<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>URLVoid Blog</title>
	<atom:link href="http://blog.urlvoid.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.urlvoid.com</link>
	<description>Latest news about Internet threats</description>
	<lastBuildDate>Mon, 15 Apr 2013 16:08:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Revamped URLVoid Website</title>
		<link>http://blog.urlvoid.com/revamped-urlvoid-website/</link>
		<comments>http://blog.urlvoid.com/revamped-urlvoid-website/#comments</comments>
		<pubDate>Fri, 01 Mar 2013 11:54:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1220</guid>
		<description><![CDATA[<p>We recently updated URLVoid website: - Optimized the report page (example) - Show MyWOT reputation - Show connection details, such as HTTP response code, connect time, etc - Capture external URL redirections (screenshot, report) - Show server geolocation map - Show more geo information about an IP address - Show detailed traffic graphs - Show [...]</p><p>The post <a href="http://blog.urlvoid.com/revamped-urlvoid-website/">Revamped URLVoid Website</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We recently updated <a href="http://www.urlvoid.com/">URLVoid</a> website:</p>
<p>- Optimized the report page (<a href="http://www.urlvoid.com/scan/urlvoid.com">example</a>)<br />
- Show MyWOT reputation<br />
- Show connection details, such as HTTP response code, connect time, etc<br />
- Capture external URL redirections (<a href="http://blog.urlvoid.com/wp-content/uploads/2013/03/capture-redirections.jpg">screenshot</a>, <a href="http://www.urlvoid.com/scan/c-townspirit.org/">report</a>)<br />
- Show server geolocation map<br />
- Show more geo information about an IP address<br />
- Show detailed traffic graphs<br />
- Show website recent activity on Facebook<br />
- Optimized scanning of a website (faster)<br />
- Added <a href="http://antispam.imp.ch/?lng=1" target="_blank">Swinog URIBL</a> and <a href="http://virustracker.info/" target="_blank">VirusTracker</a> as new scanning engines</p>
<p><a href="http://www.urlvoid.com/"><strong>Visit URLVoid.com &rarr;</strong></a></p>
<p>The post <a href="http://blog.urlvoid.com/revamped-urlvoid-website/">Revamped URLVoid Website</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/revamped-urlvoid-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress installed in compromised websites to promote pharmaceutical keywords</title>
		<link>http://blog.urlvoid.com/wordpress-installed-compromised-websites-promote-pharmaceutical-keywords/</link>
		<comments>http://blog.urlvoid.com/wordpress-installed-compromised-websites-promote-pharmaceutical-keywords/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 16:01:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[compromsioed websites]]></category>
		<category><![CDATA[pharma spam]]></category>
		<category><![CDATA[ptbl query spam]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1199</guid>
		<description><![CDATA[<p>Seems that spammers prefer WordPress as blogging platform used to advertise pharmaceutical keywords. We noted a lot of websites compromised and used to host custom installations of WordPress, hidden in subfolders, to promote keywords related to pharmaceutical products. We checked approximately 30 spammed URLs and we noted that the meta tag &#8220;generator&#8221; used by these [...]</p><p>The post <a href="http://blog.urlvoid.com/wordpress-installed-compromised-websites-promote-pharmaceutical-keywords/">WordPress installed in compromised websites to promote pharmaceutical keywords</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>Seems that spammers prefer WordPress as blogging platform used to advertise pharmaceutical keywords. We noted a lot of websites compromised and used to host custom installations of WordPress, hidden in subfolders, to promote keywords related to pharmaceutical products. </p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2013/02/website-compromised-spam1.png" alt="Website compromised and used for spam" /></p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2013/02/website-compromised-spam4.png" alt="Website compromised and used for spam" /></p>
<p>We checked approximately 30 spammed URLs and we noted that the meta tag &#8220;generator&#8221; used by these hidden WordPress installations is almost always the same:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">&lt;meta name=&quot;generator&quot; content=&quot;WordPress 3.6-alpha-*&quot;&gt;</pre></td></tr></table></div>

