<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9202429674312578040</id><updated>2012-01-25T02:55:52.283-05:00</updated><category term='Peer-to-peer'/><category term='Windows XP'/><category term='Brian Krebs'/><category term='March Madness'/><category term='Email'/><category term='European Commission'/><category term='Webserver directory index'/><category term='HTTP referrer'/><category term='Social network service'/><category term='Crime'/><category term='trojans'/><category term='malware'/><category term='kaspersky'/><category term='Mozilla Firefox'/><category term='France'/><category term='privacy'/><category term='HTML element'/><category term='anti virus'/><category term='IP address'/><category term='User'/><category term='Kaminsky'/><category term='Internet service provider'/><category term='Lost Boys'/><category term='Google Profile'/><category term='Picasa'/><category term='the team'/><category term='spam'/><category term='internet'/><category term='Windows 64-bit'/><category term='Malicious Software'/><category term='Corey Haim'/><category term='cygnos'/><category term='Kaspersky Lab'/><category term='India'/><category term='Web search engine'/><category term='Electronic Privacy Information Center'/><category term='Windows 7'/><category term='Pop-up ad'/><category term='facebook'/><category term='Federal Trade Commission'/><category term='botnets'/><category term='Domain name'/><category term='Electronic Communications Privacy Act'/><category term='Windows Vista'/><category term='Storm'/><category term='Website'/><category term='Lambdanet'/><category term='Cross-site scripting'/><category term='security'/><category term='File Transfer Protocol'/><category term='Command and control'/><category term='Eric Schmidt'/><category term='Taskbar'/><category term='Sandra Bullock'/><category term='symantec'/><category term='For Sale or Auction'/><category term='Search'/><category term='Consultants'/><category term='Bullguard'/><category term='Google'/><category term='Business'/><category term='Operating system'/><category term='E-mail'/><category term='Tabanus sudeticus'/><category term='Company'/><category term='cira'/><category term='antivirus'/><category term='Microsoft Windows'/><category term='Bitdefender'/><category term='defintel'/><category term='Slot machine'/><category term='dns'/><category term='FireEye'/><category term='pifts'/><category term='Domain Name System'/><category term='European Commission and Microsoft'/><category term='twitter'/><category term='Zeus'/><category term='microsoft'/><category term='Botnet'/><category term='VirusTotal'/><category term='Internet Explorer'/><category term='Tiger Woods'/><category term='Gumblar'/><category term='Uniform Resource Locator'/><category term='Google Buzz'/><category term='Google Trends'/><category term='Search engine optimization'/><title type='text'>Defence Intelligence</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Davis</name><uri>http://www.blogger.com/profile/13713470016162233081</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>45</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-6615415257962261837</id><published>2012-01-09T12:38:00.002-05:00</published><updated>2012-01-09T13:54:12.538-05:00</updated><title type='text'>7 Security Resolutions for 2012</title><content type='html'>I have spoken before about how we in the security industry need to spend less time talking amongst ourselves and more time trying to educate the average computer user. &amp;nbsp;The following 7 security resolutions for 2012 are part of that pledge.&lt;br /&gt;&lt;br /&gt;For anyone in the industry, there is nothing new here. &amp;nbsp;Having said that, security experts are just as guilty as most when it comes to some of the basics. &amp;nbsp;Do you really use a unique password everywhere? Have you never clicked on a shortened link?&lt;br /&gt;&lt;br /&gt;We often talk about being proactive and not reactive. &amp;nbsp;Now is the chance to practice what we preach.&amp;nbsp;We created the following hoping that people would send it to that aunt that keeps forwarding the powerpoint slideshows. &amp;nbsp;That friend on messenger that keeps getting "hacked". &amp;nbsp;&amp;nbsp;Instead of helping them clean up their infested computers when it's too late, maybe we can help keep them from being compromised in the first place.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.defintel.com/images/security%20resolutions.png"&gt;http://www.defintel.com/images/security%20resolutions.png&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Happy New Year!&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-y0iTXWx3UdE/Twskb15PzMI/AAAAAAAAAHo/uMhsBjLlD8A/s1600/security+resolutions.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://1.bp.blogspot.com/-y0iTXWx3UdE/Twskb15PzMI/AAAAAAAAAHo/uMhsBjLlD8A/s640/security+resolutions.png" width="498" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-6615415257962261837?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/6615415257962261837/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=6615415257962261837' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6615415257962261837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6615415257962261837'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2012/01/7-security-resolutions-for-2012.html' title='7 Security Resolutions for 2012'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-y0iTXWx3UdE/Twskb15PzMI/AAAAAAAAAHo/uMhsBjLlD8A/s72-c/security+resolutions.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1241725660969621909</id><published>2011-11-10T11:15:00.001-05:00</published><updated>2011-11-10T11:41:01.199-05:00</updated><title type='text'>DNS Changer Malware / Operation Ghost Click</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-GSnu-QYlG2c/Trv-CZmeSdI/AAAAAAAAAHg/4tD4xlHK0KU/s1600/screen-capture-1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="121" src="http://3.bp.blogspot.com/-GSnu-QYlG2c/Trv-CZmeSdI/AAAAAAAAAHg/4tD4xlHK0KU/s320/screen-capture-1.png" width="320" /&gt;&lt;/a&gt;Trend Micro recently announced, along with the FBI, the dismantling of a cyber criminal gang based out of Estonia. The gang was allegedly responsible for compromising millions of computers and redirecting them to online ads through the implementation of rogue DNS servers. &lt;br /&gt;&lt;br /&gt;Over four million computers across 100 countries had inadvertently downloaded malware onto their systems, many through installing what they thought was a needed codec to view certain movies online. Compromised systems would then have their DNS settings altered to use servers controlled by the gang, rerouting the end users to locations on the Internet they never intended to visit. &lt;br /&gt;&lt;br /&gt;These locations contain ads which, upon click-through or even viewing, generated revenue for the gang, resulting in over $14 million made through advertising fraud. The U.S. Attorney's Office is seeking to extradite the gang for prosecution, likely due to the large number of U.S. government and businesses systems compromised by the gang and the fact that some of the rogue DNS servers were based in Chicago and New York.&lt;br /&gt;&lt;br /&gt;DNS provides the IP address location of a website so a user who types "google.com" into a browser is actually taken to "72.14.204.103" (or one of their other IP locations). By forcing a system to use a specific DNS server, like this gang did, users would receive false IP address locations for websites they were trying to visit or ads they normally would have viewed, benefiting the gang while not maliciously harming the user. Examples provided during the indictment of the six Estonian members of the gang included:&lt;br /&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;"When the user of an infected computer clicked on a domain name link for Netflix, the user was instead taken to a website for an unrelated business called 'BudgetMatch.'"&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;"When the user of an infected computer visited the home page of the Wall Street Journal, a featured advertisement for the American Express 'Plum Card' had been fraudulently replaced with an ad for 'Fashion Girl LA.'"&lt;/blockquote&gt;&lt;br /&gt;The malware which compromised these systems also prevented updates to anti-virus software and the operating system. This helped the malware stay on the compromised systems over an extended period of time. For those concerned that they may be compromised the FBI has provided a document which aids in understanding the malware and how to check for DNS settings changes on your computer, for both Windows and Mac systems.&lt;br /&gt;&lt;a href="http://www.fbi.gov/news/stories/2011/november/malware_110911/dns-changer-malware.pdf"&gt;The FBI doc &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In this document the IP address ranges of the known rogue DNS servers are listed, indicating server locations in Russia, Ukraine, U.S., and Amsterdam. You can see the ranges below:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;85.255.112.0 through 85.255.127.255&lt;br /&gt;67.210.0.0 through 67.210.15.255&lt;br /&gt;93.188.160.0 through 93.188.167.255&lt;br /&gt;77.67.83.0 through 77.67.83.255&lt;br /&gt;213.109.64.0 through 213.109.79.255&lt;br /&gt;64.28.176.0 through 64.28.191.255&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;-Matt Sully&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1241725660969621909?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1241725660969621909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1241725660969621909' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1241725660969621909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1241725660969621909'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/11/dns-changer-malware-operation-ghost.html' title='DNS Changer Malware / Operation Ghost Click'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-GSnu-QYlG2c/Trv-CZmeSdI/AAAAAAAAAHg/4tD4xlHK0KU/s72-c/screen-capture-1.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-6972363040072431081</id><published>2011-11-03T15:08:00.000-04:00</published><updated>2011-11-03T15:08:39.501-04:00</updated><title type='text'>Security through the eyes of a teenager. Part 2</title><content type='html'>&lt;br /&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;b&gt;Are young people more knowledgeable about information security than their elders?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;I believe that young people are more knowledgeable when it comes to security. The reason being that my generation has been brought up with daily use of computers. We have more experience than most of the older population. This does not mean that everyone from my generation knows how to stay secure while online.&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;b&gt;Are young people concerned about privacy online?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;Everyone says they are worried about their privacy, but young people have already posted all kinds of information about themselves on Facebook, Twitter, and many other social networks&amp;nbsp; Even if the settings on that site lower the visibility to the public eye, they are still there. I’m not sure if young people believe privacy of their information to be important since it is already up there. If it is banking information then we worry, but if not, then it is less of a concern.&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;b&gt;How concerned about information security are young people?&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;Personally, I don’t believe that young people are worried about information security at all. We all fret when something goes wrong, but before something happens, security is not always important. I think the reason for this is that we are not the ones paying for it. It also depends on what kind of computer they are using, and the marketing out there. I remember when I got my MacBook, I thought it was immune to harmful internet malware. I started downloading more movies and music, something I would have not done on my old laptop which was a PC.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: normal normal normal 12px/normal Helvetica; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: left;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;Here are the results of the survey that I sent to my friends:&lt;/span&gt;&lt;/div&gt;&lt;div style="font: normal normal normal 12px/normal Helvetica; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 14px; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-3R6QKIXDjPw/TrLjANEf7dI/AAAAAAAAAHQ/sHhsLw1_xHQ/s1600/montana+blog_Page_2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/-3R6QKIXDjPw/TrLjANEf7dI/AAAAAAAAAHQ/sHhsLw1_xHQ/s640/montana+blog_Page_2.png" width="492" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-h0k4FCsmn1Y/TrLjB6Jkr3I/AAAAAAAAAHY/XaPgfrbhvRw/s1600/montana+blog_Page_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://3.bp.blogspot.com/-h0k4FCsmn1Y/TrLjB6Jkr3I/AAAAAAAAAHY/XaPgfrbhvRw/s640/montana+blog_Page_3.png" width="496" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px; min-height: 14.0px;"&gt;&lt;span style="letter-spacing: 0.0px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-MymS-QoSzZE/TrLBe5CKxoI/AAAAAAAAAG4/DVzHPeGYsnw/s1600/montana+blog_Page_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #0000ee;"&gt;-Montana&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="font: 12.0px Helvetica; margin: 0.0px 0.0px 0.0px 0.0px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-6972363040072431081?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/6972363040072431081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=6972363040072431081' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6972363040072431081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6972363040072431081'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/11/security-through-eyes-of-teenager-part.html' title='Security through the eyes of a teenager. Part 2'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-3R6QKIXDjPw/TrLjANEf7dI/AAAAAAAAAHQ/sHhsLw1_xHQ/s72-c/montana+blog_Page_2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-6746974985592036857</id><published>2011-10-24T17:25:00.000-04:00</published><updated>2011-10-24T17:25:12.488-04:00</updated><title type='text'>Security through the eyes of a teenager.  Part 1</title><content type='html'>&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;i&gt;It's often assumed that younger generations are more aware of online threats than us old folks. &amp;nbsp;The notion being that since they've grown up on the internet, they are more knowledgeable and tech savvy. We decided to put this theory to the test.&lt;/i&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;i&gt;As part of a co-op initiative, &amp;nbsp;Defence Intelligence has recently been joined by a 17 year old high school student named Montana. &amp;nbsp;We thought this would be a great chance to get some insight into what young people really think about information security. &amp;nbsp;As part of her work here, she's going to be doing some research on awareness amongst her peers. &amp;nbsp;Over the next couple of weeks, she'll be taking over our blog and posting her findings. &amp;nbsp;Here she is with her introduction. &amp;nbsp;- Keith&lt;/i&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;My name is Montana, and I am a student at West Carleton Secondary School in Dunrobin, Ontario. I signed up for co-op last year to gain an understanding of a specific field that could possibly open many opportunities. I take co-op for five days a week, three hours a day.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;I first decided I was going to take the co-op course at my school when a friend informed me about her experience. I was interested in learning more about a possible career, and&amp;nbsp;began to think what field I would be interested in. I have taken an interest in working with computers but I was uncertain of which direction. After doing some research I discovered Defence Intelligence – a small Ottawa based information security company.&amp;nbsp;I was fortunate to be able to have such a unique Co-op placement.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;My first day of co-op started by getting myself lost on the OC Transpo bus routes. Once I found the place, I was confused just by the terminology, let alone the work I was doing. After a few days of adjustment and the help of Mr. Sully’s patient explanations, I became more comfortable.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;I was first given a project to research the top 25 websites I visited most often. I learned how to use many online resources, the threat analyst interface, and Google search in an effective way. I was able to identify what information is valuable when making a decision about the safety of a website.&amp;nbsp;Each day I was getting better and faster by expanding my intake of knowledge. I was eager to learn as much as possible and to test out my abilities.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Back at school, many students were interested when I got to describe my job and share what I do. It made me sound pretty technical, although I had no previous experience with internet security before.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;After many weeks, I gave a presentation to my co-workers.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;That’s what I enjoy about working here. I get the opportunity to make an actual business presentation where I am relied on to demonstrate my understanding. I learned how to speak to people and how to present myself with the comprehension I gained.&amp;nbsp;&amp;nbsp;The subject was the threat analyst interface, which has been an ongoing project since I joined Defence Intelligence. I was not nervous about presenting in front of everyone, but was afraid of not giving a clear explanation. I did fairly well, but with some improvements needed.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;When I walked in one afternoon, I was told that I was to be moved around to get a feel for all parts of the business. I am not only learning about the specialty of the business, but the sales side and much more.&amp;nbsp;I was also given a project to create a survey for my friends to answer.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;This survey was intended to get feedback from teenagers about internet security and if they really cared about it. The survey was made up of 10 questions. The first time I mentioned the survey was on Facebook. I posted the survey as a disguised link. This way I was able to see the amount of people who will click on an unknown (potentially untrustworthy) link. I will later repost the link and ask my friends to complete the survey.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Mrs. Stewart, my co-op teacher, came in one day to see how things were going at my work placement. She was pleased to hear that I was enjoying my time at Defence Intelligence. She was also impressed with the variety of areas that I would be working in.