security_response/writeup.jsp?docid=2005-111115-4810-99&lt;/a&gt;    &lt;br /&gt;http://www.adobe.com/devnet/security/security_zone/mpsb05-07.html&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;“Bloodhound.Exploit.52 is a heuristic detection for the Flash Player 7 Improper Memory Access Vulnerability. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;An attacker who exploits this vulnerability could perform a denial-of-service, or potentially execute arbitrary code with the privileges of the logged-on user. The exploit is triggered by viewing a specially crafted Macromedia Flash file. This is usually hosted on a web page.”&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In short, assuming the server at cdn.slashkey.com has not been hacked, and assuming that the file “poppy.swf” that is being served by cdn.slashkey.com has not been replaced with a fake one that tries to take advantage of the Flash vulnerability, then I think we can safely assume that the virus alert was a false positive.&amp;#160; Certainly, the fact that the SWF detected is named “poppy[1].swf” makes it extremely unlikely that the alert was being triggered by any advertisement that was being displayed (the fact that there is a [1] appended to the name of the SWF simply means that there was already a SWF named poppy.swf on the computer in question, so the new copy was downloaded and saved but renamed).&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Anyway, SillySandy hasn’t logged in at the Farm Town forums since she posted her last message so I think we can assume that she has abandoned the topic.&amp;#160; And it is probably not worth posting to the thread in question to submit my theory on the incident because &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2010/04/14/1763406.aspx" target="_blank"&gt;my last few posts to that thread were moderated, and were not allowed to go live&lt;/a&gt; AND my forum account was locked down so much I couldn’t even edit my own profile details, or view anybody else’s public profile.&amp;#160; Not only that, a couple of posts by other people were deleted before a moderator went ahead and got rid of the whole lot (as evidenced by the “Reply to Thread” emails that I received that quoted messages that were no longer there by the time I went to review the thread).&amp;#160; I haven’t received any correspondence to tell me why my posts were not allowed to go live, or to tell me that my profile had been locked down, or why, or if/when the moderation would be lifted.&amp;#160; All in all, the place is a little too revisionist for my tastes.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;The only public response to SillySandy has been:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/7532.image_5F00_18E5975D.png" width="837" height="394" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Further info from SillySandy:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4214.image_5F00_5F202127.png" width="848" height="497" /&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2158.image_5F00_6836EF6C.png" width="266" height="135" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1764284" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Malvertizing at boingboing.net</title><link>http://msmvps.com/blogs/spywaresucks/archive/2010/01/13/1751372.aspx</link><pubDate>Wed, 13 Jan 2010 08:12:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1751372</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1751372</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2010/01/13/1751372.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 0px 20px 20px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="right" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/6378.image_5F00_4FF58031.png" width="123" height="526" /&gt; &lt;/p&gt;  &lt;p&gt;Original source: Dynamoo   &lt;br /&gt;&lt;a title="http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html" href="http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html" target="_blank"&gt;http://www.dynamoo.com/blog/2010/01/boingboingnet-bootcampmediacom-ad-leads.html&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;We have seen problems at bootcampmedia for a LONG time (&lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210#" target="_blank"&gt;at least a year&lt;/a&gt;) – Jamie Dalgetty needs to start cleaning up bootcampmedia.&lt;/p&gt;  &lt;p&gt;Historical evidence:   &lt;br /&gt;&lt;a href="http://www.google.com/cse?cx=007665253733268001951:qtjb7x6vodw&amp;amp;ie=UTF-8&amp;amp;q=bootcampmedia&amp;amp;sa=Search&amp;amp;siteurl=www.google.com/cse/home%3Fcx%3D007665253733268001951:qtjb7x6vodw" target="_blank"&gt;http://www.google.com/cse?cx=007665253733268001951:qtjb7x6vodw&amp;amp;ie=UTF-8&amp;amp;q=bootcampmedia&amp;amp;sa=Search&amp;amp;siteurl=www.google.com/cse/home%3Fcx%3D007665253733268001951:qtjb7x6vodw&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Now, I’ve been able to reproduce Dynamoo’s findings, but I saw a different advertisement (I’m sure I’ve seen that fake craigslist advert before), and different domains.&lt;/p&gt;  &lt;p&gt;I bounced from bootcampmedia.com to firedogred.com to &lt;strong&gt;deliver.azrielwhereincozen.com&lt;/strong&gt; (which hosted the advert itself) to &lt;strong&gt;content.bookletjigsawsenam.com&lt;/strong&gt; (which redirected us to&lt;strong&gt; bonnapet.com&lt;/strong&gt;).&amp;#160; bonnapet.com is the domain that was used to attempt to download malicious content to my test machine (an attempt that was easily thwarted, thanks to IE8’s infobar).&lt;/p&gt;  &lt;p&gt;Domain details are below the screenshot.&lt;/p&gt;  &lt;p&gt;The malicious behaviour has been reported to Right Media (Yieldmanager) with supporting evidence.&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/4621.image_5F00_5EA1FB20.png" width="854" height="621" /&gt; &lt;/p&gt;  &lt;p&gt;bootcampmedia.com   &lt;br /&gt;ICANN Registrar: GODADDY    &lt;br /&gt;Created: 11 dECEMBER 2007 &lt;/p&gt;  &lt;p&gt;IP: 69.163.209.214 - New Dream Network LLC &lt;/p&gt;  &lt;p&gt;Shares IP with 26 other sites. &lt;/p&gt;  &lt;p&gt;Registrant hidden by domainsbyproxy.com &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;firedogred.com   &lt;br /&gt;ICANN Registrar: GODADDY    &lt;br /&gt;Created:15 September 2009 &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - Godaddy.com, inc. &lt;/p&gt;  &lt;p&gt;Registrant - anonymised...   &lt;br /&gt;Domain Owner    &lt;br /&gt;15156 SW 5th    &lt;br /&gt;Scottsdale, Arizona 85260    &lt;br /&gt;USA &lt;/p&gt;  &lt;p&gt;Aren&amp;#39;t 555 phone numbers always fake? 800 555 1212 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;azrielwhereincozen.com   &lt;br /&gt;ICANN Registrar: GODADDY    &lt;br /&gt;Created: 7 January 2010 &lt;/p&gt;  &lt;p&gt;IP: 74.207.232.202 - New Jersey - Absecon, Linode &lt;/p&gt;  &lt;p&gt;Registrant hidden behind domainsbyproxy.com &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;bookletjigsawsenam.com   &lt;br /&gt;ICANN Registrar: GODADDY    &lt;br /&gt;Created: 7 January 2010 &lt;/p&gt;  &lt;p&gt;IP: 69.164.196.55 - New Jersey - Absecon, Linode &lt;/p&gt;  &lt;p&gt;Registrant hidden behind domainsbyproxy.com &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;bonnapet.com   &lt;br /&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created: 11 January 2010 &lt;/p&gt;  &lt;p&gt;IP: 217.2.114.40 - Berlin - Netdirekt E.K. &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Wade Cook (wade.cooke@yahoo.com)    &lt;br /&gt;12 Hull Street    &lt;br /&gt;Boston MA 02113    &lt;br /&gt;US&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1751372" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Please treat content from trendbanner.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx</link><pubDate>Sat, 12 Sep 2009 09:16:19 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1722754</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1722754</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/09/12/1722754.aspx#comments</comments><description>&lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5488.image_5F00_67DFCC06.png" width="550" height="261" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;It has been implicated in the facilitation of malvertizing that attempts to infect computers via PDF exploit&lt;/p&gt;  &lt;p&gt;The way it works is as follows:&lt;/p&gt;  &lt;p&gt;ad.trendbanner.com uses document.write to load the JS content at banner.pushbanner769.info&lt;/p&gt;  &lt;p&gt;banner.pushbanner769.info displays an advertisement, but also loads content from content from t.banner08092.com.