<p><img src="http://blog.urlvoid.com/wp-content/uploads/2013/02/meta-tag-wordpress-36-alpha.png" alt="Website compromised and used for spam" /></p>
<p>Interesting is that the main website shows a different meta generator:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Main website:
hxxp://www. ropaycomplementos .org/
&lt;meta name=&quot;generator&quot; content=&quot;WordPress 2.5&quot; /&gt;
&nbsp;
Hijacked URL:
hxxp://www. ropaycomplementos .org/wp-content/uploads/2008/09/?ptbl=4120-PureHands-pure-hands-discount-z
&lt;meta name=&quot;generator&quot; content=&quot;WordPress 3.6-alpha-23400&quot;&gt;</pre></td></tr></table></div>

<p>And in some cases the main website does not have WordPress installed:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Main website:
hxxp://www. parenting101 .net/
Not WordPress
&nbsp;
Hijacked URL:
hxxp://www. parenting101 .net/img/folen/?ptbl=10030-Flexeril-flexeril-in-canada
&lt;meta name=&quot;generator&quot; content=&quot;WordPress 3.6-alpha-23451&quot;&gt;</pre></td></tr></table></div>

<p>Searching for a specific keyword is possible to find almost all compromised URLs:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2013/02/research-spam-urls-google.png" alt="Google keyword used to find spammed URLs" /></p>
<p>The post <a href="http://blog.urlvoid.com/wordpress-installed-compromised-websites-promote-pharmaceutical-keywords/">WordPress installed in compromised websites to promote pharmaceutical keywords</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/wordpress-installed-compromised-websites-promote-pharmaceutical-keywords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress-how-to-videos(dot)com Spreads Java Exploits</title>
		<link>http://blog.urlvoid.com/wordpress-how-to-videosdotcom-spreads-java-exploits/</link>
		<comments>http://blog.urlvoid.com/wordpress-how-to-videosdotcom-spreads-java-exploits/#comments</comments>
		<pubDate>Sun, 16 Sep 2012 01:13:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit kit]]></category>
		<category><![CDATA[java exploit]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1184</guid>
		<description><![CDATA[<p>When we analyzed few Twitter followers in one of our websites, we noted that there was an user that was following us, see the image: We have analyzed the website (infected): www (dot) wordpress-how-to-videos (dot) com The website wordpress-how-to-videos(dot)com is hosted at BSE Software GmbH and its current IP address is 82.220.34.22 (330.hostserv.eu). The server [...]</p><p>The post <a href="http://blog.urlvoid.com/wordpress-how-to-videosdotcom-spreads-java-exploits/">WordPress-how-to-videos(dot)com Spreads Java Exploits</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>When we analyzed few Twitter followers in one of our websites, we noted that there was an user that was following us, see the image:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/09/exp2.png" alt="" title="exp2" width="550" class="alignnone size-full wp-image-1185" /></p>
<p>We have analyzed the website (<font color="red">infected</font>):</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">www (dot) wordpress-how-to-videos (dot) com</pre></td></tr></table></div>

<p>The website wordpress-how-to-videos(dot)com is hosted at BSE Software GmbH and its current IP address is 82.220.34.22 (330.hostserv.eu). The server machine is located in Switzerland (CH) and in the same server there are hosted other 0 websites. The domain is registered with the suffix COM and the keyword of the domain is wordpress-how-to-videos. The organization is hosttech GmbH.</p>
<p>The above website is used to redirect users to a malicious URL that tries to exploit the user&#8217;s browser with a Java exploit, as you can see from this image:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/09/exp3.png" width="550" alt="Java Exploit" /></p>
<p>The malicious redirect is activated only if the user browse the malicious website with a referer that contains the string of search engines, such as Google. Using the free service <a href="http://www.htmlsniffer.com/" title="View HTTP Request and Response Header | View HTML Source of Remote URL" target="_blank">HTML Sniffer</a> we can simulate the Google referer and we can see that we are redirected to the exploit URL:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/09/exp4.png" alt="" title="exp4" width="590" class="alignnone size-full wp-image-1188" /></p>
<p>The exploit URL seems to be updated very frequently:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">garliccommercial .ru /pavilion?8
midwaydance .ru /pavilion?8</pre></td></tr></table></div>

<p>Both malicious URLs are hosted in this IP address:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">206.53.52 .13</pre></td></tr></table></div>

<p>The Java exploit is loaded from another malicious URL:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/09/1.png" alt="" title="1" width="555" height="308" class="alignnone size-full wp-image-1189" /></p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">ypcbpukqt. lflinkup .com /PJeHubmUDaovPDRCJxGMEzlYXdvvppcg</pre></td></tr></table></div>