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;My co-op placement has lived up to my expectations and I am learning more than what a class in school could teach me – business techniques, management, working with others, communications skills, and so much more. I’m really thankful to Defence Intelligence for taking me on as a co-op student and feeding me with incredible amounts of knowledge.&amp;nbsp;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;- Montana&lt;/div&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-6746974985592036857?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/6746974985592036857/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=6746974985592036857' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6746974985592036857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6746974985592036857'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/10/security-through-eyes-of-teenager-part.html' title='Security through the eyes of a teenager.  Part 1'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-8173087962581422576</id><published>2011-08-24T10:41:00.000-04:00</published><updated>2011-08-24T10:41:07.796-04:00</updated><title type='text'>It's only an option if you know you have a choice</title><content type='html'>I have backlogs everywhere and am probably the worst person in the world at keeping up with my social networking updates. If people only knew about my life through my sporadic social updates, they'd think I was still "Having a good time at Steak and Ale, about to go see this new Gladiator movie."&lt;br /&gt;&lt;br /&gt;In one of my few and far between surfacings for air, I saw some important offerings in the blogging world addressing privacy and security issues of our currently beloved social tools, Twitter and Linkedin.&lt;br /&gt;&lt;br /&gt;Graham Cluley put out a &lt;a href="http://nakedsecurity.sophos.com/2011/08/24/twitter-https-by-default/"&gt;blog this morning&lt;/a&gt; about Twitter's efforts to begin default HTTPS usage, starting with a small percentage of users. The option to choose an HTTPS connection, however, is available to all Twitter users, and can be enabled through the settings page (at the bottom).&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-BKKiOaMRRyU/TlT_ED_CImI/AAAAAAAAAGs/1D8VfbjEQuI/s1600/twitter_https.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="37" src="http://1.bp.blogspot.com/-BKKiOaMRRyU/TlT_ED_CImI/AAAAAAAAAGs/1D8VfbjEQuI/s320/twitter_https.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;HTTPS encrypts your normal HTTP traffic across the network, protecting the data being exchanged and the identification of the exchanging parties. This was publicly popularized for banking and purchasing transactions but is making its way into other facets of the internet.&lt;br /&gt;&lt;br /&gt;It's always a smart move to choose HTTPS for your connections into social networking sites. No matter who you are or what sort of details you share with others, every user should be concerned about their privacy and protection of the ownership over their own accounts. For those who like to connect to public wi-fi spots, this is especially important, as open wi-fi leaves you vulnerable to eavesdropping by others.&lt;br /&gt;&lt;br /&gt;Facebook offers HTTPS as well, so search out this setting and enable it if it isn't already enabled. HTTPS is of course important to your security, but there are plenty more settings on Facebook and elsewhere that may be of concern to you regarding usage of your private data.&lt;br /&gt;&lt;br /&gt;Rik Ferguson recently &lt;a href="http://countermeasures.trendmicro.eu/linkedin-optout/"&gt;blogged&lt;/a&gt; about Linkedin settings dealing with social advertising, which would use your own personal information in some of the ads put out across the Linkedin site. This would include your name and profile photo integrated right into the advertisement, giving the appearance that you personally endorse a product or service. I already have a big enough issue with buying shirts smeared with the name of the department store. Where's my discount for free advertising? They should pay ME to wear these shirts.&lt;br /&gt;&lt;br /&gt;To disable these advertising options on Linkedin, go to your settings page and click on "account" in the bottom left. Rik walks you through it on his blog &lt;a href="http://countermeasures.trendmicro.eu/linkedin-optout/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Spend some time today, and periodically (new defaults pop up all the time), digging through your social networking settings and opt out of what you don't want. Pay attention to what you're agreeing to when you sign up for a new service. Your safety and privacy could be at risk. And stop buying T-shirts with the store name on them. That's just wrong.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-8173087962581422576?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/8173087962581422576/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=8173087962581422576' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8173087962581422576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8173087962581422576'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/08/its-only-option-if-you-know-you-have.html' title='It&apos;s only an option if you know you have a choice'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-BKKiOaMRRyU/TlT_ED_CImI/AAAAAAAAAGs/1D8VfbjEQuI/s72-c/twitter_https.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-3060567468291400458</id><published>2011-08-10T16:07:00.000-04:00</published><updated>2011-08-10T16:07:05.474-04:00</updated><title type='text'>Defcon 19 Cell Hack</title><content type='html'>Hackers from around the globe recently met in Vegas for the 19th Defcon hacking conference. This is a huge event for those interested in security and more importantly, the holes in current security products and tactics, as well as next generation vulnerabilities. So naturally, one might be wary of freely using their laptop or smart phone around so many hacking enthusiasts. Throwing caution to the digital wind however, perhaps through arrogance, confidence, or disregard, people still actively connected, but mostly through their cell phones instead of their laptops.&lt;br /&gt;&lt;br /&gt;Though little is confirmed about a legitimate hack, while at the conference people were expressing concern over strange occurrences on their phones, including degraded signal and well timed multiple suggested software updates. Degraded service where thousands of 4G users are bombarding towers all at the same time may be reasonably expected. According to a post on &lt;a href="http://seclists.org/fulldisclosure/2011/Aug/76"&gt;seclists.org&lt;/a&gt;, however, a "weapon" may have been used to gain access to thousands of what should have been suspecting cell phone users' phones and computers at Defcon.&lt;br /&gt;&lt;br /&gt;In the seclists.org post by coderman, he says the attack was designed for mass exploitation, reconnaissance, [data] exfiltration, and eavesdropping, using a variety of exploits and techniques across CDMA and 4G connections.&lt;br /&gt;&lt;br /&gt;He offers in the same post symptoms or actions that may indicate a victim of the Defcon cell attack. Some of the symptoms are vague and include an Android crash or charging troubles, which could be caused by normal issues. Other symptoms, which may still be benign, include full signal but poor bandwidth, or slow download speeds but fast upload speeds. Most concerning, though possibly excluding phones, he mentions the presence of an ssh process that can't be killed.&lt;br /&gt;&lt;br /&gt;Fake charging stations, believed to be a delivery method for the malware mentioned here, were sprinkled throughout the area. Many were wise enough to spot and avoid them, but plugging in anywhere while at Defcon was a generally recognized bad idea, but apparently not recognized enough.&lt;br /&gt;&lt;br /&gt;I am disappointed by the lack of paranoia/caution displayed by the people who attended this event. They should know better than to trust leaving anything open to compromise when going to a conference like this, from their wallets to their cell phones. Attendees were even advised by &lt;i&gt;staff&lt;/i&gt; not to use the available wifi. Even hackers are victims from time to time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-3060567468291400458?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/3060567468291400458/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=3060567468291400458' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3060567468291400458'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3060567468291400458'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/08/defcon-19-cell-hack.html' title='Defcon 19 Cell Hack'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-3388564386585121630</id><published>2011-07-28T13:45:00.003-04:00</published><updated>2011-08-11T19:16:19.453-04:00</updated><title type='text'>IT Security Isn't Important - Part 1 of 3</title><content type='html'>&lt;br /&gt;That's right, it isn't important. &amp;nbsp;I realize that it matters to most of the people reading this. &amp;nbsp;What I have &amp;nbsp;recently realized, however, is that it really doesn't matter to most. &amp;nbsp;We in the industry are in denial about our place in the scheme of things. &amp;nbsp;It's self-evident to us that information security is of vital importance. &amp;nbsp;We talk about the massive market for IT security, the amount of press breaches are given, and the big push for compliance and increased security across all standards. &amp;nbsp;Still, it's just not that important to enough people. &amp;nbsp;Symantec had roughly $6b in revenue last year. &amp;nbsp;While they were doing that, Avon sold $11b worth of cosmetics using a network of door to door salespeople. &amp;nbsp;Think about it.&lt;br /&gt;&lt;br /&gt;The IT security market is considerable. &amp;nbsp;Gartner estimates it to be in the realm of $85b a year. &amp;nbsp;$85b is a lot of money. &amp;nbsp;Having said that, there was more money spent on commercial cleaning and garbage removal last year than there was on IT security. &amp;nbsp;So really, how important are we? &amp;nbsp;While the threat of a dirty office is no laughing matter, I don't think it is quite as important as keeping your data secure.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-aJE4HxdjWeE/TjGftbajoLI/AAAAAAAAAGc/BiL5XKYRW6Y/s1600/WXdJB.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-aJE4HxdjWeE/TjGftbajoLI/AAAAAAAAAGc/BiL5XKYRW6Y/s320/WXdJB.jpg" width="239" /&gt;&lt;/a&gt;We talk a lot about user awareness and training, and yet I think we've failed in that it's something that we mention to people and then forget. &amp;nbsp;It's very much a "do as I say and not as I do" mentality. &amp;nbsp;We speak to organizations and groups about awareness, but do little ourselves to spread that awarenes. &amp;nbsp;I'm as guilty as anyone in this regard. &amp;nbsp;Three years in, and the most my friends and family can say of my business is that I do "fancy anti-virus or something". &amp;nbsp;This is usually followed up by a request to "speed their computer up". &amp;nbsp;The number one question I get from the average consumer? &amp;nbsp;"Is it safe to use my credit card online?" &amp;nbsp;Nearly twenty years on, and we still haven't answered a single question for the general public.&lt;br /&gt;&lt;br /&gt;Most people have a very good knowledge of “real world” crimes. &amp;nbsp;It makes sense, they’ve been around longer and get all the good TV shows. &amp;nbsp;What we need to do is translate cyber crimes into “real world” crimes. &amp;nbsp;Most people think they know what a virus is, or what a hacker does. &amp;nbsp;Mostly though, they just don’t. &amp;nbsp;I have had far too many conversations with C-level execs and VPs who have absolutely no clue. &amp;nbsp;It's disheartening when you speak to the CIO of a Fortune 50 company who doesn't know what a botnet is. &amp;nbsp;It's disheartening, but it's also enlightening. We need people to understand that what happens online affects the real world, and them directly. &amp;nbsp;In short, we need to make information security important to them personally.&lt;br /&gt;&lt;br /&gt;It’s up to us as security professionals to make it important to everyone. &amp;nbsp;It’s up to us to help people understand. &amp;nbsp;We need to step outside of the security groups and the IT crowd. &amp;nbsp;We need to talk to the business leaders, the financial teams, the HR groups, all of them. &amp;nbsp;We should be talking to our friends, our colleagues, that aunt that keeps sending out the cute slideshows. &amp;nbsp;If we ever want the average user to “get it”, we need to help them do so. &amp;nbsp;Until then, it just won’t be important.&lt;br /&gt;&lt;br /&gt;While we need to exchange ideas and information with our peers, what I think is even more crucial is that we spend more time talking to the uninitiated. &amp;nbsp;It's great to see all the experts at an event, but what would help our industry more is to see the non-experts at these events. If we keep talking to other experts and rely on them to spread the word, we'll continue to fail.&lt;br /&gt;&lt;br /&gt;So do we start at the top? &amp;nbsp;Should we try to get the government to mandate the hell out of security and force people's hands? &amp;nbsp;Do we harass CEOs to institute appropriate policies and then enforce them? &amp;nbsp;I don't think so. &amp;nbsp;Good policy is important, but even the best policy is easily ignored by those who care little for it. &amp;nbsp;I think we all know enough users who skirt their employers facebook policy. &amp;nbsp;If people don't understand the policy and the reasoning behind it, they will never back it, and they will never adhere to it.&lt;br /&gt;&lt;br /&gt;Defence Intelligence has run a number of informational seminars in the past. &amp;nbsp;These have mostly been aimed at specific threats or technologies, and were designed for security experts. &amp;nbsp;What I'm asking myself now is, why have we never done a far more basic seminar for the layman? &amp;nbsp;We feel the pain of the security staff while they try to justify their budget, but what have we done to help them? &amp;nbsp;I've been frustrated many times while trying to explain why "we have a firewall" is not a legitimate security stance. &amp;nbsp;Really, though, how much have I done to correct it? &lt;br /&gt;&lt;br /&gt;We’re going to change. &amp;nbsp;We’re going to start offering basic informational seminars and training to both our clients and our potential clients. &amp;nbsp;No fees, no product pitch, just basic information, awareness and policy for anyone who might be interested. &amp;nbsp;At least then we’ll be able to say that we’re doing our part to make security important.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Part 2 coming soon - Why IT Security Isn't Important&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-3388564386585121630?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/3388564386585121630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=3388564386585121630' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3388564386585121630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3388564386585121630'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/07/it-security-isnt-important.html' title='IT Security Isn&apos;t Important - Part 1 of 3'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-aJE4HxdjWeE/TjGftbajoLI/AAAAAAAAAGc/BiL5XKYRW6Y/s72-c/WXdJB.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1373784211029377562</id><published>2011-07-25T17:24:00.002-04:00</published><updated>2011-07-25T17:24:43.776-04:00</updated><title type='text'>Mariposa Redux</title><content type='html'>It seems that long after we identified and took down Mariposa, bad folks are still using the butterfly kit behind it to build large botnets.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;There’s been some coverage around the EvilFistSquad/Metulji takedown recently, and given the relationship to Mariposa, I thought I’d say a few words.&lt;br /&gt;&lt;br /&gt;A few points:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Mariposa is back?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;EvilFistSquad/Metulji is not Mariposa.&amp;nbsp; It is similar in intent and based on the same butterfly kit.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How big is it?&amp;nbsp;&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;Like Mariposa, it’s impossible to tell for certain.&amp;nbsp; Even if all command and control domains were seized, dynamic ips, NATs/firewalls, etc. make it impossible to be sure.&amp;nbsp; By all accounts, it’s big.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Who is behind it?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The FBI and Interpol arrested two individuals earlier this month in connection with this botnet.&amp;nbsp; It is unclear, but likely, that other operators are still at large.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Is it still active?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Some of the command and control domains have been taken down, but not all.&amp;nbsp; Compromised systems are still losing data.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;What we can learn from this:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;What this takedown shows us is that you needn’t be technically proficient or even all that clever to amass millions of victims.&amp;nbsp; Think about it:&lt;br /&gt;&lt;br /&gt;The creator of butterfly was arrested and had his equipment seized.&amp;nbsp; The authorities have all his transaction details and know who purchased the kit.&lt;br /&gt;&lt;br /&gt;The botmasters raised suspicions by extravagant spending.&lt;br /&gt;&lt;br /&gt;The botmasters used their real names and addresses in some cases.&lt;br /&gt;&lt;br /&gt;As Luis Carrons from Panda was quoted as saying: "Obviously, those bot masters are either not concerned about going to jail or just plain stupid.”&lt;br /&gt;&lt;br /&gt;This case also goes to show just how difficult these botnets can be to dismantle.&amp;nbsp; Even when the malware is known, even when the attackers are less than gifted, it can still be incredibly difficult to take down a botnet.&amp;nbsp; Mariposa was a rare slam dunk in that we were able to gain control of all of the C&amp;amp;C domains simultaneously and redirect them to our space.&lt;br /&gt;&lt;br /&gt;Working with Panda and the FBI for the Mariposa takedown was a pleasure, and I’m glad to see that they’re staying on top of all the butterflies out there.&amp;nbsp; This is another example of how Law Enforcement, Researchers, and the private sector can work together to be more effective in the fight against online crime.