&lt;/p&gt;  &lt;p&gt;t.banner08092.com simply redirects to blackwater-cuprumworks.net&lt;/p&gt;  &lt;p&gt;blackwater-cuprumworks.net includes a javascript (valla.js) which loads content from bintus-bahi.cn in a 0x0 iframe&lt;/p&gt;  &lt;p&gt;bintus-bahi.cn uses CVE-2009-0927 (Stack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab object) to infect vulnerable computers, as well as downloading other malware.&lt;/p&gt;  &lt;p&gt;The SWF (oneComesEthics.swf) is suspected to be malicious.&lt;/p&gt;  &lt;p&gt;Virustotal analysis of some content received via bintus-bahi.cn:&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476" href="http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476" target="_blank"&gt;http://www.virustotal.com/analisis/fbf39bcd9dea6e1233895e391c2d4bab22096cf7b76b8a6b760203f3d0efa76d-1252662476&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domain information&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;ad.trendbanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN REGISTRAR: GODADDY.COM, INC    &lt;br /&gt;Created 30 July 2009    &lt;br /&gt;NS47.DOMAINCONTROL.COM    &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 161.58.56.25 and 207.57.97.233 &lt;/p&gt;  &lt;p&gt;Shares IP with &lt;strong&gt;doityourselfbuilder.com&lt;/strong&gt; and &lt;strong&gt;banner.islandbanner.com&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;&lt;strong&gt;Modena Inc&lt;/strong&gt; (domains@modenainc.com) (associated with 102 domains)    &lt;br /&gt;921 SW Washington ST    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205    &lt;br /&gt;United States &lt;/p&gt;  &lt;p&gt;Modena Inc have a dubious history, with complaints as far back to 2005 about &amp;quot;spyware infested filesharing programs&amp;quot;, site scraping and 302 domain poisoning: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.freedomcrowsnest.org/forum/viewtopic.php?t=1416" target="_blank"&gt;http://www.freedomcrowsnest.org/forum/viewtopic.php?t=1416&lt;/a&gt;    &lt;br /&gt;&lt;a href="http://forum.abestweb.com/showthread.php?p=456066&amp;amp;mode=threaded#post456066" target="_blank"&gt;http://forum.abestweb.com/showthread.php?p=456066&amp;amp;mode=threaded#post456066&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Modena Inc domains were also part of the malvertizing incident that his digitalspy.co.uk:   &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;There is also a dishonorable mention at bluetack.co.uk (**10** different security exploits were used in that incident) - domains used were banners.exitexchange.com and count.exit1208.com:   &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=210&amp;amp;p=90509&amp;amp;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;It is interesting that ashoping.com was part of the incident recorded at bluetack.co.uk. The registrant, helen.nikolson@gmail.com, has been seen myriad times, in association with traffichunters.net (which we can tie to Innovative Marketing in the Ukraine):   &lt;br /&gt;&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx" target="_blank"&gt;http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;doityourselfbuilder.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: MELBOURNE IT, LTD D/B/A INTERNET NAMES WORLDWIDE    &lt;br /&gt;Created 10 June 2006    &lt;br /&gt;NS1.SECURE.NET    &lt;br /&gt;NS2.SECURE.NET &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Music Unlimited Inc    &lt;br /&gt;PO Box 1200    &lt;br /&gt;Jacksonville 97530 &lt;/p&gt;  &lt;p&gt;Admin Name:   &lt;br /&gt;David Sprunger (pptorders@playpianotoday.com) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;banner.islandbanner.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created 24 July 2009    &lt;br /&gt;NS45.DOMAINCONTROL.COM    &lt;br /&gt;NS46.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (shares IP with 11,039,738 other sites) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;&lt;strong&gt;Modena Inc&lt;/strong&gt; (domains@modenainc.com) (associated with 102 domains)    &lt;br /&gt;921 SW Washington Street    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;pussbanner769.info&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created 7 August 2009    &lt;br /&gt;NS47.DOMAINCONTROL.COM    &lt;br /&gt;NS48.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 (shares IP with 11,039,738 other sites) &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Domain Owner (trafficbuyer@gmail.com)    &lt;br /&gt;15156 SW 5th    &lt;br /&gt;Scottsdale    &lt;br /&gt;Arizona 85260    &lt;br /&gt;Tel: +1 8005551212 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;blackwater-cuprumworks.net&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created 7 September 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 213.155.2.112 - Namibia, Grinvich3, Vladimir Gubarenko &lt;/p&gt;  &lt;p&gt;Shares IP with the domains aw-work.net, awirons-work.com, sexamateur-hartcore.com and sleazy-dreamers.net &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Eduard Skobelev (eddiscobbi3@gmail.com)    &lt;br /&gt;ul. Starinskaya, d.1, kv. 92    &lt;br /&gt;g. Moskva    &lt;br /&gt;g. Moskva, 107009    &lt;br /&gt;RU    &lt;br /&gt;Tel: +7 4952243948 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;masterwood-works.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: NETWORK SOLUTIONS, LLC.    &lt;br /&gt;Created 19 February 1999    &lt;br /&gt;NS.WVT.NET    &lt;br /&gt;NS2.WVT.NET &lt;/p&gt;  &lt;p&gt;IP: 65.36.167.73 - Delaware, Newark, Hostmysite &lt;/p&gt;  &lt;p&gt;Shares IP with 395 other sites &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Master Wood-Works    &lt;br /&gt;4526 Olentangy River Road    &lt;br /&gt;Delaware, OH 43015    &lt;br /&gt;US &lt;/p&gt;  &lt;p&gt;Admin:   &lt;br /&gt;Steve Krengel (hostmaster@wvt.net) &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;bintus-bahi.cn&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: Chinese    &lt;br /&gt;Created 15 August 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET    &lt;br /&gt;NS3.EVERYDNS.NET    &lt;br /&gt;NS4.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 61.235.117.72 - Guangdong, Shenzen, China Railcom Guangdong Shenzhen Subbranch &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Cehhost, inc (owns about 84 other domains)    &lt;br /&gt;Lucas Steven (steven_lucas_2000@yahoo.com)&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;margin:10px 20px 20px 0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/1565.image_5F00_0E68EB58.png" width="1012" height="462" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1722754" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>DIRECTI action… or lack thereof…</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/23/1706154.aspx</link><pubDate>Thu, 23 Jul 2009 06:22:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1706154</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1706154</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/23/1706154.aspx#comments</comments><description>&lt;p&gt;Directi have “suspended” masters-woodworks.com, but NOT the almost identical masterwood-works.net, or the sites awiron-work.com, freshy-girls.com or sleazy-dreams.net&amp;#160; (all of which are on the same IP and have the same Registrant). &lt;/p&gt;  &lt;p&gt;They have also “suspended” viorfjoj-1.com (different IP, same registrant), but have NOT suspended viorfjoj-2.com or viorfjoj-3.com (again, same IP, same Registrant)&lt;/p&gt;  &lt;p&gt;Too little, too late. &lt;/p&gt;  &lt;p&gt;Bearing in mind my comments &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700470.aspx" target="_blank"&gt;here&lt;/a&gt; about adclickmate.net and adburau.net, I am beginning to wonder (again) just what is going on at DIRECTI.&amp;#160; It seems to me that they could do more to protect the Internet as a whole by investigating and suspending domains that are closely associated with bad behaviour – especially when there are multiple incidents of bad behaviour as dangerous as that we have been documenting these past few days.