<p>Pay attention when clicking on websites of your Twitter followers!</p>
<p>The post <a href="http://blog.urlvoid.com/wordpress-how-to-videosdotcom-spreads-java-exploits/">WordPress-how-to-videos(dot)com Spreads Java Exploits</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/wordpress-how-to-videosdotcom-spreads-java-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>URLVoid API v2.0</title>
		<link>http://blog.urlvoid.com/urlvoid-api-v2-0/</link>
		<comments>http://blog.urlvoid.com/urlvoid-api-v2-0/#comments</comments>
		<pubDate>Thu, 09 Aug 2012 15:24:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[urlvoid api]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1175</guid>
		<description><![CDATA[<p>URLVoid API is a free service (for non commercial use) that allow users to query our database of already analyzed domains and receive, in XML format, detailed details about each submitted domain. The URLVoid API supports multiple domains in one single query, so you can submit 250 domains and receive details of each domains in [...]</p><p>The post <a href="http://blog.urlvoid.com/urlvoid-api-v2-0/">URLVoid API v2.0</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>URLVoid API is a free service (for non commercial use) that allow users to query our database of already analyzed domains and receive, in XML format, detailed details about each submitted domain. The URLVoid API supports multiple domains in one single query, so you can submit 250 domains and receive details of each domains in just few seconds. </p>
<p>An example of XML output is this:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="xml" style="font-family:monospace;"><span style="color: #009900;"><span style="color: #000000; font-weight: bold;">&lt;?xml</span> <span style="color: #000066;">version</span>=<span style="color: #ff0000;">&quot;1.0&quot;</span> <span style="color: #000066;">encoding</span>=<span style="color: #ff0000;">&quot;UTF-8&quot;</span><span style="color: #000000; font-weight: bold;">?&gt;</span></span>
<span style="color: #009900;"><span style="color: #000000; font-weight: bold;">&lt;detected<span style="color: #000000; font-weight: bold;">&gt;</span></span></span>
	<span style="color: #009900;"><span style="color: #000000; font-weight: bold;">&lt;details</span> <span style="color: #000066;">domain</span>=<span style="color: #ff0000;">&quot;google.com&quot;</span> <span style="color: #000066;">last_scan</span>=<span style="color: #ff0000;">&quot;1344104440&quot;</span> <span style="color: #000066;">detected</span>=<span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000066;">lists_detected</span>=<span style="color: #ff0000;">&quot;&quot;</span> <span style="color: #000000; font-weight: bold;">/&gt;</span></span>
	<span style="color: #009900;"><span style="color: #000000; font-weight: bold;">&lt;details</span> <span style="color: #000066;">domain</span>=<span style="color: #ff0000;">&quot;xxxtoolbar.com&quot;</span> <span style="color: #000066;">last_scan</span>=<span style="color: #ff0000;">&quot;1344524302&quot;</span> <span style="color: #000066;">detected</span>=<span style="color: #ff0000;">&quot;10&quot;</span> <span style="color: #000066;">lists_detected</span>=<span style="color: #ff0000;">&quot;MyWOT,SCUMWARE,MalwareBlacklist,hpHosts,BrowserDefender,Malware Patrol ,DNS-BH,GoogleSafeBrowsing,SURBL,WebSecurityGuard&quot;</span> <span style="color: #000000; font-weight: bold;">/&gt;</span></span>
	<span style="color: #009900;"><span style="color: #000000; font-weight: bold;">&lt;details</span> <span style="color: #000066;">domain</span>=<span style="color: #ff0000;">&quot;ysweb.com&quot;</span> <span style="color: #000066;">last_scan</span>=<span style="color: #ff0000;">&quot;1343484791&quot;</span> <span style="color: #000066;">detected</span>=<span style="color: #ff0000;">&quot;0&quot;</span> <span style="color: #000066;">lists_detected</span>=<span style="color: #ff0000;">&quot;&quot;</span> <span style="color: #000000; font-weight: bold;">/&gt;</span></span>
<span style="color: #009900;"><span style="color: #000000; font-weight: bold;">&lt;/detected<span style="color: #000000; font-weight: bold;">&gt;</span></span></span></pre></td></tr></table></div>