&lt;br /&gt;&lt;br /&gt;Congratulations to all those who worked on this, keep up the good fight.&lt;br /&gt;&lt;br /&gt;Keith Murphy&lt;br /&gt;CEO&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1373784211029377562?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1373784211029377562/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1373784211029377562' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1373784211029377562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1373784211029377562'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/07/mariposa-redux.html' title='Mariposa Redux'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-448205925659279016</id><published>2011-07-20T10:32:00.000-04:00</published><updated>2011-07-20T10:32:24.595-04:00</updated><title type='text'>Google Plus Anti-Malware</title><content type='html'>Google never rests, and is always mixing up something new to try out on its users. Some efforts have been failures and others have been welcomed by many. Recently, &lt;a href="http://googleblog.blogspot.com/2011/07/using-data-to-protect-people-from.html"&gt;Google announced&lt;/a&gt; a seemingly one-time attempt at informing specific users of a possible malware compromise on their systems.&lt;br /&gt;&lt;br /&gt;Currently they are a bit vague on the malware involved, but state in their blog that this particular malware uses a limited number of proxies to send traffic to Google. When a user compromised by this malware visits Google they are displayed a message at the top of their browsers saying, "Your computer appears to be infected."&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-mUJadOi3wXE/TibmkNRQrPI/AAAAAAAAAGY/uKPzTl7IZk0/s1600/MalwareWarningScreenshot.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="83" src="http://3.bp.blogspot.com/-mUJadOi3wXE/TibmkNRQrPI/AAAAAAAAAGY/uKPzTl7IZk0/s320/MalwareWarningScreenshot.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It must really be a very specific and limited means of terminating traffic that ends up at Google through these proxies for the company to display these messages with confidence. A wide range of malware utilizes Google in some way to carry out functions or as a form of communication. Some use Google resources as a way to spread malware, through fake Blogspot pages or highjacked web searches. Some malware just checks Google to make sure the compromised system has an internet connection.&amp;nbsp;&lt;br /&gt;&lt;br /&gt;This may only be a one time event, but I wouldn't put it past Google that this is an introduction into future areas of exploration into the anti-virus field. Why not? They dip their fingers into every other internet pot. Google safe browsing is already a sight people have grown accustomed to and understand as well as embrace.&amp;nbsp; Is Google going to capitalize on their already existing involvement in the malware world by taking the extra step toward their end users? Is Google AV on the horizon?&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-448205925659279016?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/448205925659279016/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=448205925659279016' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/448205925659279016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/448205925659279016'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/07/google-plus-anti-malware.html' title='Google Plus Anti-Malware'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-mUJadOi3wXE/TibmkNRQrPI/AAAAAAAAAGY/uKPzTl7IZk0/s72-c/MalwareWarningScreenshot.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-5694060452586510203</id><published>2011-06-14T15:40:00.000-04:00</published><updated>2011-06-14T15:40:20.079-04:00</updated><title type='text'>Defence Intelligence</title><content type='html'>And we're back.&lt;br /&gt;&lt;br /&gt;Not that we really went anywhere, we've just neglected the blog for awhile as we concentrated on improving our flagship product, reworking our website and brand, hiring some new talent, and widening our malware dragnet to keep our clients safer.&amp;nbsp; Needless to say, we've been rather busy.&lt;br /&gt;&lt;br /&gt;The last year has been a whirlwind for all of us here at Defence Intelligence.&amp;nbsp; As with most IT startups, we were not without our share of growing pains.&amp;nbsp; We have spent most of the last year narrowing our focus and clearly defining our space and goals.&amp;nbsp; We've had some personnel changes, some product changes, and even split off part of our business.&amp;nbsp; Having said all of that, we're finally ready to put ourselves out there again, and we'll be updating this blog on a regular basis.&lt;br /&gt;&lt;br /&gt;You'll notice our new logo, our new website, and our new version of Nemesis over at &lt;a href="http://www.defintel.com/"&gt;www.defintel.com&lt;/a&gt;.&amp;nbsp; With all of the changes we've made, we wanted our brand to reflect our growth and advances while retaining ties to our roots.&amp;nbsp; I think the talented folks at Owly Design did a great job, and can't recommend them enough.&amp;nbsp; Feel free to let us know what you think of their work.&lt;br /&gt;&lt;br /&gt;The biggest news is Nemesis 2.0.&amp;nbsp; It's been a long time coming.&amp;nbsp; I can't tell you how happy I am to be able to announce the release of this product. This is what we've been working so hard on for what seems like an eternity.&amp;nbsp; This is the product that we always wanted to give our clients. Nemesis 2.0 is truly a revolutionary approach to malware protection, and it is quite simply the most effective anti-malware tool on the market. We've made lots of improvements, but some of the most obvious are as follows:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Improved compromise detection and  protection capabilities&lt;/li&gt;&lt;li&gt;A web based management console that provides real time awareness of malicious activity on the client network&lt;/li&gt;&lt;li&gt;Client defined rule creation to immediately block suspicious network communication&lt;/li&gt;&lt;li&gt;Event history search and custom filtering options to find details behind Nemesis protection events&lt;/li&gt;&lt;li&gt;Easy summary/situational reporting generation and download&lt;/li&gt;&lt;/ul&gt;You can learn more at: &lt;a href="http://defintel.com/solutions-nemesis.php"&gt;http://defintel.com/solutions-nemesis.php&lt;/a&gt; or &lt;a href="http://defintel.com/contact-us.php"&gt;contact us&lt;/a&gt; for a free trial.&lt;br /&gt;&lt;br /&gt;We'll be rolling out more improvements to Nemesis in the near future, keep an eye on our blog for details. As always, all additions and upgrades to our products are free of charge to our clients.&lt;br /&gt;&lt;br /&gt;I'd like to thank our clients, our partners and our friends for their support during all of this, it is much appreciated.&amp;nbsp; I'd also like to thank all of our team for their work on 2.0.&amp;nbsp; Eric and Matt in particular have gone above and beyond the call of duty, and I know that it hasn't been easy.&amp;nbsp; Now I get to start harassing them for 2.1. ;)&lt;br /&gt;&lt;br /&gt;If you haven't looked at Nemesis or Defence Intelligence before, now is the time.&amp;nbsp; Malware has evolved.&amp;nbsp; So have we.&lt;br /&gt;&lt;br /&gt;All the best,&lt;br /&gt;&lt;br /&gt;Keith Murphy&lt;br /&gt;CEO&lt;br /&gt;&lt;a href="http://www.defintel.com/"&gt;www.defintel.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-5694060452586510203?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://defintel.com' title='Defence Intelligence'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/5694060452586510203/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=5694060452586510203' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5694060452586510203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5694060452586510203'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2011/06/defence-intelligence.html' title='Defence Intelligence'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-3396958145139712786</id><published>2010-04-30T10:35:00.001-04:00</published><updated>2010-04-30T10:35:59.968-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Peer-to-peer'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Storm'/><category scheme='http://www.blogger.com/atom/ns#' term='FireEye'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><category scheme='http://www.blogger.com/atom/ns#' term='E-mail'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='IP address'/><title type='text'>Cloudy Skies</title><content type='html'>&lt;div class="zemanta-img" style="display: block; float: right; margin: 1em; width: 250px;"&gt;&lt;a href="http://www.flickr.com/photos/54304913@N00/209017661" rel="nofollow"&gt;&lt;img alt="Before the Storm" height="148" src="http://farm1.static.flickr.com/60/209017661_4ffa35612d_m.jpg" style="border: medium none; display: block;" width="240" /&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image by &lt;a href="http://www.flickr.com/photos/54304913@N00/209017661"&gt;premasagar&lt;/a&gt; via Flickr&lt;/span&gt;&lt;/div&gt;Storm talk is thundering across the security blog horizon. Despite the consensus that this spam monster is indeed a Storm relative, there is some argument over just how NEW this new Storm is.&lt;br /&gt;&lt;br /&gt;Several people have taken a look at the spam spewing samples, digging into the &lt;a href="https://www.honeynet.org/node/539"&gt;malware's functionality&lt;/a&gt; as well as its communication, and the &lt;a href="http://community.ca.com/blogs/securityadvisor/archive/2010/04/26/the-come-back-of-storm-worm.aspx"&gt;templates used&lt;/a&gt; for generating the various spam emails. They have found major similarities between several aspects of the new and old Storm fronts, including filename usage and user-agent typos (Windoss instead of Windows), but the more recent version has excluded the peer to peer portion of the code.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.fireeye.com/research/2010/04/storm-resurrection-is-it-true.html"&gt;Atif Mushtaq at FireEye writes&lt;/a&gt; that these are all details he observed on a Storm variant back in 2008. So is this old news? Nothing about what is being called Pecoan (another name in the long list: Nuwar, Peacomm, Zhelatin, Dorf) is really more sophisticated than its predecessor and the samples I ran only connected with one static IP, so I don't think this Storm will be as violent as the last. The creators of the original Storm have had enough time to code a better botnet so perhaps this is just a rediscovery of a forgotten remnant. &lt;br /&gt;&lt;br /&gt;Right now compromised systems are sending out online pharmacy, adult dating, and nude celebrity emails. The template design allows for a wide array of sender names, subjects, message content, and destination URLs. The malware harvests email addresses from the victim machines and sends Base64 encoded POSTS to pass information and report in to its C&amp;amp;C.&lt;br /&gt;&lt;br /&gt;As always, be cautious while online and when in doubt, don't click.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/b419296a-e934-4714-a744-af554902adee/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_b.png?x-id=b419296a-e934-4714-a744-af554902adee" style="border: medium none; float: right;" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script defer="defer" src="http://static.zemanta.com/readside/loader.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-3396958145139712786?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/3396958145139712786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=3396958145139712786' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3396958145139712786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3396958145139712786'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/04/cloudy-skies.html' title='Cloudy Skies'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm1.static.flickr.com/60/209017661_4ffa35612d_t.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-269455348697973885</id><published>2010-04-21T10:49:00.000-04:00</published><updated>2010-04-21T10:49:14.892-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='France'/><category scheme='http://www.blogger.com/atom/ns#' term='India'/><category scheme='http://www.blogger.com/atom/ns#' term='Federal Trade Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='Electronic Privacy Information Center'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Eric Schmidt'/><category scheme='http://www.blogger.com/atom/ns#' term='Electronic Communications Privacy Act'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Buzz'/><title type='text'>Private Discussion</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;User privacy is of major concern to just about everyone, because just about everyone needs some level of privacy. Google, with its massive user following and array of product offerings, has a huge responsibility to keep their users' data confidential and safe. The &lt;a href="http://defintel.blogspot.com/2010/02/buzz-words.html"&gt;Google Buzz bungle&lt;/a&gt; is an example of how Google's handling of private user information doesn't always live up to expectations.&lt;br /&gt;&lt;br /&gt;Privacy/Data/Information commissioners from 10 countries sent a joint &lt;a href="http://www.priv.gc.ca/media/nr-c/2010/let_100420_e.cfm"&gt;letter&lt;/a&gt; to Google CEO Eric Schmidt on April 20, expressing their concern that "the privacy rights of the world’s citizens are being forgotten as Google rolls out new technological applications."&lt;br /&gt;&lt;br /&gt;The letter made various statements like Google Buzz "betrayed a disappointing disregard for fundamental privacy norms and laws" and that "launching a product in “beta” form is not a substitute for ensuring that new services comply with fair information principles before they are introduced." Also included were suggested principles to be used by Google to ensure user privacy, such as "collecting and processing only the minimum amount of personal information necessary to achieve the identified purpose of the product or service" and "ensuring that all personal data is adequately protected."&lt;br /&gt;&lt;br /&gt;While the letter seems well intentioned, its message is a bit late to the stage. U.S. congressmen John Barrow penned his own joint letter to the Federal Trade Commission at the end of March over the same Buzz/privacy issues. Congressman Barrow's &lt;a href="http://barrow.house.gov/images/stories/Google_Buzz_Letter.pdf"&gt;letter&lt;/a&gt; cites the Electronic Privacy Information Center's (EPIC) previously filed complaint "alleging that Google Buzz violates federal privacy law."&amp;nbsp; In a manner of public response, Google issued a &lt;a href="http://www.scribd.com/doc/30196432/FTC-Roundtable-Comments-Final"&gt;letter&lt;/a&gt; to the Federal Trade Commission regarding their policies on information privacy. In this ten page letter, Google shared their efforts to "develop products that reflect strong privacy standards and practices." They also stated their support for "strong industry commitments to ensure transparency, user control, and security in Internet services for consumers" as well as "strengthened protections from government intrusion."&lt;br /&gt;&lt;br /&gt;To demonstrate a small history of various government "intrusion", Google created the government requests page (&lt;a href="http://www.google.com/governmentrequests/"&gt;http://www.google.com/governmentrequests/&lt;/a&gt;). The page maps out content removal requests and user data requests made by government agencies for the second half of 2009.&amp;nbsp; The leaders in user data requests are Brazil (3663), the U.S. (3580), the U.K. (1166) and India (1061).&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&amp;nbsp;&lt;a href="http://1.bp.blogspot.com/_nMx-DUJRrDc/S88GGHTLwkI/AAAAAAAAAFg/gUnwwr-bS-4/s1600/screen-capture.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" src="http://1.bp.blogspot.com/_nMx-DUJRrDc/S88GGHTLwkI/AAAAAAAAAFg/gUnwwr-bS-4/s320/screen-capture.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Also displayed through this map is the inclusion of&amp;nbsp; every country who signed the privacy letter to Google. Government agencies from France, Germany, Israel, Italy, Ireland, Netherlands, New Zealand, Spain, Canada and the United Kingdom all scolded Google for inadvertently disclosing&amp;nbsp; personal user information, but prodded them for the same information months earlier. &lt;br /&gt;&lt;br /&gt;Though data protection departments may not be the ones who made the requests, government is often looked at as a collective entity, causing some to consider these actions as hypocrisy. In the FAQ for the government requests page, Google says "the statistics primarily cover requests in criminal matters."&amp;nbsp; Does this justify cooperation from Google? When is it okay to abandon privacy for the sake of law enforcement? I don't know. It is a difficult balance for Google and world governments in protecting both privacy and national laws. &lt;br /&gt;&lt;br /&gt;The Electronic Communications Privacy Act (ECPA) is a key part of finding this balance. Find out more:&lt;br /&gt;&lt;a href="http://www.digitaldueprocess.org/"&gt;www.digitaldueprocess.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you want to see what Google has on you, start with:&lt;br /&gt;&lt;a href="http://www.google.com/dashboard"&gt;www.google.com/dashboard&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;br /&gt;&lt;div class="zemanta-pixie" style="height: 15px; margin-top: 10px;"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/c408a091-771c-4d41-8a15-174dae879ba8/" title="Reblog this post [with Zemanta]"&gt;&lt;img alt="Reblog this post [with Zemanta]" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_b.png?x-id=c408a091-771c-4d41-8a15-174dae879ba8" style="border: medium none; float: right;" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script defer="defer" src="http://static.zemanta.com/readside/loader.js" type="text/javascript"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-269455348697973885?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/269455348697973885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=269455348697973885' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/269455348697973885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/269455348697973885'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/04/private-discussion.html' title='Private Discussion'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nMx-DUJRrDc/S88GGHTLwkI/AAAAAAAAAFg/gUnwwr-bS-4/s72-c/screen-capture.