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1706154" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>More bad stuff from content.bannersulike.com, r.banner0709.com, worwink.com</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/23/1705977.aspx</link><pubDate>Thu, 23 Jul 2009 04:51:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1705977</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1705977</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/23/1705977.aspx#comments</comments><description>&lt;p&gt;Kimberley wrote about a couple of incidents on 18 July 2009 and again yesterday – they are not the same incidents as I have written about:   &lt;br /&gt;&lt;a href="http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=240#" target="_blank"&gt;http://www.bluetack.co.uk/forums/index.php?showtopic=18064&amp;amp;st=240#&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1705977" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Update re digitalspy.co.uk</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx</link><pubDate>Wed, 22 Jul 2009 03:52:49 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1704910</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1704910</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/22/1704910.aspx#comments</comments><description>&lt;p&gt;My apologies for the delay.&amp;#160; For what its worth, I received an email within 3 hours of my report to the ad network in question, advising me that the malicious creatives had been identified and deactivated.&lt;/p&gt;  &lt;p&gt;So, now to the details.&amp;#160; Technically, the incident was very similar to that which I wrote about &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/07/14/1700082.aspx" target="_blank"&gt;here&lt;/a&gt;, but there were some new domains involved, all of which should be treated with extreme caution.&lt;/p&gt;  &lt;p&gt;content.bannersulike.com   &lt;br /&gt;r.banner0709.com (Response = 302 Found moved to &amp;quot;masters-woodworks.com&amp;quot; and “worwink.com”)    &lt;br /&gt;masters-woodworks.com    &lt;br /&gt;worwink.com    &lt;br /&gt;xn-18ba.example.com (example.com is a domain reserved for use in documentation and not available for registration (RFC 2606, Section 3))    &lt;br /&gt;viorfjoj-1.com&lt;/p&gt;  &lt;p&gt;There are screenshots of the advertisements displaying during a hijack, and other events, at the end of this article.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;masters-woodworks.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created 8 June 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 213.155.2.112 - Namibia - Grinvich3 - Vladimir Gubarenko &lt;/p&gt;  &lt;p&gt;Shares IP with awiron-work.com, freshy-girls.com, masterwood-works.net, sleazy-dreams.net &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Dmitry Ostupin (conroetxwelc@gmail.com)    &lt;br /&gt;ul. Malaya Semenovskaya, d.5, kv. 28    &lt;br /&gt;g. Moskva, 107023    &lt;br /&gt;RU    &lt;br /&gt;Tel: +7 495 224 0537 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;viorfjoj-1.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: DIRECTI    &lt;br /&gt;Created: 8 July 2009    &lt;br /&gt;NS1.EVERYDNS.NET    &lt;br /&gt;NS2.EVERYDNS.NET &lt;/p&gt;  &lt;p&gt;IP: 221.5.74.34 - Guangdong, Guangzhou, China Unicom Guangdong Province Network &lt;/p&gt;  &lt;p&gt;Shares IP with 24-stunden-voegeln.com, Leevitra-viaagra.com, Original-vjiagra.com, Originalpillen.com, P0tenz-pillen.com, P0tenzpillen-bestellung.com, P0tenzpillen.com, Pillensh0p.com, Potent-hart-guenstig.com, Potenz-pillen-dienst.com, Potenzpillen-24.com, Potenzpillen-einkaufen.com, Potenzpillen-service.com, Potenzpusher-bestellen.com, Sichere-viagra-bestellung.com, Viaagra-bestellung.com, Viaagra-kaufen.com, Viagra-ohne-zoll.com, Viorfjoj-1.com, Viorfjoj-2.com, Viorfjoj-3.com, Vjiagra-einkaufen.com, Vjiagra-ohne-zoll.com, Vsalso-dkgj1.com, Vsalso-dkgj2.com, Vsalso-dkgj3.com &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Dmitry Ostupin (conroetxwelc@gmail.com)    &lt;br /&gt;ul. Malaya Semenovskaya, d.5, kv. 28    &lt;br /&gt;g. Moskva, 107023    &lt;br /&gt;RU    &lt;br /&gt;Tel: +7 495 224 0537 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;worwink.com     &lt;br /&gt;&lt;/strong&gt;ICANN Registrar: KEY-SYSTEMS GMBH    &lt;br /&gt;Created: 15 July 2009    &lt;br /&gt;NS1.WORWINK.COM    &lt;br /&gt;NS2.WORWINK.COM &lt;/p&gt;  &lt;p&gt;IP: 212.95.37.186 - Netdirekt E.k &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Mark Vinson (mvinson98@count.com)    &lt;br /&gt;8 Panorama Cir    &lt;br /&gt;Kunkletown PA US    &lt;br /&gt;Phone: 6106817173 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;r.banner0709.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created: 29 June 2009    &lt;br /&gt;NS37.DOMAINCONTROL.COM    &lt;br /&gt;NS38.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - Arizona, Scottsdale, Godaddy.com Inc &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Bryan Hunter (bryan@modenainc.com)    &lt;br /&gt;921 SW Washington Street    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon, 97205 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;content.bannersulike.com&lt;/strong&gt;    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC    &lt;br /&gt;Created: 13 July 2009    &lt;br /&gt;NS45.DOMAINCONTROL.COM    &lt;br /&gt;NS46.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 68.178.232.100 - Arizona, Scottsdale - Godaddy.com Inc &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Modena Inc    &lt;br /&gt;921 SW Washington St    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon 97205 &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;modenainc.com&lt;/strong&gt; (because of its association with bannersulike.com and banner0709.com)    &lt;br /&gt;ICANN Registrar: GODADDY.COM, INC.    &lt;br /&gt;Created: 21 February 2001    &lt;br /&gt;NS15.DOMAINCONTROL.COM    &lt;br /&gt;NS16.DOMAINCONTROL.COM &lt;/p&gt;  &lt;p&gt;IP: 38.100.208.45 - Oregon, Portland, Psinet Inc &lt;/p&gt;  &lt;p&gt;Shares IP with 117 other sites &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Incorporated, Modena (domains@modenainc.com)    &lt;br /&gt;921 SW Washington St    &lt;br /&gt;Suite 228    &lt;br /&gt;Portland, Oregon, 97205    &lt;br /&gt;Tel: 5032411091 &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8831.image_5F00_71C39B6B.png" width="335" height="272" /&gt;&amp;#160;&amp;#160; &lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/8400.image_5F00_597FE576.png" width="334" height="288" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2146.image_5F00_1E53BBBE.png" width="755" height="119" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0027.image_5F00_283DCE8B.png" width="756" height="119" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5873.image_5F00_6902359E.png" width="745" height="193" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0027.image_5F00_42C78E59.png" width="614" height="345" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3125.image_5F00_73A462BB.png" width="831" height="476" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0412.image_5F00_697C496B.png" width="510" height="328" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2664.image_5F00_08C411A1.png" width="548" height="483" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Malware downloaded – analysis results&lt;/strong&gt;:    &lt;br /&gt;&lt;a title="http://www.virustotal.com/analisis/3c9b52614c508cd168c3bd1d96dff6b3a6374a63d2334c754a31463bad791a5a-1248226154" href="http://www.virustotal.com/analisis/3c9b52614c508cd168c3bd1d96dff6b3a6374a63d2334c754a31463bad791a5a-1248226154" target="_blank"&gt;http://www.virustotal.com/analisis/3c9b52614c508cd168c3bd1d96dff6b3a6374a63d2334c754a31463bad791a5a-1248226154&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Another incident….&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3644.image_5F00_4F65ACFE.png" width="559" height="369" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/3225.image_5F00_4053EF86.png" width="761" height="901" /&gt;&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/2555.image_5F00_00733E84.png" width="680" height="447" /&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1704910" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: please be extremely cautious when visiting digitalspy.co.uk</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/07/20/1703278.aspx</link><pubDate>Mon, 20 Jul 2009 08:51:04 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1703278</guid><dc:creator>sandi</dc:creator><slash:comments>2</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1703278</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/07/20/1703278.aspx#comments</comments><description>&lt;p&gt;There are malvertizements being displayed on digitalspy.co.uk that attempt to take advantage of various security vulnerabilities.