<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down</title>
	<atom:link href="http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Mon, 14 Dec 2009 07:06:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Andrew from Vancouver</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/comment-page-1/#comment-14142</link>
		<dc:creator>Andrew from Vancouver</dc:creator>
		<pubDate>Mon, 14 Dec 2009 07:06:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427#comment-14142</guid>
		<description>The wgetdream.com is parked at GoDaddy after all, somehow. DNS cacheing, perhaps. The TLD servers return NXDOMAIN when queried.

fk0.info and oy7.info are both registered with GoDaddy but have not been suspended. They are currently active.</description>
		<content:encoded><![CDATA[<p>The wgetdream.com is parked at GoDaddy after all, somehow. DNS cacheing, perhaps. The TLD servers return NXDOMAIN when queried.</p>
<p>fk0.info and oy7.info are both registered with GoDaddy but have not been suspended. They are currently active.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew from Vancouver</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/comment-page-1/#comment-14140</link>
		<dc:creator>Andrew from Vancouver</dc:creator>
		<pubDate>Mon, 14 Dec 2009 05:44:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427#comment-14140</guid>
		<description>At least some of these are still active. Still active:

hxxp://us.fk0.info/f/f.exe
hxxp://us.oy7.info/f/1/cosplay.swf
hxxp://goodfriend.wgreatdream.com/show.php

The last update stamp in WHOIS for wgreatdream.com is December 7th 2009. There may have been several updates but the last result was certainly not GoDaddy suspending it.

The .exe file above is a binary file but is not an executable. The .swf file is listed by Wepawet as malicious, but according to VirusTotal, only Microsoft detects it.

http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf

http://www.virustotal.com/analisis/6804d14c311fc8a4b02a2b466b1e25fbd47a8cf87ae260e76972e486bcc72759-1260767519</description>
		<content:encoded><![CDATA[<p>At least some of these are still active. Still active:</p>
<p>hxxp://us.fk0.info/f/f.exe<br />
hxxp://us.oy7.info/f/1/cosplay.swf<br />
hxxp://goodfriend.wgreatdream.com/show.php</p>
<p>The last update stamp in WHOIS for wgreatdream.com is December 7th 2009. There may have been several updates but the last result was certainly not GoDaddy suspending it.</p>
<p>The .exe file above is a binary file but is not an executable. The .swf file is listed by Wepawet as malicious, but according to VirusTotal, only Microsoft detects it.</p>
<p><a href="http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&#038;type=swf" rel="nofollow">http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&#038;type=swf</a></p>
<p><a href="http://www.virustotal.com/analisis/6804d14c311fc8a4b02a2b466b1e25fbd47a8cf87ae260e76972e486bcc72759-1260767519" rel="nofollow">http://www.virustotal.com/analisis/6804d14c311fc8a4b02a2b466b1e25fbd47a8cf87ae260e76972e486bcc72759-1260767519</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