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-5361742411422087875</id><published>2010-03-24T14:33:00.007-04:00</published><updated>2010-03-24T14:49:16.059-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Bullguard'/><category scheme='http://www.blogger.com/atom/ns#' term='Bitdefender'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft Windows'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='Operating system'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 64-bit'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Bitdefender Gets a Bit Too Defensive</title><content type='html'>&lt;p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 310px;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Image:BitDefender_logo.svg"&gt;&lt;img src="http://upload.wikimedia.org/wikipedia/en/thumb/b/bd/BitDefender_logo.svg/300px-BitDefender_logo.svg.png" alt="BitDefender" style="border: medium none ; display: block;" height="54" width="300" /&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image via &lt;a href="http://en.wikipedia.org/wiki/Image:BitDefender_logo.svg"&gt;Wikipedia&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;Bitdefender antivirus unwittingly released a signature update to its users on March 20th that detected and quarantined key Windows system files as malware, causing general &lt;a class="zem_slink freebase/en/operating_system" href="http://en.wikipedia.org/wiki/Operating_system" title="Operating system" rel="wikipedia"&gt;OS&lt;/a&gt; failures.&lt;br /&gt;&lt;br /&gt;Bitdefender had this statement on the news portion of their site:&lt;br /&gt;&lt;br /&gt;"&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Saturday around 8:20am PST, an update that we were working on was uploaded prematurely in our servers. This update affected only products running on Windows 64-bit systems.&lt;/span&gt;&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;The premature update caused various .exe and .dll files to be quarantined for both the Windows software and the Bitdefender software, each file detected as Trojan.FakeAlert.5.&lt;br /&gt;&lt;br /&gt;"&lt;span style="font-style: italic;font-size:85%;" &gt;Consequently, for some systems, &lt;a class="zem_slink freebase/en/bitdefender" href="http://www.bitdefender.com" title="BitDefender" rel="homepage"&gt;BitDefender&lt;/a&gt; did not run anymore, applications did not work or Windows could not start.&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;This caused quite an uproar among the AV's users as well as &lt;a class="zem_slink freebase/en/bullguard" href="http://www.bullguard.com/" title="BullGuard" rel="homepage"&gt;Bullguard&lt;/a&gt; antivirus users, whose software relies on Bitdefender's engine and signatures. Though both companies have offered assistance in remediating the situation, many customers are outraged, especially when the only compensation offered to users so far has been free usage of the very software that caused the problem. A blunder like this also does nothing for the image of AV whose &lt;a href="http://defintel.blogspot.com/2010/02/av-plays-catch-up.html"&gt;credibility&lt;/a&gt; and effectiveness has been in question for the last few years.&lt;br /&gt;&lt;br /&gt;Detection rates by some AV groups is often low and the gap between release of new malware and its detection by AV is currently too significant, allowing for the growth of large botnets like &lt;a href="http://www.google.com/hostednews/ap/article/ALeqM5hI0qlrmCn1ZX-8QXAMNklf3BCQNwD9E6MCO80"&gt;Mariposa&lt;/a&gt;. False alarms, especially when automatically quarantined, can disrupt or severely damage home user and business systems, as it has with this update mishap.&lt;br /&gt;&lt;br /&gt;I'm sure many of the Bitdefender/Bullguard users will be jumping ship, scouting alternative antivirus software, but how will they know which one to choose and which one to trust? A lot of AV company blogs end with something like, &lt;span style="font-style: italic;"&gt;make sure you are completely updated with the latest signatures or software versions to ensure your protection&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;Well, that's not working for Bitdefender. What are they going to say now?&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Bitdefender's help page:&lt;br /&gt;&lt;a href="http://www.bitdefender.com/site/KnowledgeBase/consumer/#638"&gt;http://www.bitdefender.com/site/KnowledgeBase/consumer/#638&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Bullguard's help page:&lt;br /&gt;&lt;a href="http://bullguard.com/support/system-status.aspx"&gt;http://bullguard.com/support/system-status.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;br /&gt; &lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/ee06a488-7851-4fb3-af9d-e417c3289501/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=ee06a488-7851-4fb3-af9d-e417c3289501" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-5361742411422087875?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/5361742411422087875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=5361742411422087875' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5361742411422087875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5361742411422087875'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/03/bitdefender-gets-bit-too-defensive.html' title='Bitdefender Gets a Bit Too Defensive'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1041043243618896756</id><published>2010-03-18T15:08:00.007-04:00</published><updated>2010-03-18T15:30:39.839-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Search'/><category scheme='http://www.blogger.com/atom/ns#' term='March Madness'/><category scheme='http://www.blogger.com/atom/ns#' term='Search engine optimization'/><category scheme='http://www.blogger.com/atom/ns#' term='Sandra Bullock'/><category scheme='http://www.blogger.com/atom/ns#' term='Tiger Woods'/><category scheme='http://www.blogger.com/atom/ns#' term='facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='Lost Boys'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Trends'/><category scheme='http://www.blogger.com/atom/ns#' term='Web search engine'/><category scheme='http://www.blogger.com/atom/ns#' term='Uniform Resource Locator'/><category scheme='http://www.blogger.com/atom/ns#' term='Corey Haim'/><title type='text'>Malware Spread Optimization</title><content type='html'>&lt;p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 250px;"&gt;&lt;a href="http://www.flickr.com/photos/18548283@N00/1704538333"&gt;&lt;img src="http://farm3.static.flickr.com/2053/1704538333_075cd54463_m.jpg" alt="Mt. San Miguel is on fire.  San Diego County w..." style="border: medium none ; display: block;" height="160" width="240" /&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image by &lt;a href="http://www.flickr.com/photos/18548283@N00/1704538333"&gt;slworking2&lt;/a&gt; via Flickr&lt;/span&gt;&lt;/p&gt;When I heard of &lt;a class="zem_slink freebase/en/corey_haim" href="http://www.imdb.com/name/nm0000433/" title="Corey Haim" rel="imdb"&gt;Corey Haim&lt;/a&gt;'s death, shortly after fond recollections of &lt;a class="zem_slink freebase/en/license_to_drive" href="http://www.imdb.com/title/tt0095519/" title="License to Drive" rel="imdb"&gt;License to Drive&lt;/a&gt; and &lt;a class="zem_slink freebase/en/the_lost_boys" href="http://www.imdb.com/title/tt0093437/" title="The Lost Boys" rel="imdb"&gt;The Lost Boys&lt;/a&gt; cinema moments, I wondered how soon the unfortunate news would be used in the spread of malware. Well it didn't take long. Hours after the announcement of Haim's death, search results for his name came up with domains used to spread rogue antivirus software.&lt;br /&gt;&lt;br /&gt;Using search engine optimization (SEO), online criminals force their malware hosting sites into higher billing slots within search engine results. Often a series of redirection sites are traveled through by the user before the final malicious domain is contacted. This creates a level of separation from the actual malware and allows a variety of domains to be constantly created, altered, and moved around, evading detection and termination. Using timely and highly popular topics of interest. domains referring to these topics stay in the leading search engine results. Recent topics covered in SEO campaigns include the Haiti disaster, the Olympics, the Oscars, and &lt;a href="http://defintel.blogspot.com/2010_01_01_archive.html"&gt;unnamed Facebook applications&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So why do these attacks work so well? Amazingly there is still a level of trust by users for top resulting sites of search engine queries. It is common for people to see familiar sites time and again on the first page of search results, and popular sites deemed primarily benign usually take dominant billing. Perhaps this is why folks rarely question clicking on the initial links provided by their favorite search engines. They hadn't been burned in the past when trusting the top resulting URLs, so why should they now question the validity and intention of every suggested link? Malware is why.&lt;br /&gt;&lt;br /&gt;I don't always keep up with the latest events, but with a little social interaction and casual reading I hear about most events I find interesting and usually several others I don't, all within a reasonable amount of time. When I want to receive my news from a specific source I usually go to one location online or watch Robin Meade on HLN in the mornings. (There's no such thing as bad news when Robin reads it.) I use search engines like everyone else to gather information on various inquiries but I don't do grab bag research, blindly clicking on any keyword matching domains. I've never used the "I'm feeling Lucky" button because I never felt that lucky about randomly visiting unknown domains across the internet, and I certainly don't want to be a punk. (nod to Dirty Harry in case that was missed)&lt;br /&gt;&lt;br /&gt;Choosing a default news site to read about all things newsworthy would seem to be an obvious point to suggest here, just as a safety precaution. However, the simple facts behind these breaking stories are not commonly what people are after.  There is usually a promise of a sex tape or footage of a celebrity's death, which can't be found on CNN. What they can't find on news sites is what sends users searching, which is ironic because most people only go searching for this bonus material after reading about its availability outside of regular news sites. Maybe news site restriction or loyalty would keep more users safe from attack. But then there's always Facebook and Twitter and forums/comment/email spam to shield your eyes from as well.&lt;br /&gt;&lt;br /&gt;When I want to know what people are searching for I go to Google Trends: &lt;a href="http://www.google.com/trends"&gt;http://www.google.com/trends&lt;/a&gt;. I assume this is what criminals intent on spreading their malware also do. Topics that are "On Fire" and "Volcanic" are being queried the most and make for prime targets. If you want to try a little safer searching, wait for topics to cool down a little before clicking around. Even better, find a news site you trust and go there for your news. Anything outside of seeking the facts may just land you in some fire of your own.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/08029eed-9136-4f72-9fac-bffc093b4f2a/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=08029eed-9136-4f72-9fac-bffc093b4f2a" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1041043243618896756?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1041043243618896756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1041043243618896756' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1041043243618896756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1041043243618896756'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/03/malware-spread-optimization.html' title='Malware Spread Optimization'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm3.static.flickr.com/2053/1704538333_075cd54463_t.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-5036169968046670758</id><published>2010-03-10T16:23:00.011-05:00</published><updated>2010-03-11T09:30:36.973-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Command and control'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Crime'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet service provider'/><category scheme='http://www.blogger.com/atom/ns#' term='Email'/><category scheme='http://www.blogger.com/atom/ns#' term='Brian Krebs'/><category scheme='http://www.blogger.com/atom/ns#' term='Zeus'/><category scheme='http://www.blogger.com/atom/ns#' term='Botnet'/><title type='text'>Lightning Crashes</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nMx-DUJRrDc/S5gPctjU3VI/AAAAAAAAAE4/Vdc6jg6gqq0/s1600-h/Picture+5.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 126px;" src="http://1.bp.blogspot.com/_nMx-DUJRrDc/S5gPctjU3VI/AAAAAAAAAE4/Vdc6jg6gqq0/s400/Picture+5.png" alt="" id="BLOGGER_PHOTO_ID_5447120735243132242" target="blank" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;statistical chart from zeustracker.abuse.ch&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;Zeus is undoubtedly one of the most prevalent malware being used for web based criminal activity. It has compromised thousands of systems and, though an exact count is unknown, an example like the Kneber/Zeus botnet &lt;a href="http://www.netwitness.com/resources/pressreleases/feb182010.aspx" target="blank"&gt;reported by Netwitness&lt;/a&gt; showed that one collection of infected computers consisted of "75,000 systems in 2,500 organizations around the world." There have certainly been &lt;a href="http://defintel.blogspot.com/2010/03/mariposa-dead.html" com="" 2010="" 03="" html="" target="blank"&gt;larger botnets&lt;/a&gt; concentrated on data theft, but with fluxing configurations, binaries and the domains used for hosting, the array of zeus botnets have remained both widespread and dangerous. Then, on March 9th 2010, Zeus took a big hit to its infrastructure.&lt;br /&gt;&lt;br /&gt;Abuse.ch, who runs the &lt;a href="https://zeustracker.abuse.ch/monitor.php"&gt;ZeusTracker&lt;/a&gt; project, &lt;a href="http://www.abuse.ch/?p=2417"&gt;reported a significant drop&lt;/a&gt; in the active number of Zeus command and control servers, falling from 249 to 181 overnight. What they discovered was that the ISP Troyak (&lt;a href="http://www.robtex.com/as/as50215.html" target="blank"&gt;AS50215&lt;/a&gt;), and its dependent networks, had essentially been taken offline. These networks had been considered bulletproof hosting for Zeus domains, which means the hosting groups involved were believed to actively protect the malicious activity, ignore requests for ending it, or otherwise assumed by its users to be a safe zone for malicious domains.&lt;br /&gt;&lt;br /&gt;While disconnecting thousands of compromised systems from their C&amp;amp;C domains is a great win, though likely a temporary one, no one knows who to congratulate. Security researchers assume it was an external takedown, but no one has stepped forward to be recognized. What is even more interesting, as mentioned by Brian Krebs, is that, 11 days prior to the Troyak switch-off, spam promoting Zeus also went into decline. On February 27th, as stated in &lt;a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline/"&gt;Kreb's blog&lt;/a&gt;, a large Zeus spamming gang stopped sending new spam.&lt;br /&gt;&lt;br /&gt;For now we'll just have to wonder who is behind this mysterious crusade against Zeus. It seems unlikely that it was the work of any security group or company as it is generally in our favor to promote such efforts. Perhaps a rival gang was involved and the "Zeus killer" feature in SpyEye wasn't enough for them, or maybe somebody just thought to quit while they were ahead. That would be a novel idea.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;br /&gt;Update:&lt;br /&gt;Moments after posting this, Troyak found a new upstream provider and got back online. They have since moved to yet another provider, trying to evade a second disruption of "services." Some would say they're on the run.&lt;br /&gt;&lt;br /&gt;&lt;fieldset class="zemanta-related"&gt;&lt;legend class="zemanta-related-title"&gt;Related articles by Zemanta&lt;/legend&gt;&lt;ul class="zemanta-article-ul"&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://www.computerworld.com/s/article/9159138/Kneber_just_another_botnet_?source=rss_news"&gt;Kneber just another botnet?&lt;/a&gt; (computerworld.com)&lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://go.theregister.com/feed/www.theregister.co.uk/2010/02/09/spyeye_bots_vs_zeus/"&gt;Upstart crimeware wages turf war on mighty Zeus bot&lt;/a&gt; (go.theregister.com)&lt;/li&gt;&lt;/ul&gt;&lt;/fieldset&gt;  &lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/b39ab86f-01e0-4213-b0c3-6b7e8171c51c/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=b39ab86f-01e0-4213-b0c3-6b7e8171c51c" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-5036169968046670758?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/5036169968046670758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=5036169968046670758' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5036169968046670758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5036169968046670758'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/03/lightning-crashes.html' title='Lightning Crashes'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_nMx-DUJRrDc/S5gPctjU3VI/AAAAAAAAAE4/Vdc6jg6gqq0/s72-c/Picture+5.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1318381292322178184</id><published>2010-03-03T10:34:00.008-05:00</published><updated>2010-03-03T11:05:13.101-05:00</updated><title type='text'>Mariposa Dead.</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.defintel.com/images/mariposa_obit.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 260px; height: 560px;" src="http://www.defintel.com/images/mariposa_obit.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For more information:&lt;br /&gt;&lt;a href="http://defintel.com/mariposa.shtml"&gt;http://defintel.com/mariposa.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more on the press coverage:&lt;br /&gt;&lt;a href="http://defintel.com/media.shtml"&gt;http://defintel.com/media.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.defintel.com/images/mariposa_obit.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="file:///Users/jjohnston/Desktop/Mariposa%20Obit/mariposa_obit.jpg" alt="" /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/c27c631e-cf25-48e0-b725-e0db5c1a4a0a/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=c27c631e-cf25-48e0-b725-e0db5c1a4a0a" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1318381292322178184?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1318381292322178184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1318381292322178184' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1318381292322178184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1318381292322178184'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/03/mariposa-dead.html' title='Mariposa Dead.'