<p>As you can see, you receive useful info:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">domain=&quot;xxxtoolbar.com&quot;</pre></td></tr></table></div>

<p>The name of the domain submitted.</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">last_scan=&quot;1344524302&quot;</pre></td></tr></table></div>

<p>The date of the last available report.</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">detected=&quot;10&quot;</pre></td></tr></table></div>

<p>The number of blacklist engines that have detected the domain.</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">lists_detected=&quot;MyWOT,SCUMWARE,MalwareBlacklist,hpHosts,BrowserDefender,Malware Patrol ,DNS-BH,GoogleSafeBrowsing,SURBL,WebSecurityGuard&quot;</pre></td></tr></table></div>

<p>The name of each blacklist engines that have detected the domain.</p>
<h2>How can I obtain an API key ?</h2>
<p>The service needs a special key to being used and you can request your own API key by contacting us at info (at) novirusthanks (dot) org with the subject <u>Request for URLVoid API Key</u>, please include the following details:</p>
<p>1) Your Name<br />
2) Your Email<br />
3) Your Company<br />
4) Your Website URL<br />
5) Small description on how you are going to use URLVoid API</p>
<p>All your details will not be shared in any way and will be strictly private and used only to assign the API key to your email, nickname and website. After we have received your email, we will send in few days your API key to your email. Please note that you need to respect the following terms to use correctly our free API:</p>
<p>1) Not include/use the API in commercial products or services<br />
2) Not use the API as substitute for Security products<br />
3) Not use the API in unethical services<br />
4) Include a backlink to our website (urlvoid.com)<br />
5) Not abuse the service usage<br />
6) Not use the API in services where you have no control</p>
<p>Non-compliance with these rules will result in the termination of your account/API key without prior notification and you will not be able to use the service.</p>
<p>For any other questions just send us an email. We recommend to <a href="http://feedburner.google.com/fb/a/mailverify?uri=URLVoid&#038;loc=en_US" target="_blank">follow our blog</a> or our <a href="http://www.twitter.com/urlvoid" target="_blank">Twitter account</a> to stay always updated with news and changes about this service.</p>
<p>The post <a href="http://blog.urlvoid.com/urlvoid-api-v2-0/">URLVoid API v2.0</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/urlvoid-api-v2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: PayPal Account Review Department</title>
		<link>http://blog.urlvoid.com/phishing-paypal-account-review-department/</link>
		<comments>http://blog.urlvoid.com/phishing-paypal-account-review-department/#comments</comments>
		<pubDate>Wed, 13 Jun 2012 11:40:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[paypal phishing]]></category>
		<category><![CDATA[phishing email]]></category>
		<category><![CDATA[spam email]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1171</guid>
		<description><![CDATA[<p>Phishing email against PayPal users: Header details: Received: from mail14j.g14.rapidsite.net (mail14j.g14.rapidsite.net [128.121.64.175]) Received: from ca1-mx26.mlpsca01.us.mxservers.net (128.121.64.172) by mail14j.g14.rapidsite.net Received: from unknown [128.121.143.147] (EHLO mmm1430.rapidsite.net) by ca1-mx26.mlpsca01.us.mxservers.net (mxl_mta-3.1.0-05) Received: from unknown (HELO mikesmirnoff-%cf%ca.local) (marketing@77.50.19.97) Subject: Account Review Department Date: Wed, 13 Jun 2012 12:27:42 +0400 X-SOURCE-IP: [128.121.143.147] To:undisclosed-recipients:; Content-Disposition: attachment; filename=&#34;Account.zip&#34; Attached there is a ZIP [...]</p><p>The post <a href="http://blog.urlvoid.com/phishing-paypal-account-review-department/">Phishing: PayPal Account Review Department</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>Phishing email against PayPal users:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/06/13_06_2012-13_17_13.jpeg" alt="Phishing Email" title="PayPal Phishing Email" /></p>
<p>Header details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Received: from mail14j.g14.rapidsite.net (mail14j.g14.rapidsite.net [128.121.64.175])
Received: from ca1-mx26.mlpsca01.us.mxservers.net (128.121.64.172) by mail14j.g14.rapidsite.net
Received: from unknown [128.121.143.147] (EHLO mmm1430.rapidsite.net) by ca1-mx26.mlpsca01.us.mxservers.net (mxl_mta-3.1.0-05)
Received: from unknown (HELO mikesmirnoff-%cf%ca.local) (marketing@77.50.19.97)
Subject: Account Review Department
Date: Wed, 13 Jun 2012 12:27:42 +0400
X-SOURCE-IP: [128.121.143.147]
To:undisclosed-recipients:;
Content-Disposition: attachment; filename=&quot;Account.zip&quot;</pre></td></tr></table></div>