&amp;#160; Research and evidence-gathering is happening as I type, and the appropriate parties will be contacted on an urgent basis.&lt;/p&gt;  &lt;p&gt;For the time being, be extremely cautious when visiting the web site.&amp;#160; There is a thread warning of malicious content that started back on 30 May 2009 which I found, coincidentally, while researching antventure.com.&lt;/p&gt;  &lt;p&gt;I’ll post more information soon.&lt;/p&gt;  &lt;p&gt;BTW, the incident is technically identical to the yieldmanager incident that I reported on a few days ago, but there are a few new domains in the mix – no antventure.com but there is a visually identical advertisement featuring Expedia, and an Acer advert, and an iPhone advert and one for contact lenses.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1703278" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>ALERT: Please treat the domain statisticsishere.com and measurehits.com with extreme caution</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676761.aspx</link><pubDate>Mon, 09 Mar 2009 01:04:03 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1676761</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1676761</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676761.aspx#comments</comments><description>&lt;p&gt;I received this email a short while ago:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;We have been getting a lot of ads accessing scripts from this domain statisticsishere.com. So far there is no malware redirect or download but this domain looks suspicious having been created less than a week.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I have to agree that the domain is suspicious.&amp;#160; &lt;/p&gt;  &lt;p&gt;Before we get started, it is important that I remind you that the fact that there is no suspicious behavior *at the moment* is of no comfort.&amp;#160; The crooks behind malvertizing have been known to establish a relationship with potential victims by running one or more “clean” campaigns, thereby building a level of trust between them and their victims, before hitting their victims with malvertizing.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Let’s look at the WHOIS information for statisticsishere.com:&lt;/p&gt;  &lt;p&gt;ICANN Registrar: YESNIC CO. LTD.   &lt;br /&gt;Created: 5 March 2009    &lt;br /&gt;NS1.STATISTICSISHERE.COM - IP 116.50.15.1 (HostFresh)    &lt;br /&gt;NS2.STATISTICSISHERE.COM - IP 116.50.15.1 (HostFresh)    &lt;br /&gt;NS3.STATISTICSISHERE.COM - IP 89.149.226.121 (Netdirekt)&lt;/p&gt;  &lt;p&gt;IP: 195.62.37.14 - Sardegna, Olbia, Geonic.net Ltd &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Gabriel Jenks (gabrielcjenks17@mail.com)    &lt;br /&gt;3515 Cooks Mine Road    &lt;br /&gt;88101    &lt;br /&gt;US    &lt;br /&gt;Tel: 1 505-763-5453 &lt;/p&gt;  &lt;p&gt;First of all, HostFresh and Netdirekt have both been problematic in the past but, more importantly, &lt;strong&gt;the postcode (88101) and phone number (505-763-5453) map to Clovis, New Mexico.&amp;#160; I cannot find a &amp;quot;Cooks Mine Road&amp;quot; in Clovis.&amp;#160; Not only that, the phone number listed in the WHOIS is apparently owned by a Brian A Jones and Delinda K Jones, not a Gabriel Jenks.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_0E071297.png" width="663" height="256" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Now, let’s look at the NS for the domain statisticsishere.com: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP of NS1.STATISTICSISHERE.COM - 116.50.15.1     &lt;br /&gt;IP of NS2.STATISTICSISHERE.COM - 116.50.15.1&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A Records&lt;/strong&gt; - you will see some very familiar domains.... &lt;/p&gt;  &lt;p&gt;mail.xxx-online.in   &lt;br /&gt;ns2.02sta.com    &lt;br /&gt;&lt;strong&gt;ns2.admediastats.com     &lt;br /&gt;ns2.onlinestatsmanager.com      &lt;br /&gt;ns2.promorotation.com      &lt;br /&gt;ns2.securityclick.net      &lt;br /&gt;ns2.st-athome.net      &lt;br /&gt;ns2.st-aticglobalsources.com      &lt;br /&gt;ns2.statisticsishere.com      &lt;br /&gt;ns2.themonitoring.net      &lt;br /&gt;ns2.traffic-analytics.com      &lt;br /&gt;ns2.waytotheprofit.com      &lt;br /&gt;&lt;/strong&gt;www.xxx-online.in &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using NS1.STATISTICSISHERE.COM as nameserver&lt;/strong&gt;: statisticsishere.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using NS1.STATISTICSISHERE.COM as nameserver under another name&lt;/strong&gt; (again, you&amp;#39;re going to see some familiar names): &lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;statisticsishere.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Nameservers missing in zone: &lt;/p&gt;  &lt;p&gt;ns1.statisticsishere.com   &lt;br /&gt;ns2.statisticsishere.com    &lt;br /&gt;ns3.statisticsishere.com &lt;/p&gt;  &lt;p&gt;Used as nameserver but missing in zone: statisticsishere.com &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;IP of NS3.STATISTICSISHERE.COM - 89.149.226.121 &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;PTRS of IP numbers&lt;/strong&gt;: 89-149-226-121.internetserviceteam.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A Records&lt;/strong&gt; (again, lots of familiar names): &lt;/p&gt;  &lt;p&gt;89-149-226-121.internetserviceteam.com   &lt;br /&gt;ns3.02sta.com    &lt;br /&gt;&lt;strong&gt;ns3.admediastats.com     &lt;br /&gt;ns3.promorotation.com      &lt;br /&gt;ns3.securityclick.net      &lt;br /&gt;ns3.st-athome.net      &lt;br /&gt;ns3.st-aticglobalsources.com      &lt;br /&gt;ns3.themonitoring.net      &lt;br /&gt;ns3.traffic-analytics.com      &lt;br /&gt;ns3.waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver&lt;/strong&gt;:&amp;#160; statisticsishere.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver under another name&lt;/strong&gt;: &lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Nameservers missing in zone: &lt;/p&gt;  &lt;p&gt;ns1.statisticsishere.com   &lt;br /&gt;ns2.statisticsishere.com    &lt;br /&gt;ns3.statisticsishere.com &lt;/p&gt;  &lt;p&gt;Used as nameserver but missing in zone: statisticsishere.com&lt;/p&gt;  &lt;p&gt;*****&lt;/p&gt;  &lt;p&gt;According to a Registrant search, “Gabriel Jenks” owns another domain, being &lt;strong&gt;measurehits.com&lt;/strong&gt;, which should also be treated with extreme caution.&lt;/p&gt;  &lt;p&gt;ICANN Registrar: YESNIC CO. LTD.   &lt;br /&gt;Created: 26 February 2009 &lt;/p&gt;  &lt;p&gt;NS1.MEASUREHITS.COM (116.50.15.1)   &lt;br /&gt;NS2.MEASUREHITS.COM (89.149.226.121 &lt;/p&gt;  &lt;p&gt;IP: 212.117.165.128 - Luxembourg, Root Esolutions &lt;/p&gt;  &lt;p&gt;Registrant:   &lt;br /&gt;Gabriel Jenks (gabrielcjenks17@mail.com)    &lt;br /&gt;3515 Cooks Mine Road    &lt;br /&gt;88101    &lt;br /&gt;US    &lt;br /&gt;Tel: 1 505-763-5453 &lt;/p&gt;  &lt;p&gt;Shares IP address with the following domains, all of which should be treated with extreme caution. &lt;/p&gt;  &lt;p&gt;advertpanda.com, clickanalytic.com, extrabigad.com, greatad.net, securityclick.net, waytotheprofit.com, whoisadvert.com &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;NS1.MEASUREHITS.COM &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A-Records: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;mail.xxx-online.in   &lt;br /&gt;ns1.statisticsishere.com    &lt;br /&gt;ns2.02sta.com    &lt;br /&gt;&lt;strong&gt;ns2.admediastats.com     &lt;br /&gt;ns2.onlinestatsmanager.com      &lt;br /&gt;ns2.promorotation.com      &lt;br /&gt;ns2.securityclick.net      &lt;br /&gt;ns2.st-athome.net      &lt;br /&gt;ns2.st-aticglobalsources.com      &lt;br /&gt;ns2.statisticsishere.com      &lt;br /&gt;ns2.themonitoring.net      &lt;br /&gt;ns2.traffic-analytics.com      &lt;br /&gt;ns2.waytotheprofit.com      &lt;br /&gt;&lt;/strong&gt;www.xxx-online.in &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver under another name: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;statisticsishere.