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-6504387157906982131</id><published>2010-02-24T18:36:00.008-05:00</published><updated>2010-02-24T18:58:38.171-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows Vista'/><category scheme='http://www.blogger.com/atom/ns#' term='Taskbar'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet Explorer'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><category scheme='http://www.blogger.com/atom/ns#' term='European Commission'/><category scheme='http://www.blogger.com/atom/ns#' term='European Commission and Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Browser Bingo</title><content type='html'>&lt;p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 250px;"&gt;&lt;a href="http://www.flickr.com/photos/10251343@N05/2394495152"&gt;&lt;img src="http://farm3.static.flickr.com/2164/2394495152_1189fc20b8_m.jpg" alt="bingo" style="border: medium none ; display: block;" height="130" width="190"&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image by &lt;a href="http://www.flickr.com/photos/10251343@N05/2394495152"&gt;hownowdesign&lt;/a&gt; via Flickr&lt;/span&gt;&lt;/p&gt;Way back in 2007 the &lt;a class="zem_slink freebase/en/european_commission" href="http://en.wikipedia.org/wiki/European_Commission" title="European Commission" rel="wikipedia"&gt;European Commission&lt;/a&gt; and Microsoft began a legal dispute over competition concerns regarding Microsoft's domination in the European user space. In December of 2009 the dialogue between the EC and Microsoft ended, culminating in a resolution that would aid in easy interoperability with various software and force Microsoft to force browser choice on its current European users.&lt;br /&gt;&lt;br /&gt;A large part of the agreements by Microsoft deals with browser choice for OEMs and end users on Windows 7, XP, and Vista operating systems. Starting the week of March 1st, users in 30 European nations with IE as their default browser may start seeing an introductory screen pop up on their machines. This introductory screen, only seen after installing the relevant Microsoft update and restarting their systems, will explain the purpose behind the subsequent choice screen.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nMx-DUJRrDc/S4W4UwV4FFI/AAAAAAAAAEY/TSAtioKDWPY/s1600-h/clip_image002_136F9F12.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 245px;" src="http://3.bp.blogspot.com/_nMx-DUJRrDc/S4W4UwV4FFI/AAAAAAAAAEY/TSAtioKDWPY/s320/clip_image002_136F9F12.jpg" alt="" id="BLOGGER_PHOTO_ID_5441958391460664402" border="0"&gt;&lt;/a&gt;&lt;br /&gt;The choice screen will display 12 of the most used browsers in random order, with the top 5 highest ranked browsers displayed randomly in the first positions. The idea behind the settlement is to prevent monopoly holdings for any one vendor and create a fair presentation of consumer options, but this top 5 configuration will obviously give the bigger guns a better aim at end user installment. Internet Explorer, as a major holder of the browsing community, will then always be listed in the first few slots.&lt;br /&gt;&lt;br /&gt;So, what will user reaction be to all this? I'm guessing more confusion than anything else. Part of the update being sent out will allow IE to be turned off, it will "unpin" the IE icon from the taskbar and, where IE is turned off, "no icons, links or shortcuts or any other means will appear within Windows to start a download or installation of Internet Explorer." &lt;span style="font-size: 85%;"&gt;(microsoft commitments document)&lt;/span&gt; Then users will be given a choice to select their browser.&lt;br /&gt;&lt;br /&gt;I know that some people need to be presented their options in a supermarket fashion, like side by side sodas in the snacks aisle, where Coke is next to Pepsi and the generic version, but I don't think this is an ultimate solution to the problem. For the less clueful users who "just want to get on the internet", this may just create problems. Those same users, who are now presented with a browser lineup, may not understand or try to understand what their options actually are. In all likelihood they will recognize Internet Explorer from the list given them and click on install without reading the additional information.&lt;br /&gt;&lt;br /&gt;For the users who already understand the choice of browser usage, they have already made their choice. They don't need any more education and, likely not having IE as their default browser, won't see the new choice screen. Efforts like this to change bias will likely be ineffective in producing real change or raising awareness to the right people. The bias of users comes from long term ignorance, disinterest, marketing inundation, and comfort level on the internet. None of this will be reversed by what many users will just view as more pop ups.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;br /&gt;sources:&lt;br /&gt;&lt;a href="http://microsoftontheissues.com/cs/blogs/mscorp/archive/2010/02/19/the-browser-choice-screen-for-europe-what-to-expect-when-to-expect-it.aspx" target="blank"&gt;Microsoft On the Issues&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/Presspass/press/2009/dec09/12-16Statement.mspx" target="blank"&gt;Microsoft.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/95d9a4f9-638e-45f4-898d-3487afc5b115/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=95d9a4f9-638e-45f4-898d-3487afc5b115" alt="Reblog this post [with Zemanta]"&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-6504387157906982131?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/6504387157906982131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=6504387157906982131' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6504387157906982131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6504387157906982131'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/02/browser-bingo.html' title='Browser Bingo'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm3.static.flickr.com/2164/2394495152_1189fc20b8_t.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1964547075466947486</id><published>2010-02-18T13:03:00.005-05:00</published><updated>2010-02-18T13:14:43.944-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cross-site scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Profile'/><category scheme='http://www.blogger.com/atom/ns#' term='Social network service'/><category scheme='http://www.blogger.com/atom/ns#' term='Google Buzz'/><category scheme='http://www.blogger.com/atom/ns#' term='Picasa'/><title type='text'>Buzz Words</title><content type='html'>&lt;p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 250px;"&gt;&lt;a href="http://www.flickr.com/photos/28567825@N03/2872466777"&gt;&lt;img src="http://farm4.static.flickr.com/3239/2872466777_75aefa8f84_m.jpg" alt="Neil Armstrong &amp;amp; Buzz Aldrin" style="border: medium none ; display: block;" height="160" width="240" /&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image by &lt;a href="http://www.flickr.com/photos/28567825@N03/2872466777"&gt;cliff1066™&lt;/a&gt; via Flickr&lt;/span&gt;&lt;/p&gt;Google Buzz is definitely the buzz word of the week and, in this industry, has been quickly put under the microscope. As a result, a &lt;a class="zem_slink freebase/en/cross-site_scripting" href="http://en.wikipedia.org/wiki/Cross-site_scripting" title="Cross-site scripting" rel="wikipedia"&gt;cross-site scripting&lt;/a&gt; vulnerability was already &lt;a href="http://ha.ckers.org/blog/20100216/google-buzz-security-flaw/"&gt;discovered&lt;/a&gt; and &lt;a href="http://news.cnet.com/8301-30684_3-10454982-265.html"&gt;fixed&lt;/a&gt; in the mobile version of the buzz utility. I'm sure close examination will continue to reveal additional security or operational flaws in Buzz, but security minded folks were not the only active critics of the social networking tool from Google.&lt;br /&gt;&lt;br /&gt;Initial users were upset by Buzz's default "all inclusive" settings. These automatic features included adding yourself as a follower of those you most contact through email or chat, (allowing them to automatically follow you as well), displaying all users involved in the follow-fest on your Google Profile, and instant sharing of activity on your other Google sites like &lt;a class="zem_slink freebase/en/picasa" href="http://picasa.google.com/" title="Picasa" rel="homepage"&gt;Picasa&lt;/a&gt; and Reader. Providing easy display of a lot of information to potentially a lot of people, all of these features raised a lot of concern over privacy issues. In addition, new Buzzers were disappointed with the difficulty in finding settings options regarding these features, most while trying desperately to disable them.&lt;br /&gt;&lt;br /&gt;While some may not be all that concerned, instant exposure of this information to user contacts without giving expressed permission has been more than disappointing. Some social circles are meant to be separated. Facebook users have been forced to explore this friends and family cross communication fiasco due to multi-generational interest in the social networking world. For many users this is uncomfortable at best.&lt;br /&gt;&lt;br /&gt;Complete testing before release may have prevented the scramble for &lt;a href="http://gmailblog.blogspot.com/2010/02/millions-of-buzz-users-and-improvements.html"&gt;alterations&lt;/a&gt; that Google is now the middle of, but the feasible protection of online privacy is the real issue here. In our efforts to connect with the world, can we expect to keep secrets or achieve selective and exclusive information sharing? When we type something into our network connected devices, can we blame anyone but ourselves when that information spreads beyond the originally intended parties?&lt;br /&gt;&lt;br /&gt;Anonymity while on the internet is becoming progressively harder to maintain. With photo tagging and friends who gossip across Facebook, even people who never participate in social networking sites have an online profile, in a sense. While reluctant or non users are losing control over just how much the online world can find out about them, self surveillance is now commonplace. We've become comfortable with sharing information about ourselves and living and working online, making us vulnerable to attack over the internet and in the physical world. If the Buzzing is getting a little too close you could be in danger of getting stung.&lt;br /&gt;&lt;br /&gt;For those interested in de-Buzzing, the links below can guide you through the process:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.cnet.com/8301-17939_109-10451703-2.html"&gt;http://news.cnet.com/8301-17939_109-10451703-2.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://securitylabs.websense.com/content/Blogs/3553.aspx"&gt;http://securitylabs.websense.com/content/Blogs/3553.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For those sticking with it:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://gmailblog.blogspot.com/2010/02/new-buzz-start-up-experience-based-on.html"&gt;http://gmailblog.blogspot.com/2010/02/new-buzz-start-up-experience-based-on.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://gmailblog.blogspot.com/2010/02/5-buzz-tips.html"&gt;http://gmailblog.blogspot.com/2010/02/5-buzz-tips.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/43e47364-9158-4498-9e06-3c36997b6caa/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=43e47364-9158-4498-9e06-3c36997b6caa" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1964547075466947486?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1964547075466947486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1964547075466947486' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1964547075466947486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1964547075466947486'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/02/buzz-words.html' title='Buzz Words'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm4.static.flickr.com/3239/2872466777_75aefa8f84_t.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-8025010243820892231</id><published>2010-02-10T18:59:00.006-05:00</published><updated>2010-02-11T10:09:07.699-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='HTML element'/><category scheme='http://www.blogger.com/atom/ns#' term='Domain name'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Gumblar'/><category scheme='http://www.blogger.com/atom/ns#' term='File Transfer Protocol'/><category scheme='http://www.blogger.com/atom/ns#' term='Website'/><category scheme='http://www.blogger.com/atom/ns#' term='For Sale or Auction'/><title type='text'>RUmblar</title><content type='html'>&lt;p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 250px;"&gt;&lt;a href="http://www.flickr.com/photos/48355243@N00/256215927"&gt;&lt;img src="http://farm1.static.flickr.com/118/256215927_8eb490187b_m.jpg" alt="Pepsi" style="border: medium none ; display: block;" height="180" width="240" /&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image by &lt;a href="http://www.flickr.com/photos/48355243@N00/256215927"&gt;elmada&lt;/a&gt; via Flickr&lt;/span&gt;&lt;/p&gt;Gumblar, the massive iframe injection attack that made and sustained front page security news in early 2009, appears to still be going strong. Only slightly altered in its approach, the ongoing attack is still injecting malicious domains into sites on a fairly large scale, each site having the intention of spreading malware to the end user.&lt;br /&gt;&lt;br /&gt;Gumblar domains were previously injected into iframes of otherwise benign sites using stolen FTP credentials. The new domains are likely still injected using stolen credentials but are now using obfuscated scripts to generate a formulaic Russian domain. The obfuscated scripts are appended to javascript files and html files within script tags and create rather lengthy domain names.&lt;br /&gt;&lt;br /&gt;The second level domains for these are plentiful. Amazingly, the following list is incomplete and will likely remain so with the constant generation of new redirection domains:&lt;br /&gt;&lt;br /&gt;&lt;style&gt; &lt;!--    BODY,DIV,TABLE,THEAD,TBODY,TFOOT,TR,TH,TD,P { font-family:"Arial"; font-size:x-small }    --&gt;  &lt;/style&gt;    &lt;table border="0" cellspacing="0" cols="4" frame="VOID" rules="NONE"&gt;  &lt;colgroup&gt;&lt;col width="176"&gt;&lt;col width="176"&gt;&lt;col width="176"&gt;&lt;col width="176"&gt;&lt;/colgroup&gt;  &lt;tbody&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18" width="176"&gt;&lt;span style="font-family:Times New Roman;"&gt;18-plus.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT" width="176"&gt;&lt;span style="font-family:Times New Roman;"&gt;bluejackmusic.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT" width="176"&gt;&lt;span style="font-family:Times New Roman;"&gt;mozg-testing.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT" width="176"&gt;&lt;span style="font-family:Times New Roman;"&gt;thegiftsale.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;airseasite.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;blueseaguide.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;mozgilla.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;thelaceweb.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;allnewface.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;brownbagbar.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;musicboxpro.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;thelifetag.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;allpropro.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;brynetka.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;mygreatsale.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;themobisite.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;ampsguide.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;carswebnet.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;newhavenparks.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;thetruehelp.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;authentictype.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;cobalttrueblue.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;newlifeworld.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;toplinemarine.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;avattop.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;cometruestar.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;pastanotherlife.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;truelifefamily.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;b-i-o-v.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;counterbest.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;recentmexico.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;urlnext.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;battop.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;cyberprotech.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;red-wolf.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;videosaleonline.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;beeeo.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;easylifedirect.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;saletradeonline.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;viewhomesale.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;before-this-life.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;easytabletennis.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;seasilvercoop.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;votrelib.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;beofree.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;ezpoh.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;shoozi.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;warbest.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bestage.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;funwebmail.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;simplehomelink.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;webdesktopnet.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bestbio.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;gametopsite.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;simpleworldhouse.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;weblessnet.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bestbondsite.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;genuinecolors.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;sitesages.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;webnetenglish.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bestseasilver.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;genuinehollywood.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;sugaryhome.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;webpowerguide.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bi-test.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;genuinehollywood.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;superhighest.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;webworldshop.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;biltop.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;greatsalecenter.