<p>Attached there is a ZIP file named:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: Account.zip
Size: 6694 bytes
MD5: 6AC253515AB76EE76D1E034AEC75FCD7
SHA1: 485E0A670CFE47F247C0BF6073D089A305BB6BEB
SHA256: 6EE32A16EC8711A741B7E9E74D2289ED91F078D5A91425B7F8BAC74D74BAD9BA
SHA384: A39150F4A3ADBFF90E53D0C9A2DCF36023DB1F7DB9D84AA5B6C54433502A544658F2E323B4064B7451D73058E12D4DFB
SHA512: BFE5443A418DBDF4B051AA7FD92F299A51A8972221B73D8B708AF7174E29F9132F3D3B645E8A7F33616CAC5EE1CCF2DBDE89D7D57B29C69AE47F1B8B979BBD6B</pre></td></tr></table></div>

<p>The extracted file is a .HTML file:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: Account Verification.html
Size: 32224 bytes
MD5: FAF8A01884CC8E3941684659E015E8EB
SHA1: 9B24726C5B982DB8FE7E88E356B6CCDF74187344
SHA256: A5094D44CA1DFCEA0ED5D17DAD9385B2FCF043AB9C52E0C6FC061E38FFEC2E2D
SHA384: 3B64DE5DCED0F7F255298C20852216F4C681E9BD2C8A9B571058528775F45DFA9D1116F3462F50B0F170DD1EA246F4D4
SHA512: 6D07323C6E4AEEEF56F75178F3EC8CDECCACBBAD16F2AC66B173CAD90E2AC6CDEC6501338563E8719398836162E208BDB129A554F10C4E6B9C9890C53F1E652E</pre></td></tr></table></div>

<p>The sensitive data filled by the user is sent to this malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// akamai2.spteiqnaskqliliasnqxikcmenmn .ru /~jeremy/ze.php</pre></td></tr></table></div>

<p>Whois Details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">domain:        SPTEIQNASKQLILIASNQXIKCMENMN.RU
nserver:       ns1.nameself.com.
nserver:       ns2.nameself.com.
state:         REGISTERED, DELEGATED, UNVERIFIED
person:        Private Person
registrar:     REGTIME-REG-RIPN
admin-contact: http://whois.webnames.ru
created:       2011.08.17
paid-till:     2012.08.17
free-date:     2012.09.17
source:        TCI</pre></td></tr></table></div>

<p>URLVoid report:</p>
<p><a href="http://www.urlvoid.com/scan/spteiqnaskqliliasnqxikcmenmn.ru">http://www.urlvoid.com/scan/spteiqnaskqliliasnqxikcmenmn .ru</a></p>
<p>The post <a href="http://blog.urlvoid.com/phishing-paypal-account-review-department/">Phishing: PayPal Account Review Department</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/phishing-paypal-account-review-department/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon.com Order Confirmation leads to Blackhole Exploit Kit</title>
		<link>http://blog.urlvoid.com/amazon-com-order-confirmation-leads-to-blackhole-exploit-kit/</link>
		<comments>http://blog.urlvoid.com/amazon-com-order-confirmation-leads-to-blackhole-exploit-kit/#comments</comments>
		<pubDate>Sat, 09 Jun 2012 21:40:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[amazon order confirmation exploit]]></category>
		<category><![CDATA[blackhole exploit kit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit kit]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1164</guid>
		<description><![CDATA[<p>We received few emails with subject: Amazon.com Order Confirmation Inside the email message there is a HREF link that redirects users to a malicious web page containing malicious javascript code used to redirect users to the main URL of Blackhole exploit kit: The Blackhole exploit kit URL is: GET /main.php?page=017f3bb5c2be6a41 HTTP/1.1 User-Agent: Mozilla/4.0 (compatible; MSIE [...]</p><p>The post <a href="http://blog.urlvoid.com/amazon-com-order-confirmation-leads-to-blackhole-exploit-kit/">Amazon.com Order Confirmation leads to Blackhole Exploit Kit</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We received few emails with subject:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Amazon.com Order Confirmation</pre></td></tr></table></div>

