Friday, June 20, 2008
Increase in hijacked sites.
There has been a large increase in hijacked websites, especially those that have the video.exe and video1.exe. The same goes for redirected websites and hijacked php websites.
Saturday, June 14, 2008
Old, but a goodie.
The tatics are now down to the oldies, goodies
1) send us your name
2) send us your password
1) send us your name
2) send us your password
Wednesday, June 11, 2008
Increase in IPs
Recently, there has been an increase of raw IPs given. I'm not entirely sure of what to make of it. It is significant somehow. I have a few ideas. More on this later.
Friday, June 6, 2008
Example of hijacked machine.
No firewall? No clue?
Here is a URL address of a machine that was hijacked and they are using an alternate port (84) to phish for ebay names and passwords. At first I did not recognize it, but 3 or 4 seconds later it dawned upon me what was going on.
http://207-172-200-73.c3-0.upd-ubr13.trpr-upd.pa.cable.rcn.com:84/www.ebay.com-signin-ebay.com.html
Here is a URL address of a machine that was hijacked and they are using an alternate port (84) to phish for ebay names and passwords. At first I did not recognize it, but 3 or 4 seconds later it dawned upon me what was going on.
http://207-172-200-73.c3-0.upd-ubr13.trpr-upd.pa.cable.rcn.com:84/www.ebay.com-signin-ebay.com.html
Thursday, June 5, 2008
No Sacred Ground
Today a new domain caught my eye. I though, perhaps, that it was a hijacked domain, but not. It advertises "the latest update in ED treatment", with it being a "Limited time offer". (ED, of course, being Erectial Dysfunction.)
Anyhow, the domain is healthykidsinc.com
I guess it relates.
Anyhow, the domain is healthykidsinc.com
I guess it relates.
Ramping up.
Volume of spam over the last few days has ramped up. In addition, it looks like the captcha at geocites.com has completed failed. They have become blatant to the point of being obvious. As and example, they have completely given up on using "real sounding" domain names.
Here are a couple names as an examples.
kdoitueuryfgvavec.com
www.geocities.com/barbaraafkdxdy
Here are a couple names as an examples.
kdoitueuryfgvavec.com
www.geocities.com/barbaraafkdxdy
Tuesday, May 27, 2008
Brazen Use of Geocites.com
Should anyone forget, geocities.com is owned by Yahoo! And currently, Yahoo! is under market attack, stock market attack. As such, should not be of any wonder if the management is a bit distracted. Proof is in the names spammers are using to hijack account at geocities. Here are two (2) examples.
http://www.geocities.com/bnnmqsfqa
http://www. geocities.com/dtspdzkrzxsx
They both have their own sets of obfuscated javascript. Example below.
----
<script language="JavaScript" type="text/javascript">var pcyr='dnbwddumxrutoetjbi';var jryb=0;var zvunzgj, woqv, nueexs='581D01050D14014D14131B131A04130F5F4B2E0F1416370707040806574A180C1A0E0D1E4A1A0D074A081A0E19061C1B014B1C18070F445342500C10011D425D5A060A1518130F0C0A40011809434E515701160606150054';woqv='';var xhbgqyi;for( zvunzgj=0;zvunzgj < xhbgqyi =" unescape(">= pcyr.length ) jryb = 0;}document.write(woqv);</script>
http://www.geocities.com/bnnmqsfqa
http://www. geocities.com/dtspdzkrzxsx
They both have their own sets of obfuscated javascript. Example below.
----
<script language="JavaScript" type="text/javascript">var pcyr='dnbwddumxrutoetjbi';var jryb=0;var zvunzgj, woqv, nueexs='581D01050D14014D14131B131A04130F5F4B2E0F1416370707040806574A180C1A0E0D1E4A1A0D074A081A0E19061C1B014B1C18070F445342500C10011D425D5A060A1518130F0C0A40011809434E515701160606150054';woqv='';var xhbgqyi;for( zvunzgj=0;zvunzgj < xhbgqyi =" unescape(">= pcyr.length ) jryb = 0;}document.write(woqv);</script>
Subscribe to:
Posts (Atom)