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;NS2.MEASUREHITS.COM &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;PTRS of IP numbers&lt;/strong&gt; - 89-149-226-121.internetserviceteam.com &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Hostnames sharing IP with A-Records: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;89-149-226-121.internetserviceteam.com   &lt;br /&gt;ns3.02sta.com    &lt;br /&gt;&lt;strong&gt;ns3.admediastats.com     &lt;br /&gt;ns3.promorotation.com      &lt;br /&gt;ns3.securityclick.net      &lt;br /&gt;ns3.st-athome.net      &lt;br /&gt;ns3.st-aticglobalsources.com      &lt;br /&gt;ns3.statisticsishere.com      &lt;br /&gt;ns3.themonitoring.net      &lt;br /&gt;ns3.traffic-analytics.com      &lt;br /&gt;ns3.waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Domains using this as nameserver under another name: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;02sta.com   &lt;br /&gt;promorotation.com    &lt;br /&gt;&lt;strong&gt;st-athome.net     &lt;br /&gt;st-aticglobalsources.com      &lt;br /&gt;statisticsishere.com      &lt;br /&gt;themonitoring.net      &lt;br /&gt;traffic-analytics.com      &lt;br /&gt;waytotheprofit.com &lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1676761" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Interesting comment – Best Western malvertizing</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/26/1674103.aspx</link><pubDate>Thu, 26 Feb 2009 15:46:17 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1674103</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1674103</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/26/1674103.aspx#comments</comments><description>&lt;p&gt;The comment was posted &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/11/1656447.aspx#1673880" target="_blank"&gt;here&lt;/a&gt;.&amp;#160; I quote:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“&lt;em&gt;My company was approached by a client claiming to represent Best Western with a lower tech version of this.&amp;#160; We were give a static JPG, third one from the top and instructions to paste some odd-looking Javascript with the image.&amp;#160; &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;I ran the code in AddOps tools and it did nothing.&amp;#160; Getting suspicious I checked the src URL for the Javascript which was &amp;quot;http:// st-aticglobalsources.com&amp;quot; and found a lot of trouble associated with it.&amp;#160; &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;We refused to run the ad with the code. Client claimed ignorance saying code came from their client and would provide new tags.&amp;#160; New tags arrived, similar to the first but sourcing the J-script from &amp;quot;http:// st-ation-appraisals.net&amp;quot; this time.&amp;#160; Running this code through AdOps tools at least generates a Best Western banner, but I ran the URL through search engines, found associated with ITmeter INC, and did not run the ad.&lt;/em&gt;”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;As my regular readers will know, both of the URLs are well known to those of us who study malvertizing.&amp;#160; I hope that the commentator will tell us the name and email addresses used by the person who tried to sell them the malicious advertisement.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;st-aticglobalsources.com (79.135.187.86 - Istanbul - Istanbul - Serv2u.com International Backbone Tr)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Registrant Contact:   &lt;br /&gt;&amp;#160;&amp;#160; ITmeter INC    &lt;br /&gt;&amp;#160;&amp;#160; Sergey Belonozhko (sergbelo@gmail.com)    &lt;br /&gt;&amp;#160;&amp;#160; Fax:&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160; Dmitrienko 7    &lt;br /&gt;&amp;#160;&amp;#160; Odessa, State 65000    &lt;br /&gt;&amp;#160;&amp;#160; UA&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;st-ation-appraisals.net (79.135.187.89 - Istanbul - Istanbul - Serv2u.com International Backbone Tr)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Registrant Contact:   &lt;br /&gt;&amp;#160;&amp;#160; ITmeter INC    &lt;br /&gt;&amp;#160;&amp;#160; Sergey Belonozhko (sergbelo@gmail.com)    &lt;br /&gt;&amp;#160;&amp;#160; Fax:&amp;#160; &lt;br /&gt;&amp;#160;&amp;#160; Dmitrienko 7    &lt;br /&gt;&amp;#160;&amp;#160; Odessa, State 65000    &lt;br /&gt;&amp;#160;&amp;#160; UA&lt;/p&gt;  &lt;p&gt;It is important to note that although both bad domains have “dedicated hosting” and unique IP addresses, they are both hosted by the same company, and are within the same IP range.&amp;#160; A check of the entire IP range, 79.135.187.% reveals 266 domains, all of which should be treated with extreme caution.&lt;/p&gt;  &lt;p&gt;1spam.ru | 1yandex.ru | Abusehost.ru | Abuzhost.ru | Advert1.ru | Aloincognito.ru | Buildhost.ru | Business-orders.ru | Cammin.ru | Compaq-hp-dv.ru | Cpammagazin4.ru | Detiamdo.ru | Email-s.ru | Email-spam.ru | Emailspam.ru | Enterboom.ru | Evroreklama.ru | Farma-reklama.ru | Flovermag.ru | Forum-it.ru | Generatorcompany.ru | Goohost.ru | Goosoft.ru | Gottobe.ru | Hotmailer.ru | Hrumer2007.ru | Igrushki-detiam.ru | Irkmailer.ru | Junar-trade.com | Kuklasex.ru | Magazinreklamy.ru | Mailadvertising.ru | Mnogonarodu.ru | Montenegrovilla.ru | Neintim.ru | Nochklub.ru | Notebook7.ru | O-la-la.ru | Online-email.ru | Online-mailer.ru | Online-master.ru | Online-standart.ru | Ppkurort.ru | Proektclty.ru | Reklamabiznesa.ru | Reklamict.ru | Reklmagazin.ru | Robotraff.ru | Rukinomania.ru | Saitbaz.ru | Seosuper.ru | Setevaya-reklama.ru | Shablon1.ru | Sitepostroim.ru | Spam502.ru | Spamarena.ru | Spamchik.ru | Spamim.ru | Spammagazin.ru | Spammagazine3.ru | Spammagazine5.ru | Spmagazin.ru | Starshe18.ru | Super-fuel-max.ru | Super-mailer.ru | Turistmag.ru | Wmir.biz | Wreklama.ru | Wsws.ru | Wtorg.ru | Xmailer.ru | Yandex1.ru | L-state.com | P-state.com | R-state.com | V-state.com | 4utraffic.cc | 4utraffic.net | Cashpopup.cc | Cashpopup.info | Newprogress.tv | Einrock.com | Makomset.com | Ribcot.com | Megavipsite.cn | Installing.cc | Loader.cc | Windowscentersite.com | Tgspk.com | Statbroun.com | Loots-leg.com | Newprogress.asia | Newprogress.biz | Alertplump.com | Bdgerggggs.com | Beatstrust.com | Chiefgracious.com | Circlesensational.com | Clearorganized.com | Eagermulti.com | Fizzpeak.com | Fizzslick.com | Hardyfab.com | Humbleoxygen.com | Notablebase.com | Proudlucky.com | Royalmeek.com | Rx13.com | Safetyunselfish.com | Sdggfdfgd.com | Serviceclear.com | Sfdgsvddsdfs.com | Sgdfgdfgdf.com | Sgdfgsdfsddfgdf.com | Sjbisdgergess.com | Stayunsurpassed.com | Thankfulmountain.com | Topseductive.com | Usdrugstorebest.com | Westcharming.com | Zestloyal.com | Zipbold.com | Skype-security.net | Afrogruster.com | Agiromentop.com | Agrostergio.com | Akierodentos.com | Aportobrasok.com | Atopresorgo.com | Aviorebato.com | Awrentoblasgo.com | Beshragos.com | Counterprise.com | Diomertona.com | Dresmondas.com | Equalcrowd.ru | Frododkoone.com | Frododkotwo.com | Hortesoda.com | Kioretions.com | Kordanoser.com | Krombustor.com | Massachuret.com | Notifisarto.com | Privatesecuritycenter.com | Rx-online-order.com | Twopgoslyso.com | Filarmon.info | Gvatemal.biz | Jumpingo.org | Grandtraf.com | Loaddasig.com | Zetross.com | 5traff.cn | Axa3.cn | Beencn.cn | Centerifart.cn | Ftalyl.cn | Londoncn.cn | Mostdey.cn | Originalcn.cn | Traxxk.cn | Typecn.cn | Hibucks.com | Moviesforall.info | Musicscollection.com | Welovemovie.com | Ds1ff.com | Googlesearchingweb.net | Index938.com | 2ndattempt.net | Angelok.org | Anxietypedia.net | Anxinews.org | Any-doctor.net | Availmeds.com | Balmpro.net | Balzaks.net | Bighealthy.net | Bigremedy.net | Caremedicals.net | Delivery-services.net | Discountmeds.name | Docclive.net | Doctor11.net | Doctor5.net | Doctor6.net | Doctorlive.net | Doctorr.org | Easy-meds.org | Fresh-infa.net | Generecs.net | Generikes.net | Generiks.net | Getphen.net | Gomedy.net | Healtn.net | Helth-life.net | Hotnewlette.net | Hotnewslette.net | Hotnewsletter.net | Hotnewsletter.ru | Hydrophen.com | Index333.com | Index345.com | Lodono.com | Medguide.in | Medicalaz.net | Medsizi.net | Most900.com | Mostsearch.net | My-order.org | Myangst.net | Myhomemed.net | Noconsult.net | Normalmed.net | Opapapa.net | Pharmaenergi.net | Phenhydro.net | Rx-free.net | Rxfair.net | Rxneds.com | Rxneds.net | Savehealth.net | Search-traffic.net | Seedeals.net | Singleslady.com | Suicide-forum.com | Theclinical.net | Track-order.com | Trialpack.net | Vicod.net | Vicodi.net | Webadvices.net | Webremedies.net | Winyourhealth.net | Wwwhotnewsletter.net | &lt;strong&gt;Officialstat.net | Ne-wstat.net | Of-ficialstat.com | Ourstats-online.com | Statgroup.net | St-at-diagnostic-imaging.net | St-atetstr.com | Stats-manager-online.com | St-atgroup.net | Staticglobalsources.net | Traffic-ad-manager.com | Station-appraisals.com | St-athisranch.com | St-athisranch.net | St-athome.net | St-aticglobalsources.com | St-aticglobalsources.net | St-ation-appraisals.com | St-ation-appraisals.net | S-tatetstr.com | S-tathisranch.com | S-tathisranch.net | Track-your-stats.com | S-tatgroup.net | Freegreenstats.com | Of-ficialstat.net | Themonitoring.net | Statstrackingmanager.com | Traffic-analytics.com&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1674103" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>Lifestyles of the Rich and Infamous, and an update about the status of the FTC versus Innovative Marketing et al lawsuit</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx</link><pubDate>Tue, 10 Feb 2009 08:42:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1671117</guid><dc:creator>sandi</dc:creator><slash:comments>1</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1671117</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/10/1671117.