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;superore.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;whosaleonline.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bio-age.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;guidebat.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;superseatoddy.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;wintersaleonline.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bio-free.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;halfsite.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;superseawind.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;worldhighspeed.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bio-oib.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;homesaleplus.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;supertruelife.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;worldsouth.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bio-tube.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;homesitedesigns.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;supertruelife.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;worldwebworld.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bio-z.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;huntalong.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;susance.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;xboxliveweb.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bionaft.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;huzzahwebdesign.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;teenwebdesign.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;yourasite.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;biovoz.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;inother.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;theanotherlife.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;yourauthentic.ru &lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;biozavr.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;lagworld.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;theantimatrix.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;yourhotelsite.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;biozov.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;maxserviceworld.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;theatticsale.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;yourtagheuer.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bitest.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;mindgameworks.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;theaworld.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;yourtruegame.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;bluejackin.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;mingleas.ru&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;thechocolateweb.ru &lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;yourtruemate.ru&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;  &lt;/tbody&gt; &lt;/table&gt;&lt;br /&gt;Though the groupings here are obviously all .ru domains, other researchers indicate countless other domains being used in the same way. Many are using &lt;a href="http://www.abuse.ch/?p=1801"&gt;dynamic dns 2lds&lt;/a&gt; while others have a similar structure to the domains above, only with .cn TLDs, as was the original gumblar.cn. Others appear to have no theme and are using .cz, .dk, .de, .nl, and several other country code TLDs. The IPs behind these domains are just as widespread and varied. This list is also likely incomplete:&lt;br /&gt;&lt;br /&gt;&lt;style&gt; &lt;!--    BODY,DIV,TABLE,THEAD,TBODY,TFOOT,TR,TH,TD,P { font-family:"Arial"; font-size:x-small }    --&gt;  &lt;/style&gt;    &lt;table border="0" cellspacing="0" cols="4" frame="VOID" rules="NONE"&gt;  &lt;colgroup&gt;&lt;col width="113"&gt;&lt;col width="113"&gt;&lt;col width="113"&gt;&lt;col width="113"&gt;&lt;/colgroup&gt;  &lt;tbody&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18" width="113"&gt;&lt;span style="font-family:Times New Roman;"&gt;188.138.24.133&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT" width="113"&gt;&lt;span style="font-family:Times New Roman;"&gt;77.68.44.169&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT" width="113"&gt;&lt;span style="font-family:Times New Roman;"&gt;89.110.147.181&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT" width="113"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.86.130&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;188.40.118.68&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;78.31.107.49&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;89.149.202.142&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.88.218&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;188.72.199.24&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;78.41.156.236&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;89.149.244.211&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.96.181&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;188.72.211.253&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;80.69.74.73&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.1.99&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;92.48.124.212&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;195.242.98.212&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;82.165.194.22&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.108.53&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;92.48.78.252&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;212.117.165.149&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;82.165.47.29&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.112.227&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.228.219.11&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;213.186.57.19&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;82.192.88.35&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.121.6&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.11.38&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;213.251.164.84&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;82.98.231.25&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.142.111&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.14.110&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;213.251.184.114&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;84.16.227.72&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.166.221&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.199.154&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;217.160.110.21&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;84.201.9.32&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.167.41&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.206.229&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;217.23.5.27&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;85.14.202.210&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.211.226&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.211.214&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;62.212.74.148&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;85.184.10.80&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.24.139&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.4.164&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;62.250.9.105&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;85.25.152.241&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.4.99&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;94.23.89.95&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;62.4.85.229&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;85.25.73.243&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.49.129&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;95.168.170.89&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;62.75.184.40&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;87.106.247.193&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.7.26&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;95.211.10.130&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;62.75.218.192&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;87.118.90.76&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.74.84&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;95.211.4.193&lt;/span&gt;&lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td align="LEFT" height="18"&gt;&lt;span style="font-family:Times New Roman;"&gt;77.37.19.43&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;89.105.199.130&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;span style="font-family:Times New Roman;"&gt;91.121.79.191&lt;/span&gt;&lt;/td&gt;    &lt;td align="LEFT"&gt;&lt;br /&gt;&lt;/td&gt;   &lt;/tr&gt;  &lt;/tbody&gt; &lt;/table&gt;&lt;br /&gt;The full unobfuscated domains look something like this, containing popular domain name snippets in an effort to appear legitimate:&lt;br /&gt;&lt;br /&gt;foxsports-com.google.cn.spiegel-de.avattop.ru&lt;br /&gt;yomiuri-co-jp.google.cz.playstation-com.yourtagheuer.ru&lt;br /&gt;theplanet-com.1133.cc.nikkansports-com.bestnewhaven.ru&lt;br /&gt;&lt;br /&gt;The full URLs will include file requests similar to:&lt;br /&gt;:8080/ts/in.cgi?pepsi[variable numbers]&lt;br /&gt;:8080/cache/readme.pdf&lt;br /&gt;:8080/cache/flash.swf&lt;br /&gt;:8080/filez/java.html&lt;br /&gt;:8080/filez/Show.class&lt;br /&gt;:8080/filez/win.jpg&lt;br /&gt;&lt;br /&gt;The files are designed to exploit vulnerabilities in Acrobat, Flash, and Office, and redirect to the final domain for download of the actual malware, which consistently appears to be Bredolab.&lt;br /&gt;&lt;br /&gt;The Bredolab downloader has been tied to Gumblar from the beginning and is still being served by the malicious domains, ultimately serving up rogue AV and information theft end-goal malware. The information theft malware is to grab the FTP credentials to perpetuate the whole cycle. Bredolab has also been found in mass spam campaigns since late last year, attached to emails purporting to represent DHL, UPS, Facebook, Western Union, ISPs fake ecard senders and "potential girlfriends."&lt;br /&gt;&lt;br /&gt;You may have come across one like:&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Subject: Facebook Password Reset Confirmation.&lt;br /&gt;&lt;br /&gt;Because of the measures taken to provide safety to our clients, your password has been changed.&lt;br /&gt;You can find your new password in attached document.&lt;br /&gt;&lt;br /&gt;Thanks,&lt;br /&gt;The Facebook Team&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;If many benign sites are hosting the final malware download due to the highjacking mechanism, blocking the redirection attempts would to be the best course of action. It is necessary for the owners of the highjacked sites to clean up the injected redirection domains or malicious files, and the end user to keep their software updated in an effort to negate exploits.&lt;br /&gt;&lt;br /&gt;The Pepsi Challenge&lt;br /&gt;Many of the files requested on the redirect domains have something similar to&lt;br /&gt;":8080/ts/in.cgi?pepsi18":&lt;br /&gt;&lt;br /&gt;18-plus.ru:8080/ts/in.cgi?pepsi18&lt;br /&gt;inother.ru:8080/ts/in.cgi?pepsi18&lt;br /&gt;test-health.ru:8080/ts/in.cgi?pepsi18&lt;br /&gt;&lt;br /&gt;I just find this amusing, because one of the Gumblar sites reported &lt;a href="http://blog.unmaskparasites.com/2009/12/18/list-of-gumblar-zombie-urls/"&gt;here&lt;/a&gt; hosted "/rimages/coke.php". It's nice that we have a choice of malicious beverage and, while I prefer Coke, it seems Pepsi is the choice of the new "Rumblar" generation of domains.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp;amp; Analysis&lt;br /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/3f9333b5-6ec8-40d8-bbb2-2018e568b7e3/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=3f9333b5-6ec8-40d8-bbb2-2018e568b7e3" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-8025010243820892231?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/8025010243820892231/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=8025010243820892231' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8025010243820892231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8025010243820892231'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/02/rumblar.html' title='RUmblar'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm1.static.flickr.com/118/256215927_8eb490187b_t.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-2717244273899503281</id><published>2010-02-03T17:40:00.007-05:00</published><updated>2010-02-04T10:04:06.591-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Tabanus sudeticus'/><category scheme='http://www.blogger.com/atom/ns#' term='Company'/><category scheme='http://www.blogger.com/atom/ns#' term='Business'/><category scheme='http://www.blogger.com/atom/ns#' term='Kaspersky Lab'/><category scheme='http://www.blogger.com/atom/ns#' term='VirusTotal'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Consultants'/><title type='text'>AV Plays Catch Up</title><content type='html'>No security or AV company is equipped with a procedure, independent of hardware or personnel requirements, that can easily keep up with the daily barrage of newborn threats. Shadowserver shows they receive daily unique binaries numbering in the tens of thousands. With the mass amount of malware being created and distributed across the internet, each security company is left with the burden of being unable to "catch 'em all."&lt;br /&gt;&lt;br /&gt;They must then employ a prioritization method of analysis, often leaving data too long in the queue, some collecting dust. Some security companies concentrate on searching for malicious domains and IPs while others concentrate on binary identification, many using a hybrid approach. All, however, are in search of a way to efficiently label these variables as malicious or benign, trying desperately to keep pace with the release of new malware.&lt;br /&gt;&lt;br /&gt;AV companies have of course felt the strain of keeping up with the Joneses and for fear of looking inferior have made the choice to often "borrow" the conclusions made by other AV groups.&lt;br /&gt;&lt;br /&gt;According to this "&lt;a href="http://www.viruslist.com/en/weblog?weblogid=208188011" target="blank"&gt;Analyst's Diary&lt;/a&gt;" entry at Kaspersky Lab, an experiment was used to show just how often AV groups rely on one another to categorize samples as malicious in order to appear up to date. From the blog:&lt;br /&gt;&lt;br /&gt;"We created 20 clean files and added a fake detection for 10 of them. Over the next few days we re-uploaded all twenty files to &lt;a class="zem_slink freebase/en/tabanus_sudeticus" href="http://www.virustotal.com" title="VirusTotal" rel="homepage" target="blank"&gt;VirusTotal&lt;/a&gt; to see what would happen. After ten days, all of our detected (but not actually malicious) files were detected by up to 14 other AV companies..."&lt;br /&gt;&lt;br /&gt;I can't exactly blame those copycat AV companies for trying to stay on par with others. There is constant pressure, of which all security groups are aware, to try and balance reputation, integrity, and effectiveness. Trying to avoid false positives means evil may slip by unnoticed, while avoiding false negatives means sacrifices in accuracy. A series of check systems could be put in place but often there is insufficient detail or time for quality assurance, and delays in the conviction process detracts from the goal of real-time protection.&lt;br /&gt;&lt;br /&gt;Security researchers often collaborate in some way, perhaps only in certain circles, but we do so because each performs their own independent analysis in their own area of expertise, bringing unique input to the table. Our products should behave no differently. Only shared information that meets certain quality requirements should be used, according to the individual company's ruleset. If a company or security product has nothing to contribute and only relies on the work of others then it has little purpose in this industry, (yet may find success with the right marketing). However, a company will struggle greatly if they dismiss or completely separate themselves from the security zeitgeist.&lt;br /&gt;&lt;br /&gt;In recognition of this need for both dependence and originality, Defence Intelligence is working to bring security and internet architecture groups together to create something new and more complete. We want to make a product that takes a more global approach to the threats we're facing, but also bring a confidence and purpose back to our industry that seems to have waned. A strong offence may rely on a good defence but we need both if we're ever going to make real advancement on this battleground. &lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp; Analysis &lt;br /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/889c669d-8f45-494d-8777-59db94cf3408/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=889c669d-8f45-494d-8777-59db94cf3408" alt="Reblog this post [with Zemanta]"&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-2717244273899503281?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/2717244273899503281/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=2717244273899503281' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2717244273899503281'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2717244273899503281'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/02/av-plays-catch-up.html' title='AV Plays Catch Up'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-5447921201795194692</id><published>2010-01-27T14:33:00.015-05:00</published><updated>2010-01-27T15:23:29.432-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='User'/><category scheme='http://www.blogger.com/atom/ns#' term='Search engine optimization'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTP referrer'/><category scheme='http://www.blogger.com/atom/ns#' term='facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='Pop-up ad'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='Webserver directory index'/><title type='text'>Rumor has it.</title><content type='html'>&lt;span style="font-family:georgia;"&gt;Facebook users are being targeted again, but in a more roundabout manner. Rumors are spreading, as rumors do, that an "unnamed app" is integrated into user accounts which is responsible for slowing down facebook and is being used to spy on user activity. (These rumors have not been proven true.) &lt;/span&gt;  &lt;span style="font-family:georgia;"&gt;&lt;br /&gt;&lt;br /&gt;Users are then advised in the form of ALERTS to delete this unnamed app. The interesting part is that user suspicion of these messages is what gives them their malicious power. A Facebook user would then Google the alert or the keywords "unnamed app" and be directed through several sites to ones serving rogue AV. Using &lt;a class="zem_slink freebase/en/search_engine_optimization" href="http://en.wikipedia.org/wiki/Search_engine_optimization" title="Search engine optimization" rel="wikipedia" target="blank"&gt;SEO&lt;/a&gt; techniques many of the top sites listed are the key redirection sites in this process.