<p>Inside the email message there is a HREF link that redirects users to a malicious web page containing malicious javascript code used to redirect users to the main URL of Blackhole exploit kit:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/06/09_06_2012-14_28_40.png" alt="Amazon.com fake order page" title="Amazon.com fake order page" /></p>
<p>The Blackhole exploit kit URL is:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">GET /main.php?page=017f3bb5c2be6a41 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: adnroidsoft .net</pre></td></tr></table></div>

<p>Fortunately the domain is not anymore active.</p>
<p>The post <a href="http://blog.urlvoid.com/amazon-com-order-confirmation-leads-to-blackhole-exploit-kit/">Amazon.com Order Confirmation leads to Blackhole Exploit Kit</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/amazon-com-order-confirmation-leads-to-blackhole-exploit-kit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Malicious Injected Code: Injection_head and Injection_tail</title>
		<link>http://blog.urlvoid.com/new-malicious-injected-code-injection_head-and-injection_tail/</link>
		<comments>http://blog.urlvoid.com/new-malicious-injected-code-injection_head-and-injection_tail/#comments</comments>
		<pubDate>Fri, 08 Jun 2012 22:29:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Injection_head]]></category>
		<category><![CDATA[Injection_tail]]></category>
		<category><![CDATA[javascript injected code]]></category>
		<category><![CDATA[js exploit]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1156</guid>
		<description><![CDATA[<p>We have logged few websites infected with a new injected javascript code that seems to target mainly the websites powered with WordPress and Joomla. Below there is a screenshot of the malicious script: As we can see from the image above, the injected code starts with: &#60;!--Injection_head[SessionID=...]--&#62; And it ends with: &#60;!--Injection_tail[SessionID=...]--&#62; Here is the [...]</p><p>The post <a href="http://blog.urlvoid.com/new-malicious-injected-code-injection_head-and-injection_tail/">New Malicious Injected Code: Injection_head and Injection_tail</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We have logged few websites infected with a new injected javascript code that seems to target mainly the websites powered with WordPress and Joomla. Below there is a screenshot of the malicious script: </p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/2012/06/injected-evil-code.jpeg" alt="Image" title="Evil Code Injected in HTML Pages" /></p>
<p>As we can see from the image above, the injected code starts with:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">&lt;!--Injection_head[SessionID=...]--&gt;</pre></td></tr></table></div>

<p>And it ends with:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">&lt;!--Injection_tail[SessionID=...]--&gt;</pre></td></tr></table></div>