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;ll include some history of events so that you can get a sense of perspective with regards to the time frame around these events.&amp;#160;&amp;#160; It is especially important to note that the FTC lawsuit is not the only problem that Jain is facing.&amp;#160; He has been indicted in the State of California and is facing several criminal charges there, and there are pending charges against him in Illinois.&amp;#160; Events relevant to the California criminal charges and the Illinois investigation are highlighted.&lt;/p&gt;  &lt;p&gt;You’ll see that the lifestyle enjoyed by Kristy Ross as revealed by her credit card statements was nothing if not lavish.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Defendants Kristy Ross and Sam Jain (who were (are?) boyfriend and girlfriend): &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;26 March 2008&lt;/u&gt; - US District Court, San Jose, California: USA v Shaileshkumar Jain - four counts being criminal copyright infringement, trafficking in counterfeit goods, wire fraud and mail fraud (for activities that took place in 2003) (CR-08-00197-HRL) (charges relate to events on 12 and 26 January and the sale of fake Symantec software).&amp;#160; The Grand Jury indictment requests the forfeiture of &amp;quot;approximately $13,522,080 in United States currency or after acquired assets traceable thereto&amp;quot;.&amp;#160; Sam Jain&amp;#39;s full name is Shaileshkumar Jain.&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;&amp;quot;late September&amp;quot; 2008&lt;/u&gt; - Ted W Cassman (he and his firm Arguedas, Cassman &amp;amp; Headley LLP represent(ed) Jain in the ongoing California criminal proceedings and the ongoing investigation in Illinois) met with Assistant US Attorney and two agents of the FBI in Chicago, Illinois.&amp;#160; The Assistant US Attorney &amp;quot;unequivocally stated that Mr Jain will be indicted for wire fraud and computer fraud charges as a result of the Illinois Investigation &amp;#39;sooner rather than later.&amp;#39; &amp;quot; (cite: Declaration of Ted W Cassman dated 18 December 2008)&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;u&gt;2 December 2008&lt;/u&gt; - FTC requests and receives a temporary restraining order. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;12 December 2008&lt;/u&gt; - temporary restraining order expires.&amp;#160; The defendants did not turn up in Court and they failed to comply with the TRO.&amp;#160; Order to show cause issued. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;17 December 2008&lt;/u&gt; - appearances entered for Mark D&amp;#39;Souza and Sam Jain.&amp;#160; Joint response to order to show cause filed by Jain and Ross, promising to &amp;quot;fully comply with the terms of the TRO and PI by 23 December 2008&amp;quot;&amp;#160; Mark D&amp;#39;Souza also files a response, promising to comply with the requirements of the TRO and PI by 4.00pm on 23 December 2008.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;18 December 2008&lt;/u&gt; - Cassman declaration signed describing the events of &amp;quot;late September&amp;quot; 2008. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;u&gt;23 December 2008&lt;/u&gt; - a letter was sent to FTC on 23 December by the law firm Patton Boggs explaining that Jain had no intention of complying with the Court orders because to do so &amp;quot;&lt;em&gt;would require Jain to incriminate himself&lt;/em&gt;&amp;quot; (the letter stated that Jain &amp;quot;&lt;em&gt;is the target of a criminal investigation in the Northern District of Illinois covering the same conduct as the Commission&amp;#39;s suit&lt;/em&gt;&amp;quot; and claimed that Jain cannot take any steps in relation to the FTC lawsuit without &amp;quot;&lt;em&gt;waiving his Fifth Amendment privilege and making admissions that could be used against him in the criminal case&lt;/em&gt;&amp;quot;).&amp;#160; Kristy Ross made the same argument.&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: bearing in mind the events of &amp;quot;late September&amp;quot; 2008 as described by Ted Cassman and detailed in his declaration signed 18 December 2008, why did Jain promise to &amp;quot;fully comply with the terms of the TRO and PI by 23 December 2008” – he must have known about the Illinois investigation and the possibility of criminal charges?&amp;#160; I do not know if criminal charges have yet been laid in Illinois) &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;u&gt;29 January 2009&lt;/u&gt; - the FTC filed a &amp;quot;memorandum of points and authorities in support of its motion for an order holding defendants Sam Jain and Kristy Ross in contempt of Court and requiring the repatriation of their assets&amp;quot;.&amp;#160; I quote: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;quot;&lt;em&gt;Defendant Ross, for example, spent the year 2008 visiting the world&amp;#39;s finest resorts (including multiple visits to the Four Seasons Resort in Nevis, as well as the British Colonial Hilton in the Bahamas, enjoying extravagant meals (including multiple $800+ meals), and gorging herself on luxury items from the world&amp;#39;s most exclusive retailers, including Harrods of London (nearly $30,000 spent in 2008), Louis Vuitton (more than $23,000 spent in 2008) and Dolce &amp;amp; Gabbana (more than $13,000 spent in 2008). &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;... &lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;To date, despite extensive efforts, the FTC has been unable to locate a single dollar of domestic assets held by either Jain or Ross.&lt;/em&gt;&amp;quot; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The above information was taken from credit card statements for Kristy Ross that were submitted to the FTC by JP Morgan Chase and BMW Bank of North America - the &amp;quot;extravagant meals&amp;quot; included a series of meals totaling over $500 as well as at least two meals totaling more than $800.&amp;#160; The charges were incurred by Ross in locations all over the world including London, Toronto, Kiev, Brussels, Zurich, Nevis, Frankfurt and Montreal.&amp;#160; Ross stopped using the credit cards in or about September 2008. (cite: declaration of Sheryl Drexler dated 29 January 2009) &lt;/p&gt;  &lt;p&gt;Two credit card accounts held by Kristy Ross and a safe deposit box held by Sam Jain have been discovered but apart from that &amp;quot;&lt;em&gt;after weeks of searching, the FTC has located only $174,000 of the defendants&amp;#39; assets. ... The bulk of these funds belong to James Reno.&amp;#160; To date, the FTC has not located a single dollar of domestic assets held by either Jain or Ross.&lt;/em&gt;&amp;quot; (cite: Plaintiff&amp;#39;s memorandum of points and authorities in support of its motion for an order holding defendants Sam Jain and Kristy Ross in contempt of Court and requiring the repatriation of their assets filed 29 January 2009) &lt;/p&gt;  &lt;p&gt;According to documents filed in the Canadian litigation (the &amp;quot;Canadian litigation&amp;quot; being the lawsuit filed by Innovative Marketing against Marc D&amp;#39;Souza and Maurice D&amp;#39;Souza in the Ontario Superior Court of Justice), the defendants&amp;#39; income from the sale of their products between 2004-2006 totaled more than $74 million! (cite: Plaintiff&amp;#39;s memorandum of points and authorities in support of its motion for an order holding defendants Sam Jain and Kristy Ross in contempt of Court and requiring the repatriation of their assets filed 29 January 2009). &lt;/p&gt;  &lt;p&gt;The FTC have requested that &amp;quot;&lt;em&gt;this Court hold Jain and Ross in civil contempt, and order them incarcerated until such time as they comply with the PI...