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left; font-family: arial;"&gt;One such site, at the number three spot in our google search:&lt;br /&gt;"http://kittingservice.com/canst.php?avi=facebook-unnamed-app"&lt;br /&gt;&lt;br /&gt;&lt;/div&gt; &lt;span style=";font-family:arial;font-size:85%;"  &gt;The domain kittingservice.com is found at 62.93.239.41.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Using javascript redirection, we are taken to:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;"http://onlinetechnicals.ru/sm/r.php"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;at 212.95.58.37&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;It looks like the referrer might be necessary for the redirection:&lt;/span&gt; &lt;span style="font-family:arial;"&gt;"Referer: http://www.google.ca/search?hl=en&amp;amp;source=hp&amp;amp;q=facebook+unnamed+app&amp;amp;meta=&amp;amp;aq=f&amp;amp;oq="&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;Otherwise a page comes up with the multiple facebook and SEO terms planted throughout, including some of the original instigating Facebook alert phrases:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;"Has your facebook been slow today? Check your application settings, go into " added to profile". If you see one in there called "unnamed app" delete it."&lt;/span&gt;  &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;"There is a " Unnamed  App " spybot on facebook and it may be slowing down Facebook applications or it may be work as a Spyware."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;The onlinetechnicals.ru page then uses another javascript to direct us to uscaau.com:&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nMx-DUJRrDc/S2Cce8_qCUI/AAAAAAAAAEQ/KNJnHGAjWxY/s1600-h/Picture+1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 80px;" src="http://4.bp.blogspot.com/_nMx-DUJRrDc/S2Cce8_qCUI/AAAAAAAAAEQ/KNJnHGAjWxY/s320/Picture+1.png" alt="" id="BLOGGER_PHOTO_ID_5431513206191950146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;uscaau.com&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;212.95.58.37&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Looking up uscaau.com/back.php comes back with the location of:&lt;/span&gt; &lt;span style="font-family:arial;"&gt;"http://battlestartedsecurity.com/hitin.php?land=20&amp;amp;affid=94801"&lt;/span&gt;  &lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;battlestartedsecurity.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;109.232.225.22&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;span style="font-family:arial;"&gt;and "hitin.php?land=20&amp;amp;affid=94801"&lt;br /&gt;is said to be at the location:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;"index.php?affid=94801"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:georgia;"&gt;This is where we finally download the beginnings of the Rogue AV. A pop up window tells us that &lt;/span&gt; &lt;span style="font-family:georgia;"&gt;"&lt;span style="font-family:courier new;"&gt;Your computer contaigns various signs of viruses and malware programs presence....&lt;/span&gt;"&lt;/span&gt; &lt;span style="font-family:georgia;"&gt; Our browser window has also seemingly disappeared but if you move the warning slightly you can see it resized to hide behind the pop up.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nMx-DUJRrDc/S2CYNwoU_gI/AAAAAAAAAD4/R66lKGeAprU/s1600-h/Picture+1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 138px;" src="http://2.bp.blogspot.com/_nMx-DUJRrDc/S2CYNwoU_gI/AAAAAAAAAD4/R66lKGeAprU/s200/Picture+1.png" alt="" id="BLOGGER_PHOTO_ID_5431508512768589314" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Agreeing to the scan displays the fake scan of our system, going back to battlestartedsecurity.com for the necessary visual items.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nMx-DUJRrDc/S2CZWaFcAfI/AAAAAAAAAEA/3--5gYAurTQ/s1600-h/Picture+3.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 200px; height: 112px;" src="http://4.bp.blogspot.com/_nMx-DUJRrDc/S2CZWaFcAfI/AAAAAAAAAEA/3--5gYAurTQ/s200/Picture+3.png" alt="" id="BLOGGER_PHOTO_ID_5431509760847118834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A few more agreements to clean up our system advises us to download "install.exe", currently only detected by 7 of 41 AV groups.&lt;br /&gt;&lt;br /&gt;Other researchers have indicated different redirection paths being taken and different end result fake security tools.&lt;br /&gt;&lt;br /&gt;As for the unnamed app it is said to just be the "boxes" tab on your Facebook profile.&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;"The Boxes tab contains application profile boxes. A user or Page will have a Boxes tab added to their new profile by default if they currently have application boxes that do not support integration with the main profile/Page left column or if they have more profile boxes than can fit into the main profile/Page left column (more than 5)." &lt;span style="font-size:85%;"&gt;(http://wiki.developers.facebook.com/index.php/Tabbed_Profile)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Removing it seems to be both nondestructive and reversible. According to&lt;br /&gt;&lt;span style="font-size:85%;"&gt;(http://answers.yahoo.com/question/index?qid=20100126190431AAJkPoW)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;"to put back your boxes tab:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;1. go back to the page where you removed the Unnamed App from.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;2. select "edit settings" for an app under the "added profile boxes" section&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;3. click remove, then click add when it appears."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp; Analysis&lt;br /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/0cdf1faa-a6a1-4c70-92cd-2ff181c7ee54/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=0cdf1faa-a6a1-4c70-92cd-2ff181c7ee54" alt="Reblog this post [with Zemanta]" /&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-5447921201795194692?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/5447921201795194692/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=5447921201795194692' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5447921201795194692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5447921201795194692'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2010/01/rumor-has-it.html' title='Rumor has it.'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nMx-DUJRrDc/S2Cce8_qCUI/AAAAAAAAAEQ/KNJnHGAjWxY/s72-c/Picture+1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1007093432957092311</id><published>2009-12-16T15:20:00.008-05:00</published><updated>2009-12-18T11:31:02.168-05:00</updated><title type='text'>CN Less Clearly</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:arial, serif;"&gt;&lt;span class="Apple-style-span"   style="  color: rgb(11, 35, 12); line-height: 18px; font-family:'Trebuchet MS', Trebuchet, Verdana, sans-serif;font-size:-webkit-xxx-large;"&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span"   style="font-family:arial, Trebuchet, Verdana, sans-serif;color:#000000;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Trebuchet MS', Trebuchet, Verdana, sans-serif; font-size: 12px; color: rgb(11, 35, 12); "&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;On December 11, the China Internet Network Information Center (CNNIC) announced that individuals hoping to register .CN domain names are now required to provide a written application. This written application must be stamped with a business seal, and a photocopy of the applicant's business license and ID must be included. This effort is touted as simply part of a greater effort to remove a significant amount of pornographic content from the web.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: 'times new roman'; "&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;The reality is far more complex.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;China has long used the Great Firewall of China to block any material it deems offensive, including pornographic material, so-called biased news sources and political commentary. Facebook, Twitter, and thousands of other sites are blocked and cannot be accessed from within China. As reported by Rebecca McKinnon, Assistant Professor, University of Hong Kong:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;"People who work for Chinese Internet companies continue to complain that they remain under heavy pressure to be more thorough about the way in which they police and censor blogging platforms, social networking sites, discussion forums, and any form of user-generated content. "&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;By restricting the .CN TLD to businesses that must meet with approval by a governing body, China is reigning in control over the Internet at a time when people are increasingly looking to the web for freedom of expression, political action, and news and information from a wide variety of sources all with their own particular bias.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;Since the announcement, the information security community has been abuzz with the notion that this new restriction will result in fewer malicious domains registered at .CN. That would certainly be good news for China, which has long been considered a pernicious purveyor of malicious content.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;Unfortunately, it isn't true.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;Looking at the original notice, it is clear that following the initial online submission and subsequent allocation of a domain name, individuals then have 5 days to provide the appropriate governing body with the required written material. If after 5 days or if the applicant is rejected, the domain will be revoked.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;It doesn't require much thought to see how this system can easily be abused. Individuals with criminal intent can simply register for a domain and generate and propagate as much malicious content as desired over the course of the next 120 hours. It is also likely, though unknown at this time, that any money spent of the domain registration would be refunded so as not to unduly penalize legitimate businesses who may simply make an error on their forms, be rejected, and have to resubmit. To be clear, I find it unlikely that the CNNIC would require people to pay for domains that they do not own. Criminals can simply use a domain for free for 5 days and then move onto the next.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;On that same note, will there be any process in place to permanently ban individuals who continually register domains only to be rejected? And does the CNNIC really expect to be able to intake and process what is potentially thousands of applications a day? What happens when that 5 day window becomes 10 days? Much to the dismay of the security world, criminals may rejoice at this announcement.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;So, while cybercriminals need only a few minutes to distribute malicious content, individuals within China whose views are not in accordance with their governments' need many words, many pages, and much support to leverage the power of the Internet to engage and enlighten the world. It is these people who will be most affected and individuals of all sorts, not just security professionals, should lament any moment when the Internet becomes a little less free, a little less open.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;Meaghan Molloy&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify; "&gt;&lt;span class="Apple-style-span" style="font-family: arial; "&gt;&lt;span class="Apple-style-span" style="font-size: small; "&gt;Threat Analyst&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1007093432957092311?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1007093432957092311/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1007093432957092311' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1007093432957092311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1007093432957092311'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/12/cn-less-clearly.html' title='CN Less Clearly'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-2251612726315175056</id><published>2009-11-06T13:37:00.001-05:00</published><updated>2009-11-06T13:38:38.742-05:00</updated><title type='text'>Mariposa and BlackEnergy DDOS</title><content type='html'>Talk of Mariposa may have faded, but the botnet is still very active. Some new occurrences have been observed here and merit reporting for those still following the story.&lt;br /&gt;&lt;br /&gt;The origins of the Mariposa botnet for Defence Intelligence goes back to the observance of a suspicious domain that was being queried for quite frequently.&lt;br /&gt;&lt;br /&gt;Butterfly.bigmoney.biz had popped up in our radar as unusual in both its name and the volume of queries for it that were being made. With some fairly extensive &lt;a href="http://defintel.blogspot.com/2009/10/mariposa-botnet-analysis.html" target="_blank"&gt;analysis&lt;/a&gt;, our investigation revealed some other domains of interest:&lt;br /&gt;&lt;br /&gt;butterfly.sinip.es&lt;br /&gt;bfisback.sinip.es&lt;br /&gt;qwertasdfg.sinip.es&lt;br /&gt;&lt;br /&gt;These four, butterfly.bigmoney.biz included, had proved to be command and control domains for the botnet.&lt;br /&gt;&lt;br /&gt;On October 4th an update occurred and new domains were contacted.&lt;br /&gt;&lt;br /&gt;lalundelau.sinip.es&lt;br /&gt;bf2back.sinip.es&lt;br /&gt;thejacksonfive.mobi&lt;br /&gt;&lt;br /&gt;The latter of these has taken on a much different role over time. Communication to 200.74.244.84, where thejacksonfive.mobi was also pointed, was readily seen after the 4th. Various commands to Mariposa were being issued from this IP, including one to spread itself across MSN using the drop site URL http://obamawebcam.com/load.php. The file to be dropped was named bin.exe but the spread on our test system was ineffective at the time. A Virustotal report showed detections as palevo as many of the malware behind Mariposa are labeled. Several other binaries were also downloaded, most of them from rapidshare.com.&lt;br /&gt;&lt;br /&gt;Recently, on November 3rd, a new binary was grabbed from rapidshare as instructed by butterfly.bigmoney.biz. This file, named blackjackson.exe, was found to be version 1.92 of the BlackEnergy DDOS bot and along with its installation came a new C&amp;C domain, thejacksonfive.us. Both thejacksonfive.us and thejacksonfive.mobi are now also used as web based GUI controls for BlackEnergy. &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nMx-DUJRrDc/SvRo1PzbOsI/AAAAAAAAADg/8Rtx-WZTpUI/s1600-h/Picture+2.png" target="_blank"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 48px;" src="http://2.bp.blogspot.com/_nMx-DUJRrDc/SvRo1PzbOsI/AAAAAAAAADg/8Rtx-WZTpUI/s200/Picture+2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5401057117108648642" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A good writeup on BlackEnergy can be found in Arbor's &lt;a href="http://atlas-public.ec2.arbor.net/docs/BlackEnergy+DDoS+Bot+Analysis.pdf" target="_blank"&gt;BlackEnergy+DDoS+Bot+Analysis.pdf&lt;/a&gt;. A third related domain, tamiflux.net, is also used as a web interface for the DDOS malware and is currently the only one blacklisted by Firefox.&lt;br /&gt;&lt;br /&gt;On November 4th, thejacksonfive.us issued a command to begin an HTTP GET request flood of three domains and one IP:&lt;br /&gt;&lt;br /&gt;al-hora.net&lt;br /&gt;saaid.net&lt;br /&gt;islamlight.net&lt;br /&gt;74.86.18.4 (the IP address for saaid.net)&lt;br /&gt;&lt;br /&gt;These Saudi Arabian sites appear to be forums for religious and regional political discussion so the motivation behind the attacks may also be religious or political. Al-hora.com has been targeted for "censorship" for quite some time now and has apparently been kept offline since December 2007. Read more at &lt;a href="http://www.rsf.org/en-ennemi26081-Saudi_Arabia.html" target="_blank"&gt;www.rsf.org&lt;/a&gt;. Currently, of the sites being targeted, only saaid.net has managed to recover from the attacks.&lt;br /&gt;&lt;br /&gt;On November 5th, thejacksonfive.us site changed orders to alter the attack slightly, using a syn flood instead of a GET request flood and only targeting islamlight.net and saaid.net. This alteration was likely made in response to saaid.net's sustained presence online. (They talk about the attack on the home page.) Tamiflux.net is HTTP flooding the same domains.&lt;br /&gt;&lt;br /&gt;Gaining some insight into the attacks we've discovered that the DDOS botnet has about 5500 members under active control at any given time, and over 60,000 unique compromised systems. This is rather small however compared to the 1.5 million unique computers we believe to be members of the Mariposa botnet.&lt;br /&gt;&lt;br /&gt;The Mariposa botnet has continued to grow in size since we first observed it in May and has far surpassed our original estimation of 150 to 200k compromised systems. The distribution of compromised systems is fairly wide but concentrations are obvious in Central America, Europe and South Korea.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nMx-DUJRrDc/SvRpfH8InUI/AAAAAAAAADo/WNy0nywInsU/s1600-h/map118.jpg" target="_blank"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 100px;" src="http://3.bp.blogspot.com/_nMx-DUJRrDc/SvRpfH8InUI/AAAAAAAAADo/WNy0nywInsU/s200/map118.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5401057836552199490" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-2251612726315175056?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/2251612726315175056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=2251612726315175056' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2251612726315175056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2251612726315175056'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/11/mariposa-and-blackenergy-ddos.html' title='Mariposa and BlackEnergy DDOS'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nMx-DUJRrDc/SvRo1PzbOsI/AAAAAAAAADg/8Rtx-WZTpUI/s72-c/Picture+2.png' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-7648637930249579694</id><published>2009-11-05T11:08:00.012-05:00</published><updated>2009-11-05T11:29:52.908-05:00</updated><title type='text'>MaCatte's Green roots are showing.</title><content type='html'>As an update to &lt;a href="http://defintel.blogspot.com/2009/09/riding-green-wave.html"&gt;my previous post on GreenAV&lt;/a&gt;, it seems that they are still trying to "Save the green forests of Amazonia" by having you install rogue antivirus.