<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Andrew Martin</title>
	<atom:link href="http://www.martinsecurity.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Mon, 14 Dec 2009 07:06:01 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down by Andrew from Vancouver</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/comment-page-1/#comment-14142</link>
		<dc:creator>Andrew from Vancouver</dc:creator>
		<pubDate>Mon, 14 Dec 2009 07:06:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427#comment-14142</guid>
		<description>The wgetdream.com is parked at GoDaddy after all, somehow. DNS cacheing, perhaps. The TLD servers return NXDOMAIN when queried.

fk0.info and oy7.info are both registered with GoDaddy but have not been suspended. They are currently active.</description>
		<content:encoded><![CDATA[<p>The wgetdream.com is parked at GoDaddy after all, somehow. DNS cacheing, perhaps. The TLD servers return NXDOMAIN when queried.</p>
<p>fk0.info and oy7.info are both registered with GoDaddy but have not been suspended. They are currently active.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Major Stealthy Malware Campaign &#8211; 711 Domains Taken Down by Andrew from Vancouver</title>
		<link>http://www.martinsecurity.net/2009/12/08/major-stealthy-malware-campaign-711-domains-taken-down/comment-page-1/#comment-14140</link>
		<dc:creator>Andrew from Vancouver</dc:creator>
		<pubDate>Mon, 14 Dec 2009 05:44:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=427#comment-14140</guid>
		<description>At least some of these are still active. Still active:

hxxp://us.fk0.info/f/f.exe
hxxp://us.oy7.info/f/1/cosplay.swf
hxxp://goodfriend.wgreatdream.com/show.php

The last update stamp in WHOIS for wgreatdream.com is December 7th 2009. There may have been several updates but the last result was certainly not GoDaddy suspending it.

The .exe file above is a binary file but is not an executable. The .swf file is listed by Wepawet as malicious, but according to VirusTotal, only Microsoft detects it.

http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&amp;type=swf

http://www.virustotal.com/analisis/6804d14c311fc8a4b02a2b466b1e25fbd47a8cf87ae260e76972e486bcc72759-1260767519</description>
		<content:encoded><![CDATA[<p>At least some of these are still active. Still active:</p>
<p>hxxp://us.fk0.info/f/f.exe<br />
hxxp://us.oy7.info/f/1/cosplay.swf<br />
hxxp://goodfriend.wgreatdream.com/show.php</p>
<p>The last update stamp in WHOIS for wgreatdream.com is December 7th 2009. There may have been several updates but the last result was certainly not GoDaddy suspending it.</p>
<p>The .exe file above is a binary file but is not an executable. The .swf file is listed by Wepawet as malicious, but according to VirusTotal, only Microsoft detects it.</p>
<p><a href="http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&#038;type=swf" rel="nofollow">http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&#038;type=swf</a></p>
<p><a href="http://www.virustotal.com/analisis/6804d14c311fc8a4b02a2b466b1e25fbd47a8cf87ae260e76972e486bcc72759-1260767519" rel="nofollow">http://www.virustotal.com/analisis/6804d14c311fc8a4b02a2b466b1e25fbd47a8cf87ae260e76972e486bcc72759-1260767519</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Sources of Badness &#8211; LeaseWeb by Rune Jensen</title>
		<link>http://www.martinsecurity.net/2008/12/11/sources-of-badness-leaseweb/comment-page-1/#comment-11173</link>
		<dc:creator>Rune Jensen</dc:creator>
		<pubDate>Sat, 07 Nov 2009 05:41:55 +0000</pubDate>
		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=139#comment-11173</guid>
		<description>I do not have _any_ patiense what-so-ever with Lease-web. Just blocked the entire IP-range.</description>
		<content:encoded><![CDATA[<p>I do not have _any_ patiense what-so-ever with Lease-web. Just blocked the entire IP-range.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Exploits Employed by Gumblar by Wasim Halani</title>
		<link>http://www.martinsecurity.net/2009/05/22/exploits-employed-by-gumblar-exploits-employado-por-gumblar/comment-page-1/#comment-2847</link>
		<dc:creator>Wasim Halani</dc:creator>
		<pubDate>Thu, 03 Sep 2009 16:11:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=308#comment-2847</guid>
		<description>Hi Andrew,

I too came across a similar malware, but I am stuck at one point in the wepawet analysis. 
In the segment &quot;var Kkbfhqas=&quot; what is the decoded output of the variable. I had read some place that this is the &#039;shellcode&#039;, but I am not able to figure that out myself . Any inputs on this or how I can better understand this segment ? 