&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;5 January 2009&lt;/u&gt; - a completed Consent to Release of Financial Records form was finally received from Ross (the foreign account holders (ie overseas financial institutions) have not, as far as I know, supplied the requested information). &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;12 January 2009&lt;/u&gt; - Jain failed to appear in court to face criminal charges (Criminal Minute Order, USA v Shaileshkumar Jain, CR-08-00197-RMW).&amp;#160; Bench Warrant issued, and stayed until 26 January 2009. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;u&gt;14 January 2009&lt;/u&gt; - a completed Consent to Release of Financial Records form was finally received from Jain (the foreign account holders (ie overseas financial institutions) have not, as far as I know, supplied the requested information). &lt;/p&gt;  &lt;p&gt;&lt;u&gt;26 January 2009&lt;/u&gt; - Jain requests a stay of the FTC proceedings because of the criminal proceedings in the Northern District of Illinois, until the criminal proceedings are resolved. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;u&gt;26 January 2009&lt;/u&gt; - Sam Jain became a fugitive after the Bench Warrant stay was lifted.&amp;#160; Jain forfeited a $250,000 cash bond.&amp;#160; &lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: Bearing in mind the fact that the FTC claims that Jain/Ross were able to achieve revenues in excess of $100 million, the amount of $250,000 would seem a small price to pay (even after taking into consideration the fact that Ross was going through money hand over fist in 2008). &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;u&gt;29 January 2009&lt;/u&gt; - Ross requests a stay of the FTC proceedings because of the criminal proceedings in the Northern District of Illinois, until the criminal proceedings are resolved. &lt;/p&gt;  &lt;p&gt;&lt;u&gt;5 February 2009&lt;/u&gt; - Ross files a &amp;quot;Motion to Strike or, in the alternative, for extension of time to respond&amp;quot;, moving for the Court to strike the FTC&amp;#39;s motion for an order holding Jain and Ross in contempt of court and requiring repatriation of their assets &amp;quot;as premature and procedurally improper&amp;quot;.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;u&gt;5 February 2009&lt;/u&gt; - Jain joins Ross&amp;#39;s motion to strike &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: Isn&amp;#39;t it interesting that Jain, who has been a fugitive since 26 January 2009 and whose whereabouts are apparently unknown (see FTC document filed 9 January 2009), was able to join Kristy Ross&amp;#39;s Motion to Strike on 5 February 2009?). &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;u&gt;9 January 2009&lt;/u&gt; - The FTC opposed the Motion to Strike, filing a &amp;quot;&lt;em&gt;consolidated opposition to motion of defendants Kristy Ross and Sam Jain to strike or in the alternative for an extension of time&lt;/em&gt;&amp;quot; on 9 January 2009.&amp;#160; The FTC notes in that document that &amp;quot;&lt;em&gt;to allow these defendants to flaunt the Court&amp;#39;s orders, and then escape the consequences of these actions by pointing to a possible criminal proceeding, would set bad precedent and invite similar conduct from future defendants.&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;The FTC document notes that Jain is a fugitive, and that his whereabouts are (were?) unknown. &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Defendants: James Reno and Bytehosting Internet Services &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Bytehosting/Reno are now represented.&amp;#160; A further extension of time was granted, pushing out the deadline from 23 January to 30 January 2009. &lt;/p&gt;  &lt;p&gt;Reno/Bytehosting then filed a Motion to dismiss for lack of personal jurisdiction (claiming the court has no jurisdiction) on 30 January 2009.&amp;#160; Reno/Bytehosting claim to have been &amp;quot;&lt;em&gt;merely under contract to provide services, namely technical support and a call center, to Defendant Innovative Marketing&lt;/em&gt;&amp;quot;.&amp;#160; It is also claimed that their &amp;quot;&lt;em&gt;involvement with Innovative Marketing was limited to internal technical support and post-sale support for customers through a call center&lt;/em&gt;&amp;quot;. &lt;/p&gt;  &lt;p&gt;Reno swore an affidavit which basically says the same thing on 30 January 2009. &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;(Sandi note: Uh, yeah – where I come from being aware that something bad is going on via my business because of a rogue client and not doing anything about it is as bad as being the rogue client, and there’s no way Reno could NOT have known what Innovative Marketing et al were doing, especially after the Symantec lawsuit that Reno was a party to)      &lt;br /&gt;      &lt;br /&gt;BTW, I have come across the name eFront a few times in association with Reno and Jain – a couple of comments have been posted referring to them ... would anybody like to share what they know about *that* story?       &lt;br /&gt;&lt;a title="http://www.google.com/search?hl=en&amp;amp;q=efront+reno+jain" href="http://www.google.com/search?hl=en&amp;amp;q=efront+reno+jain" target="_blank"&gt;http://www.google.com/search?hl=en&amp;amp;q=efront+reno+jain&lt;/a&gt; (eFront CEO was Sam Jain, CTO was James Reno?)&amp;#160; Why do I get the feeling that the association between Reno and Jain is more than the typical “arms length, he just walked in off the street, wouldn’t know him from Adam” client/supplier relationship?&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Defendants: Daniel Sundin, Maurice D&amp;#39;Souza, Innovative Marketing Inc &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;These defendants are still unrepresented and silent in this action.&amp;#160; Also, I have found no evidence that Innovative Marketing has paid any of the $8,000 per day fine that was imposed after it failed to comply with the Temporary Restraining Order. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font size="5"&gt;Upcoming deadlines: &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;12 February 2009 (Response)    &lt;br /&gt;17 February 2009 (Response x3)     &lt;br /&gt;23 February 2009 (Response x2 and reply x1) &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1671117" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Fraudware/default.aspx">Fraudware</category></item><item><title>More information about Olympic Media shenanigans</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668070.aspx</link><pubDate>Mon, 02 Feb 2009 07:54:48 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1668070</guid><dc:creator>sandi</dc:creator><slash:comments>0</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1668070</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668070.aspx#comments</comments><description>&lt;p&gt;Ok, when the hijack triggered via the Olympic Media supplied javascript URL that I &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668036.aspx" target="_blank"&gt;mentioned in my previous article&lt;/a&gt; triggers successfully we hit: &lt;/p&gt;  &lt;p&gt;admediastats.com/ts/in.cgi?{{redacted}} &lt;/p&gt;  &lt;p&gt;From there we end up at sg12scanner.com/{{redacted}} &lt;/p&gt;  &lt;p&gt;From there to dlsg09.com/sysgd09/install.php?track_id={{redacted}} &lt;/p&gt;  &lt;p&gt;Javascript in use: &lt;/p&gt;  &lt;p&gt;sg12scanner.com/js/jquery-1.2.5.pack.js   &lt;br /&gt;sg12scanner.com/js/jquery.timers.js (just for fun I will point out that that the JS contains the comment &amp;quot;Yeah this is major overkill...