<p>Here is the report of the website infected with the malicious script:</p>
<p><a href="http://www.scanurls.com/report/1614">http://www.scanurls.com/report/1614</a></p>
<p>The post <a href="http://blog.urlvoid.com/new-malicious-injected-code-injection_head-and-injection_tail/">New Malicious Injected Code: Injection_head and Injection_tail</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/new-malicious-injected-code-injection_head-and-injection_tail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recent Blackhole Exploit Kit Activity</title>
		<link>http://blog.urlvoid.com/recent-blackhole-exploit-kit-activity/</link>
		<comments>http://blog.urlvoid.com/recent-blackhole-exploit-kit-activity/#comments</comments>
		<pubDate>Thu, 07 Jun 2012 08:45:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blackhole exploit]]></category>
		<category><![CDATA[blackhole exploit kit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit kit]]></category>
		<category><![CDATA[fareit trojan]]></category>
		<category><![CDATA[zbot trojan]]></category>
		<category><![CDATA[zeus trojan]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1108</guid>
		<description><![CDATA[<p>Our honeypot has logged few new Blackhole Exploit Kit activity. The Java exploit file Set.jar is downloaded: GET /Set.jar HTTP/1.1 content-type: application/x-java-archive User-Agent: Mozilla/4.0 (Windows XP 5.1) Java/1.6.0_13 Host: 64.111.24.122 HTTP/1.1 200 OK Server: nginx Date: Wed, 06 Jun 2012 22:43:12 GMT Content-Type: application/java-archive Content-Length: 20868 Accept-Ranges: bytes PK........-</p><p>The post <a href="http://blog.urlvoid.com/recent-blackhole-exploit-kit-activity/">Recent Blackhole Exploit Kit Activity</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>Our honeypot has logged few new Blackhole Exploit Kit activity.</p>
<p>The Java exploit file <b>Set.jar</b> is downloaded:</p>
<pre lang="text">
GET /Set.jar HTTP/1.1<br />
content-type: application/x-java-archive<br />
User-Agent: Mozilla/4.0 (Windows XP 5.1) Java/1.6.0_13<br />
Host: 64.111.24.122</p>
<p>HTTP/1.1 200 OK<br />
Server: nginx<br />
Date: Wed, 06 Jun 2012 22:43:12 GMT<br />
Content-Type: application/java-archive<br />
Content-Length: 20868<br />
Accept-Ranges: bytes</p>
<p>PK........-</p>
<p>The post <a href="http://blog.urlvoid.com/recent-blackhole-exploit-kit-activity/">Recent Blackhole Exploit Kit Activity</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/recent-blackhole-exploit-kit-activity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: Attention ! Votre compte PayPal a ete limite</title>
		<link>http://blog.urlvoid.com/phishing-attention-votre-compte-paypal-a-ete-limite/</link>
		<comments>http://blog.urlvoid.com/phishing-attention-votre-compte-paypal-a-ete-limite/#comments</comments>
		<pubDate>Mon, 04 Jun 2012 11:42:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[email spam]]></category>
		<category><![CDATA[paypal phishing email]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1089</guid>
		<description><![CDATA[<p>New phishing email used to spread HTML files with fake PayPal login forms: Header details: Received: from ns3.komvos.gr (ns3.komvos.gr [88.198.65.153]) Received: by ns3.komvos.gr (Postfix, from userid 48) Subject: Attention ! Votre compte PayPal a été limité ! From: Service Paypal Date: Mon, 4 Jun 2012 13:00:12 +0300 (EEST) Content-Disposition: attachment; filename=&#34;Informations Compte Paypal .zip&#34; There [...]</p><p>The post <a href="http://blog.urlvoid.com/phishing-attention-votre-compte-paypal-a-ete-limite/">Phishing: Attention ! Votre compte PayPal a ete limite</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>New phishing email used to spread HTML files with fake PayPal login forms:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/04_06_2012-13_30_02.jpeg" alt="Phishing Email" title="Phishing Email" /></p>
<p>Header details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Received: from ns3.komvos.gr (ns3.komvos.gr [88.198.65.153])
Received: by ns3.komvos.gr (Postfix, from userid 48)
Subject: Attention ! Votre compte PayPal a été limité !
From: Service Paypal
Date: Mon,  4 Jun 2012 13:00:12 +0300 (EEST)
Content-Disposition: attachment; filename=&quot;Informations Compte Paypal .zip&quot;</pre></td></tr></table></div>

<p>There is a ZIP file attached:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: Informations Compte Paypal .zip
Dimensione: 5391 bytes
MD5: 2C573252C917A4E4FFC2138E48B50F2B
SHA1: 28B36A51D9215F143AC449984A27A74D520679B7
SHA256: 5E45F7E1988AE2F1B8721226D88AB7DD9EB8A395FB4C501E145554F49655C8C9
SHA384: EE4D4201B65716A986162D43F289FA695263B9BC3EB839F08F185F2B1A1DEC777C68439D91C068DAA80768712B53D80E
SHA512: BA111FCB751F40837E58F50F76314380E8D52FD97B5E98F7855D813433C8FFCDDD26AF58DEE7894F4BC4D2AF53760268FBE25C650FCDC55B0796F6D316E5147A</pre></td></tr></table></div>

<p>The extracted file is a .HTML file:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: Informations Compte Paypal .html
Dimensione: 22525 bytes
MD5: 0500506DEDA37FBC1A7CD19C22173764
SHA1: AB7F78D2A70460418E858E4783F5D3F5376CF2E2
SHA256: F81D8AAA2996D7FB13320FD6F05C37AA1A1CD7BA7BCD29823B03731ED3A067E2
SHA384: 7EEA087DEEEE72203E81F7F606CDAD90F4F5EB1233A95DC692556AFE6AA5B94426E7B84881101F21BF84730B0E132EE3
SHA512: 0B858A75C10EBDBFC9A6D7CDE4C1AB34199B67A51999AB59E85086182C93EF66C20956BA62E68647C27B91704D5A2D4E2EA68749C77ED39DF4AB1F679245BE18</pre></td></tr></table></div>