Thanks</description>
		<content:encoded><![CDATA[<p>Hi Andrew,</p>
<p>I too came across a similar malware, but I am stuck at one point in the wepawet analysis.<br />
In the segment &#8220;var Kkbfhqas=&#8221; what is the decoded output of the variable. I had read some place that this is the &#8217;shellcode&#8217;, but I am not able to figure that out myself . Any inputs on this or how I can better understand this segment ? </p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised by Tore Eriksson</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-2599</link>
		<dc:creator>Tore Eriksson</dc:creator>
		<pubDate>Sun, 30 Aug 2009 20:19:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-2599</guid>
		<description>I have struggled with this malware all weekend. It&#039;s called Krap.w and seems to be very new. All google hits are just hours old. No antivirus company has any news on it. It reinstalls a three-digit exe file every reboot, like 266.exe in temporary internet files folder, and also a random eight digit folder in user\temp\, eg. user\temp\15736234\ where three files are created: 15736234 15736234.ins and 15736234.exe (same random eight digits). F-secure&#039;s antivirus program now detects and stops it from taking over the system, but does not find the installer yet. Neither have I.</description>
		<content:encoded><![CDATA[<p>I have struggled with this malware all weekend. It&#8217;s called Krap.w and seems to be very new. All google hits are just hours old. No antivirus company has any news on it. It reinstalls a three-digit exe file every reboot, like 266.exe in temporary internet files folder, and also a random eight digit folder in user\temp\, eg. user\temp\15736234\ where three files are created: 15736234 15736234.ins and 15736234.exe (same random eight digits). F-secure&#8217;s antivirus program now detects and stops it from taking over the system, but does not find the installer yet. Neither have I.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised by TheOne</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-1573</link>
		<dc:creator>TheOne</dc:creator>
		<pubDate>Fri, 14 Aug 2009 11:43:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-1573</guid>
		<description>Well last time i booted into windows my desktop-background was izohore.bmp and a strange &quot;Anti Virus&quot; Software was scanning some files. So it seems like i have got this thing. The Problem was that i could not Run any App like firefox or taskmanager since the &quot;AV&quot; &quot;detected an infection&quot; So i quickliy shut down my computer and booted into Linux. I mounted the WINDOWS partition and fount strange nubered exe in an stange numbered folder in /all users/Application Data/ and the izohore.bmp in \user\Local Settings\Temp\ but i couldnot find any other file yet. I used ClamAV to scan this partition but it did not even find the exe in the &quot;app data&quot; folder(since it is not the best choice anyway). It seems like this scarware uses varied names to store its data but the server.exe and socks.exe should exist i think and the names do not seem like they varie. 
Since the Program doesnot seem to corrupt any random data, im going to reboot into windows and see what i can do there since i have removed ev erything if found concerning this virus. Thank you</description>
		<content:encoded><![CDATA[<p>Well last time i booted into windows my desktop-background was izohore.bmp and a strange &#8220;Anti Virus&#8221; Software was scanning some files. So it seems like i have got this thing. The Problem was that i could not Run any App like firefox or taskmanager since the &#8220;AV&#8221; &#8220;detected an infection&#8221; So i quickliy shut down my computer and booted into Linux. I mounted the WINDOWS partition and fount strange nubered exe in an stange numbered folder in /all users/Application Data/ and the izohore.bmp in \user\Local Settings\Temp\ but i couldnot find any other file yet. I used ClamAV to scan this partition but it did not even find the exe in the &#8220;app data&#8221; folder(since it is not the best choice anyway). It seems like this scarware uses varied names to store its data but the server.exe and socks.exe should exist i think and the names do not seem like they varie.<br />
Since the Program doesnot seem to corrupt any random data, im going to reboot into windows and see what i can do there since i have removed ev erything if found concerning this virus. Thank you</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Real Host now shutdown by ejes</title>
		<link>http://www.martinsecurity.net/2009/08/05/real-host-now-shutdown/comment-page-1/#comment-1093</link>
		<dc:creator>ejes</dc:creator>
		<pubDate>Fri, 07 Aug 2009 13:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=412#comment-1093</guid>
		<description>Good work man :)</description>
		<content:encoded><![CDATA[<p>Good work man <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Nine-Ball followup now with video! Part 2 by wario</title>
		<link>http://www.martinsecurity.net/2009/07/29/nine-ball-followup-now-with-video-part-2/comment-page-1/#comment-804</link>
		<dc:creator>wario</dc:creator>
		<pubDate>Sun, 02 Aug 2009 01:41:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=371#comment-804</guid>
		<description>nice informative tutorial and the music is great, it really picks up at 2:30</description>
		<content:encoded><![CDATA[<p>nice informative tutorial and the music is great, it really picks up at 2:30</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised by Lori</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-346</link>
		<dc:creator>Lori</dc:creator>
		<pubDate>Fri, 10 Jul 2009 20:18:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-346</guid>
		<description>i have this virus on my computer and was unable to access certain websites. now whenever i try to open IE 7 to any page, it shows trughtsa.com, sticks there for a while, an adobe error comes up and then the whole program shuts down. how do i get this off of my computer???? please help!!!</description>
		<content:encoded><![CDATA[<p>i have this virus on my computer and was unable to access certain websites. now whenever i try to open IE 7 to any page, it shows trughtsa.com, sticks there for a while, an adobe error comes up and then the whole program shuts down. how do i get this off of my computer???? please help!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Nine-Ball = Gumblar Redux? &#8211; 40,000 websites compromised by Jacob</title>
		<link>http://www.martinsecurity.net/2009/06/16/nine-ball-gumblar-redux-40000-websites-compromised/comment-page-1/#comment-306</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Tue, 07 Jul 2009 21:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.martinsecurity.net/?p=326#comment-306</guid>
		<description>Hi, after reading this im absolutely positive that i have this on my computer. It seems to block my anti virus from working.
(I have Trend Micro) You&#039;re website is the only place i&#039;ve found information on this so far. If you could help me in removing it, or direct me somewhere that can it would be greatly appreciated.</description>
		<content:encoded><![CDATA[<p>Hi, after reading this im absolutely positive that i have this on my computer. It seems to block my anti virus from working.<br />
(I have Trend Micro) You&#8217;re website is the only place i&#8217;ve found information on this so far. If you could help me in removing it, or direct me somewhere that can it would be greatly appreciated.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