&amp;quot;)    &lt;br /&gt;sg12scanner.com/js/file_names.js &lt;/p&gt;  &lt;p&gt;Installer URL: 89.149.236.86/sysgd09/install.php?track_id={{redacted}} &lt;/p&gt;  &lt;p&gt;Tries to download &amp;quot;SystemGuard2009.exe&amp;quot; &lt;/p&gt;  &lt;p&gt;admediastats.com (status: LOCKED)   &lt;br /&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created 4 January 2009 &lt;/p&gt;  &lt;p&gt;ns1.admediastats.com - 91.211.64.71 - Russian Federation Ural Industrial Limited Company   &lt;br /&gt;ns2.admediastats.com - 116.50.15.1 - Hong Kong Hostfresh    &lt;br /&gt;ns3.admediastats.com - 89.146.226.121 - Germany De-nic    &lt;br /&gt;ns4.admediastats.com - 212.117.162.90 - Luxembourg Root Esolutions &lt;/p&gt;  &lt;p&gt;IP: 84.243.252.179 - Berlin, Gfx-cust-worldstream &lt;/p&gt;  &lt;p&gt;Registrant: WhoisGuard Protected &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;sg12scanner.com   &lt;br /&gt;ICANN Registrar: REGTIME LTD    &lt;br /&gt;Created 14 January 2009    &lt;br /&gt;NS1.DLDNSSG09.COM    &lt;br /&gt;NS2.DLDNSSG09.COM &lt;/p&gt;  &lt;p&gt;IP: 78.26.179.253 - Odessa, Renome-service: Joint Multimedia Cable Network &lt;/p&gt;  &lt;p&gt;Shares IP with Dldnssg09.com, Dlsg09.com, Dlsgd2.com, Dlsgd3.com, Gbpings.com, Getsg09.com, Getsgd2.com, Getsgd3.com, Getsysgd09.com, Gosg09.com, Gosgd2.com, Gosgd3.com, Gosysgd09.com, Prdnssg09.com, Scannersg.com, Scansguard.com, Sg10scanner.com, Sg11scanner.com, Sg12scanner.com, Sg9scanner.com, Sgproduct.com, Sgproductm.com, Sgscanner.com, Sguardscan.com, Sgviralscan.com, Spywareguard2009.com, Spywareguard2009m.com, Systemguard2009.com and Systemguard2009m.com, all of which should be treated with extreme caution. &lt;/p&gt;  &lt;p&gt;Registrant: Kire Serona (kiresl1540@yahoo.com) - owns 2 other domains   &lt;br /&gt;Ilichova 16, Ljubljana. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;dlsg09.com   &lt;br /&gt;ICANN Registrar: REGTIME LTD    &lt;br /&gt;Created 14 January 2009    &lt;br /&gt;NS1.DLDNSSG09.COM    &lt;br /&gt;NS2.DLDNSSG09.COM &lt;/p&gt;  &lt;p&gt;IP: 78.26.179.253 - Odessa, Renome-service: Joint Multimedia Cable Network &lt;/p&gt;  &lt;p&gt;Shares IP with Dldnssg09.com, Dlsg09.com, Dlsgd2.com, Dlsgd3.com, Gbpings.com, Getsg09.com, Getsgd2.com, Getsgd3.com, Getsysgd09.com, Gosg09.com, Gosgd2.com, Gosgd3.com, Gosysgd09.com, Prdnssg09.com, Scannersg.com, Scansguard.com, Sg10scanner.com, Sg11scanner.com, Sg12scanner.com, Sg9scanner.com, Sgproduct.com, Sgproductm.com, Sgscanner.com, Sguardscan.com, Sgviralscan.com, Spywareguard2009.com, Spywareguard2009m.com, Systemguard2009.com and Systemguard2009m.com, all of which should be treated with extreme caution. &lt;/p&gt;  &lt;p&gt;Registrant: Damir Sbil (damirsbils791@gmail.com) - owns 6 other domains   &lt;br /&gt;Tavcarjeva 109, Skofja vas. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;89.149.236.86 - China Gibibits-Ltd (89-149-236-86.internetserviceteam.com - Netdirekt).&amp;#160; Known spam IP.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1668070" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item><item><title>Olympic Media are still active</title><link>http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668036.aspx</link><pubDate>Mon, 02 Feb 2009 05:50:25 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1668036</guid><dc:creator>sandi</dc:creator><slash:comments>3</slash:comments><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/spywaresucks/commentapi.aspx?PostID=1668036</wfw:comment><comments>http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668036.aspx#comments</comments><description>&lt;p&gt;I’ve &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656329.aspx" target="_blank"&gt;warned&lt;/a&gt; about &lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2009/01/05/1658482.aspx" target="_blank"&gt;Olympic Media&lt;/a&gt; several times – they continue to be active.&lt;/p&gt;  &lt;p&gt;The latest reports indicate they are claiming to be operating out of Canada and are supplying javascript code referring to admin.securityclick.net as follows:&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;img style="display:inline;" title="image" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_295AA8D9.png" width="705" height="65" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Other domains being used are onlinepromostats.com and admediastats.com.&lt;/p&gt;  &lt;p&gt;This type of trickery, supplying javascript pointing to malicious domains under the control of the fraudsters, is becoming more and more common.&amp;#160; From there, the bad guys control who does (or does not) see malicious code (&lt;a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/31/1658179.aspx" target="_blank"&gt;see this blog entry for an example&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;And, they still haven’t fixed their site typos&amp;#160; :)&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_1C82E36C.png" width="320" height="73" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom:0px;border-left:0px;display:inline;border-top:0px;border-right:0px;" title="image" border="0" alt="image" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks/image_5F00_3921EFF0.png" width="423" height="88" /&gt; &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;securityclick.net (status: LOCKED)   &lt;br /&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created 25 March 2008 &lt;/p&gt;  &lt;p&gt;NS1.SECURITYCLICK.NET - 208.79.82.50 - Tranquil Hosting   &lt;br /&gt;NS2.SECURITYCLICK.NET - 208.79.82.66 - Tranquil Hosting    &lt;br /&gt;NS3.SECURITYCLICK.NET - 77.73.98.2 - Belgium Nucleus Bvba    &lt;br /&gt;NS4.SECURITYCLICK.NET - 77.73.98.4 - Belgium Nucleus Bvba    &lt;br /&gt;NS5.SECURITYCLICK.NET - 89.149.244.29 - Germany Netdirekt E.k (internetserviceteam.com)    &lt;br /&gt;NS6.SECURITYCLICK.NET - 217.20.116.59 - Germany Netdirekt E.k (finnzi.com)    &lt;br /&gt;NS7.SECURITYCLICK.NET - 88.198.62.171 - Germany Hetzner-rz-nbg-net &lt;/p&gt;  &lt;p&gt;IP: 76.74.249.30 - Virgin Islands, Soft.sol.inc &lt;/p&gt;  &lt;p&gt;Registrant contact:   &lt;br /&gt;Serg Moons (moon.serg@gmail.com) &lt;/p&gt;  &lt;p&gt;Inaccurate WHOIS report submitted via ICANN on 27 January 2009 &lt;/p&gt;  &lt;p&gt;Sharing IP with adnetserver.com, adverlounge.com, beststatserver.com, bizadsonline.net, bizmarketads.com, greatad.net, iddqdmarketing.com, intervarioclick.com, invulnerableads.com, luckyadcoin.com, moneycometrue.com, statisticsmanager.com, statsreportserver.com, waytotheprofit.com and widestatsnow.com - all of these domains should be treated with extreme caution. &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;onlinepromostats.com (status: LOCKED)   &lt;br /&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created 3 July 2008 &lt;/p&gt;  &lt;p&gt;NS1.ONLINEPROMOSTATS.COM - 208.79.82.50 - Tranquil Hosting   &lt;br /&gt;NS2.ONLINEPROMOSTATS.COM - 208.79.82.66 - Tranquil Hosting    &lt;br /&gt;NS3.ONLINEPROMOSTATS.COM - 77.73.98.2 - Belgium Nucleus Bvba    &lt;br /&gt;NS4.ONLINEPROMOSTATS.COM - 77.73.98.4 - Belgium Nucleus Bvba    &lt;br /&gt;NS5.ONLINEPROMOSTATS.COM - 89.149.244.29 - Germany Netdirekt E.k (internetserviceteam.com)    &lt;br /&gt;NS6.ONLINEPROMOSTATS.COM - 217.20.116.59 - Germany Netdirekt E.k (finnzi.com)    &lt;br /&gt;NS7.ONLINEPROMOSTATS.COM - 213.133.100.58 - Germany Hetzner-rz-nbg-net    &lt;br /&gt;NS8.ONLINEPROMOSTATS.COM - 88.198.62.172 - Germany Hetzner-rz-nbg-net &lt;/p&gt;  &lt;p&gt;IP: 84.243.252.86 - Berlin, Gfx-cust-worldstream &lt;/p&gt;  &lt;p&gt;Registrant: namecheap.com &lt;/p&gt;  &lt;p&gt;***** &lt;/p&gt;  &lt;p&gt;admediastats.com (status: LOCKED)   &lt;br /&gt;ICANN Registrar: ENOM, INC    &lt;br /&gt;Created 4 January 2009 &lt;/p&gt;  &lt;p&gt;ns1.admediastats.com - 91.211.64.71 - Russian Federation Ural Industrial Limited Company   &lt;br /&gt;ns2.admediastats.com - 116.50.15.1 - Hong Kong Hostfresh    &lt;br /&gt;ns3.admediastats.com - 89.146.226.121 - Germany De-nic    &lt;br /&gt;ns4.admediastats.com - 212.117.162.90 - Luxembourg Root Esolutions &lt;/p&gt;  &lt;p&gt;IP: 84.243.252.179 - Berlin, Gfx-cust-worldstream &lt;/p&gt;  &lt;p&gt;Registrant: WhoisGuard Protected &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1668036" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Security_2C00_+safety+and+privacy+on+the+Internet/default.aspx">Security, safety and privacy on the Internet</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Vulnerabilities_2C00_+viruses+and+exploits/default.aspx">Vulnerabilities, viruses and exploits</category><category domain="http://msmvps.com/blogs/spywaresucks/archive/tags/Malvertizing/default.aspx">Malvertizing</category></item></channel></rss>