<p>From this HTML code:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">&lt;form action=&quot;hxxp:// byrongoldworks .com /mainbody.php&quot; method=&quot;post&quot; name=&quot;zaz&quot; onsubmit=&quot;return verif_formulaire()&quot;&gt;</pre></td></tr></table></div>

<p>We can see that the sensitive data of the form is sent to:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// byrongoldworks .com /mainbody.php</pre></td></tr></table></div>

<p>Report from URLVoid:</p>
<p><a href="http://urlvoid.com/scan/byrongoldworks.com/" target="_blank"><img src="http://blog.urlvoid.com/wp-content/uploads/04_06_2012-13_36_32.jpeg" alt="URLVoid Report for byrongoldworks .com" title="URLVoid Report for byrongoldworks .com" /></a></p>
<p>The post <a href="http://blog.urlvoid.com/phishing-attention-votre-compte-paypal-a-ete-limite/">Phishing: Attention ! Votre compte PayPal a ete limite</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/phishing-attention-votre-compte-paypal-a-ete-limite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: Abbiamo limitato l&#8217;accesso visa/mastercard account.</title>
		<link>http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/</link>
		<comments>http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/#comments</comments>
		<pubDate>Fri, 25 May 2012 15:59:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam email]]></category>
		<category><![CDATA[visa phishing]]></category>

		<guid isPermaLink="false">http://blog.urlvoid.com/?p=1083</guid>
		<description><![CDATA[<p>Another phishing email against Italian users of Mastercard / Visa: Header details: Received: from mail.oceano.hn (mail.oceano.hn [63.161.65.43]) Received: from User ([62.215.140.237]) by oceano.hn with MailEnable ESMTP; Fri, 25 May 2012 08:04:39 -0600 Subject: Abbiamo limitato l'accesso visa/mastercard account. Si prega di attenersi alla seguente procedura per risolvere. (Case # PP-001-546-712-069 - ORM001) Date: Fri, 25 [...]</p><p>The post <a href="http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/">Phishing: Abbiamo limitato l&#8217;accesso visa/mastercard account.</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>Another phishing email against Italian users of Mastercard / Visa:</p>
<p><img src="http://blog.urlvoid.com/wp-content/uploads/25_05_2012-17_47_55.jpeg" alt="Phishing Email" title="Phishing Email" /></p>
<p>Header details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Received: from mail.oceano.hn (mail.oceano.hn [63.161.65.43])
Received: from User ([62.215.140.237]) by oceano.hn with MailEnable ESMTP; Fri, 25 May 2012 08:04:39 -0600
Subject: Abbiamo limitato l'accesso visa/mastercard account. Si prega di attenersi alla seguente procedura per risolvere. (Case # PP-001-546-712-069 - ORM001)
Date: Fri, 25 May 2012 17:04:41 +0300
To: undisclosed-recipients:;
Content-Type: application/octet-stream; name=&quot;visaita.html&quot;
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename=&quot;visaita.html&quot;</pre></td></tr></table></div>

<p>There is a .HTML file attached:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: visaita.html
Size: 25970 bytes
MD5: C6D16F0B6693AB2831E2BA70534C85BE
SHA1: AB4175E9B97A6E822E3D616BD4DDD5285AC70B39
SHA256: 7B8417D0A420DB5710B44252CF5B4813295EE1B8A51552BD6D5B847AC4AD9E85
SHA384: 4DB62497B232418E708AD8C5278BCDD48DD2E593CAAC01FC0963749EFA3B300BF116A539C222FB389020F61C2A516959
SHA512: 691B828A1FC25EE938114ECA74FFF5690AFE3F8F79AF4D13BB438C064663276CE97D5BED0BDDA3143A9D682FDF67E55C9F46CB1DAE69D5747297C9BF32B491F7</pre></td></tr></table></div>

<p>The post <a href="http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/">Phishing: Abbiamo limitato l&#8217;accesso visa/mastercard account.</a> appeared first on <a href="http://blog.urlvoid.com">URLVoid Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.urlvoid.com/phishing-abbiamo-limitato-laccesso-visamastercard-account-case-pp-001-546-712-069-orm001/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