&lt;br /&gt;&lt;br /&gt;MaCatte is the newest rogue AV to appear and has ties to the GreenAV software that was recently promoted , all the websites sharing the same IP 174.142.96.2&lt;br /&gt;&lt;br /&gt;express.greencustomersupport.com&lt;br /&gt;green-av-2010-pro.com&lt;br /&gt;green-av-2010.com&lt;br /&gt;green-av-pre.com&lt;br /&gt;green-av-pro.com&lt;br /&gt;macatte.com&lt;br /&gt;my-green-av-pre.com&lt;br /&gt;my-green-av-pro.com&lt;br /&gt;my-green-av.com&lt;br /&gt;p4678z.my-green-av.com&lt;br /&gt;progresivescan.info&lt;br /&gt;zp4.green-av.com&lt;br /&gt;zp45.green-av-pro.com&lt;br /&gt;&lt;br /&gt;In fact, going to express.greencustomerssupport.com will take you to the MaCatte homepage. MaCatte, like so many other rogue AVs, runs fake scans on the machine and advises the user that the machine is infected, and that they will gladly remove the infections as long as one pays to register the product for $99. Macatte is propagating in the same manner as GreenAV through torrent sites, website redirection and freeware.&lt;br /&gt;&lt;br /&gt;MaCatte seems to be attempting to ride the coat tails of McAfee, with the similar name, logo and also similar website design. Included features on the site are a lovely challange-response captcha in the support section to ensure that the support requests are generated by an actual person and not a machine. There is a "Latest Threads Detected" box that lists a few common threats such as Conficker, and if you actually want to buy the product for $99 there is a link to plimus.com's payment processing. (At the time of writing, the order page at plimus.com was currently unavailable.) It would be interesting to see stats on how many people actually land on that payment page for MaCatte.&lt;br /&gt;&lt;br /&gt;Plimus.com is a company that offers payment processing for online businesses and takes a commission rate from each sale. Your own conclusions can be drawn regarding Plimus' track record after reading  &lt;a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=plimus.com"&gt;Google's Safe Browsing diagnostic page for Plimus&lt;/a&gt; also the reviews on &lt;a href="http://www.mywot.com/en/scorecard/plimus.com"&gt;Web of Trust.&lt;/a&gt; Norton did have the site flagged as unsafe for selling key logger software but has since changed its rating to safe. Also, the Plimus site does show a McAfee and Verisign Secure logo at the bottom of their page. I am unsure at this time if the Plimus website is in fact MaCatte secure or not.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nMx-DUJRrDc/SvL6cC4WY3I/AAAAAAAAADI/JwJNgYqIEi0/s1600-h/MaCatte+Site.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 180px; height: 158px;" src="http://3.bp.blogspot.com/_nMx-DUJRrDc/SvL6cC4WY3I/AAAAAAAAADI/JwJNgYqIEi0/s200/MaCatte+Site.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5400654262887146354" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nMx-DUJRrDc/SvL6sc6Dk3I/AAAAAAAAADQ/OVKl8algfwE/s1600-h/McAfee+Site2.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 180px; height: 186px;" src="http://1.bp.blogspot.com/_nMx-DUJRrDc/SvL6sc6Dk3I/AAAAAAAAADQ/OVKl8algfwE/s200/McAfee+Site2.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5400654544751530866" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;MaCatte offers to detect, block, and remove viruses, spyware and rootkits with a quick scan. The program also has an anti-phishing component that is supposed to warn you before accessing dangerous scam websites like their own. The feature that looks the most interesting is the Identity Protection. “Let's you shop, bank and trade online safely by asking permission before personally identifiable information like PIN'S, Bank accounts, Social Security numbers are sent from your machine.” I do not believe the effectiveness or honesty behind these statements.&lt;br /&gt;&lt;br /&gt;Currently there are no removal tools readily available to the public, but for now you are able to do a system restore back to a `pre-infection` restore point. Although there have been reports that MaCatte has added a feature to block attempts to do a system restore. So if you are infected with MaCatte Rogue AV, you might as well reformat.&lt;br /&gt;&lt;br /&gt;MaCatte is just another rendition of Rogue Antivirus using fake scans and scareware tactics to con people into paying for their software while selling off their information as an added bonus. But hey, they do have a refund policy.&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nMx-DUJRrDc/SvL7K7Y_0SI/AAAAAAAAADY/gaxdEXpo93c/s1600-h/MaCatte-Refund.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 149px;" src="http://3.bp.blogspot.com/_nMx-DUJRrDc/SvL7K7Y_0SI/AAAAAAAAADY/gaxdEXpo93c/s200/MaCatte-Refund.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5400655068330447138" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0cm; font-family: arial;"&gt;B.Kilrea&lt;br /&gt;Threat Analyst&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-7648637930249579694?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/7648637930249579694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=7648637930249579694' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/7648637930249579694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/7648637930249579694'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/11/macattes-green-roots-are-showing.html' title='MaCatte&apos;s Green roots are showing.'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_nMx-DUJRrDc/SvL6cC4WY3I/AAAAAAAAADI/JwJNgYqIEi0/s72-c/MaCatte+Site.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-1382276765363488997</id><published>2009-10-30T14:57:00.005-04:00</published><updated>2009-10-30T15:11:47.339-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Lambdanet'/><category scheme='http://www.blogger.com/atom/ns#' term='Malicious Software'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Slot machine'/><category scheme='http://www.blogger.com/atom/ns#' term='Domain Name System'/><category scheme='http://www.blogger.com/atom/ns#' term='Mozilla Firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='IP address'/><title type='text'>Blogspot Whammies</title><content type='html'>&lt;p class="zemanta-img" style="margin: 1em; float: right; display: block; width: 310px;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Image:Casino_slots.jpg"&gt;&lt;img src="http://upload.wikimedia.org/wikipedia/en/thumb/6/65/Casino_slots.jpg/300px-Casino_slots.jpg" alt="Slot machines in the Trump Taj Mahal" style="border: medium none ; display: block;" height="189" width="300"&gt;&lt;/a&gt;&lt;span class="zemanta-img-attribution"&gt;Image via &lt;a href="http://en.wikipedia.org/wiki/Image:Casino_slots.jpg"&gt;Wikipedia&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;I enjoy seeing what the world has to say from time to time and to give everyone's voice a fair shake I will often click "Next Blog" in Blogspot's standard blog header. I know that Blogspot pages are now a popular point of redirection for initiating malware download, especially with Koobface. I also know that rogue AV is the gravy train of scam software and is now being promoted through Koobface. Now when I go gambling I never win anything, but it appears the Blogspot "Next Blog" slot machine has shown up all cherries. Well, maybe lemons.&lt;br /&gt;&lt;br /&gt;In a very swift redirection I was brought to "antivirusn.com/scan1/?pid=156&amp;amp;engine=%3DnQyzTjuNjgyLjIzLjI4JnRpbWU9MTI1MTgxMI0OaA%3DN". This was supposed to perform a "scan" of my computer as is customary with rogue AV, but Firefox was kind enough to report this as a "Reported Attack Site!"&lt;br /&gt;Let's take a peek at "antivirusn.com" and see what this family of rogue AV looks like. Maybe I know some of your relatives.&lt;br /&gt;&lt;br /&gt;antivirusn.com  A  83.133.119.154&lt;br /&gt;antivirusn.com  A  91.212.107.7&lt;br /&gt;antivirusn.com  NS  ns1.everydns.net&lt;br /&gt;antivirusn.com  NS  ns2.everydns.net&lt;br /&gt;antivirusn.com  NS  ns3.everydns.net&lt;br /&gt;antivirusn.com  NS  ns4.everydns.net&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;Name: Lian S Richard&lt;br /&gt;Address: Overhogdal 25&lt;br /&gt;City: MOLNLYCKE&lt;br /&gt;Province/state: MOLNLYCKE&lt;br /&gt;Country: SE&lt;br /&gt;Postal Code: 43510&lt;br /&gt;&lt;br /&gt;Administrative Contact:&lt;br /&gt;Name: Lian S Richard&lt;br /&gt;Organization: n/a&lt;br /&gt;Address: Overhogdal 25&lt;br /&gt;City: MOLNLYCKE&lt;br /&gt;Province/state: MOLNLYCKE&lt;br /&gt;Country: SE&lt;br /&gt;Postal Code: 43510&lt;br /&gt;Phone: +5.3017560166&lt;br /&gt;Fax: +5.3017560166&lt;br /&gt;Email: info@airlineshun.be&lt;br /&gt;&lt;br /&gt;Technical Contact:&lt;br /&gt;Name: Lian S Richard&lt;br /&gt;Organization: n/a&lt;br /&gt;Address: Overhogdal 25&lt;br /&gt;City: MOLNLYCKE&lt;br /&gt;Province/state: MOLNLYCKE&lt;br /&gt;Country: SE&lt;br /&gt;Postal Code: 43510&lt;br /&gt;&lt;br /&gt;Nameserver Information:&lt;br /&gt;ns1.everydns.net&lt;br /&gt;ns2.everydns.net&lt;br /&gt;ns3.everydns.net&lt;br /&gt;ns4.everydns.net&lt;br /&gt;&lt;br /&gt;Create: 2009-10-28 18:44:36&lt;br /&gt;Update: 2009-10-29&lt;br /&gt;Expired: 2010-10-28&lt;br /&gt;&lt;br /&gt;What else is going on at these IPs?&lt;br /&gt;&lt;br /&gt;Passive DNS over at www.bfk.de reveals the following:&lt;br /&gt;&lt;br /&gt;virus-detect01.com  A  83.133.119.154&lt;br /&gt;bestantispyware11.com  A  83.133.119.154&lt;br /&gt;top-scanner11.com  A  83.133.119.154&lt;br /&gt;detect-spyware1.com  A  83.133.119.154&lt;br /&gt;top-scanner02.com  A  83.133.119.154&lt;br /&gt;top-scanner2.com  A  83.133.119.154&lt;br /&gt;virus-detect2.com  A  83.133.119.154&lt;br /&gt;top-scanner04.com  A  83.133.119.154&lt;br /&gt;virus-detect04.com  A  83.133.119.154&lt;br /&gt;detect-spyware5.com  A  83.133.119.154&lt;br /&gt;virus-detect6.com  A  83.133.119.154&lt;br /&gt;detect-spyware7.com  A  83.133.119.154&lt;br /&gt;virus-detect08.com  A  83.133.119.154&lt;br /&gt;bestantispyware09.com  A  83.133.119.154&lt;br /&gt;detect-spyware9.com  A  83.133.119.154&lt;br /&gt;top-scanner9.com  A  83.133.119.154&lt;br /&gt;kill-virusc.com  A  83.133.119.154&lt;br /&gt;kill-virusd.com  A  83.133.119.154&lt;br /&gt;scannerg.com  A  83.133.119.154&lt;br /&gt;scannerh.com  A  83.133.119.154&lt;br /&gt;antivirusk.com  A  83.133.119.154&lt;br /&gt;antivirusm.com  A  83.133.119.154&lt;br /&gt;antivirusn.com  A  83.133.119.154&lt;br /&gt;scannerr.com  A  83.133.119.154&lt;br /&gt;scanneru.com  A  83.133.119.154&lt;br /&gt;154.119.133.83.in-addr.arpa  PTR  id1148.rdso.ru&lt;br /&gt;&lt;br /&gt;virus-detect01.com  A  85.12.24.12&lt;br /&gt;bestantispyware11.com  A  85.12.24.12&lt;br /&gt;top-scanner11.com  A  85.12.24.12&lt;br /&gt;top-scanner02.com  A  85.12.24.12&lt;br /&gt;top-scanner2.com  A  85.12.24.12&lt;br /&gt;top-scanner04.com  A  85.12.24.12&lt;br /&gt;bestantispyware09.com  A  85.12.24.12&lt;br /&gt;top-scanner9.com  A  85.12.24.12&lt;br /&gt;&lt;br /&gt;And we find another IP: 91.212.107.7&lt;br /&gt;&lt;br /&gt;virus-detect01.com  A  91.212.107.7&lt;br /&gt;bestantispyware11.com  A  91.212.107.7&lt;br /&gt;top-scanner11.com  A  91.212.107.7&lt;br /&gt;detect-spyware1.com  A  91.212.107.7&lt;br /&gt;top-scanner02.com  A  91.212.107.7&lt;br /&gt;top-scanner2.com  A  91.212.107.7&lt;br /&gt;virus-detect2.com  A  91.212.107.7&lt;br /&gt;top-scanner04.com  A  91.212.107.7&lt;br /&gt;virus-detect04.com  A  91.212.107.7&lt;br /&gt;detect-spyware5.com  A  91.212.107.7&lt;br /&gt;virus-detect6.com  A  91.212.107.7&lt;br /&gt;detect-spyware7.com  A  91.212.107.7&lt;br /&gt;virus-detect08.com  A  91.212.107.7&lt;br /&gt;bestantispyware09.com  A  91.212.107.7&lt;br /&gt;detect-spyware9.com  A  91.212.107.7&lt;br /&gt;top-scanner9.com  A  91.212.107.7&lt;br /&gt;kill-virusc.com  A  91.212.107.7&lt;br /&gt;kill-virusd.com  A  91.212.107.7&lt;br /&gt;scannerg.com  A  91.212.107.7&lt;br /&gt;scannerh.com  A  91.212.107.7&lt;br /&gt;antivirusk.com  A  91.212.107.7&lt;br /&gt;antivirusm.com  A  91.212.107.7&lt;br /&gt;antivirusn.com  A  91.212.107.7&lt;br /&gt;scannerr.com  A  91.212.107.7&lt;br /&gt;scanneru.com  A  91.212.107.7&lt;br /&gt;&lt;br /&gt;Well, rogue AV is obviously the name of the game here. Let's look on a larger scale at the AS level.&lt;br /&gt;&lt;br /&gt;83.133.119.154 is under AS13237 (LAMBDANET)&lt;br /&gt;&lt;br /&gt;MalwareURL.com reports 200 domains under Lambdanet, the majority of which relate to rogue AV.&lt;br /&gt;&lt;br /&gt;85.12.24.12 points to AS34305 (EUROACCESS)&lt;br /&gt;&lt;br /&gt;They are small time with only 23 domains reported by MalwareURL.com. They consist of rogue AV and Zbot.&lt;br /&gt;&lt;br /&gt;The big guy comes with AS49038 (RICCOM) which was over the IP 91.212.107.7.&lt;br /&gt;&lt;br /&gt;326 Riccom domains were reported by MalwareURL.com, and only about seven were unrelated to rogue software.&lt;br /&gt;&lt;br /&gt;There's a dozen other IPs mixed in here going back to March, but most notable is 91.212.107.103 which also comes up under AS29550 (EUROCONNEX). This IP gem has hundreds of domains pointed to it in relation to rogue software, such as:&lt;br /&gt;windoptimizer.com  A  91.212.107.103&lt;br /&gt;woptimizer.com  A  91.212.107.103&lt;br /&gt;goscandir.com  A  91.212.107.103&lt;br /&gt;in5cs.com  A  91.212.107.103&lt;br /&gt;general-antivirus.com  A  91.212.107.103&lt;br /&gt;www.general-antivirus.com  A  91.212.107.103&lt;br /&gt;generalantivirus.com  A  91.212.107.103&lt;br /&gt;goscanneat.com  A  91.212.107.103&lt;br /&gt;in5ct.com  A  91.212.107.103&lt;br /&gt;in5it.com  A  91.212.107.103&lt;br /&gt;wopayment.com  A  91.212.107.103&lt;br /&gt;goscanrest.com  A  91.212.107.103&lt;br /&gt;ereuqba.cn  A  91.212.107.103&lt;br /&gt;dycotda.cn  A  91.212.107.103&lt;br /&gt;&lt;br /&gt;just to list a few. This also leads back to Koobface and the "2008 ali baba and 40, LLC" which you can read about in &lt;a href="http://ddanchev.blogspot.com/2009/09/koobface-botnets-scareware-business.html" target="_blank"&gt;Dancho's&lt;/a&gt; blog from September. It looks like antivirusn.com was part of a large family after all. No surprise there. I'm sure I'll be bumping into you again.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp; Analysis&lt;br /&gt;&lt;br /&gt;&lt;fieldset class="zemanta-related"&gt;&lt;legend class="zemanta-related-title"&gt;Related articles by Zemanta&lt;/legend&gt;&lt;ul class="zemanta-article-ul"&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://news.cnet.com/8301-17939_109-10384028-2.html?part=rss&amp;amp;subj=Webware"&gt;Fake Facebook e-mail contains Trojan&lt;/a&gt; (news.cnet.com)&lt;/li&gt;&lt;li class="zemanta-article-ul-li"&gt;&lt;a href="http://r.zemanta.com/?u=http%3A//news.bbc.co.uk/2/hi/technology/8333194.stm&amp;amp;a=9046542&amp;amp;rid=1275fa91-8154-4747-8ba7-536a66815175&amp;amp;e=5ab3f5ad03a73f1753fe86b0a926a510"&gt;Internet addresses set for change&lt;/a&gt; (news.bbc.co.uk)&lt;/li&gt;&lt;/ul&gt;&lt;/fieldset&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"&gt;&lt;a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/1275fa91-8154-4747-8ba7-536a66815175/" title="Reblog this post [with Zemanta]"&gt;&lt;img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=1275fa91-8154-4747-8ba7-536a66815175" alt="Reblog this post [with Zemanta]"&gt;&lt;/a&gt;&lt;span class="zem-script more-related more-info pretty-attribution"&gt;&lt;script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"&gt;&lt;/script&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-1382276765363488997?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/1382276765363488997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=1382276765363488997' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1382276765363488997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/1382276765363488997'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/10/blogspot-whammies.html' title='Blogspot Whammies'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-2526271908911156004</id><published>2009-10-29T12:38:00.014-04:00</published><updated>2009-10-29T13:07:14.266-04:00</updated><title type='text'>ICANN and IDNs</title><content type='html'>ICANN is meeting in Korea this week to discuss several issues regarding domain management, including post-expiration domain name recovery, registration abuse policies, new gTLDs and IDN ccTLDs. While all of this is interesting, I started to think about how many of English-as-their-only-language web users are even aware of this final issue. Did you ever consider that while the Internet is dominated by English focused websites, 60% of its users are non-English speakers? How many of you were aware that a URL could even be written in Chinese?&lt;br /&gt;&lt;br /&gt;IDNs are internationalized domain names that are written using local language characters, not just limited to Latin or ASCII based script. The second level domains have been available for some time, such as "日本語ドメイン.com" but are currently limited to 2LDs and on, leaving the ASCII familiar TLDs (top-level domains) like ".com" to remain as a foreign language appendix. What we are likely to see very soon however, thanks to the ICANN discussions, is domains completely constructed using just one language.&lt;br /&gt;&lt;br /&gt;ICANN has set up a test page at &lt;a href="http://idn.icann.org/" target="_blank"&gt;idn.icann.org&lt;/a&gt;. Here you can see the same example.test domain in Arabic, Greek, Cyrillic, and Hebrew.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_nMx-DUJRrDc/SunFWVr3OkI/AAAAAAAAACo/_hfcgv2H7uc/s1600-h/Picture+1.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 143px;" src="http://4.bp.blogspot.com/_nMx-DUJRrDc/SunFWVr3OkI/AAAAAAAAACo/_hfcgv2H7uc/s320/Picture+1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398062615949163074" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So what does this mean for DNS which performs its Q&amp;A based on the ASCII code?  In order for DNS to understand and interpret these IDNs the unicode domain string is encoded using punycode, transforming it into ASCII so it can resolve properly. A full explanation of the punycode bootstring algorithm can be found &lt;a href="http://tools.ietf.org/html/rfc3492" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For every domain there is a label assigned to it. The DNS stored label is usually the same as the displayed label for Latin based domain names, but with IDNs and punycode we see a more significant difference between the two. A displayed label is called a U-label for unicode and its stored version is an A-label for ASCII. The result now, that most consumers will never realize, is you can have "'example.test', displayed as 'пример.испытание', (in cyrillic) but is stored as 'xn--e1afmkfd.xn--80akhbyknj4f'"(example from &lt;a href="http://idn.icann.org/IDN_basics" target="_blank"&gt;ICANN&lt;/a&gt;). Every punycode version of these IDNs will begin with "xn--".&lt;br /&gt;&lt;br /&gt;It's great that ICANN is making this movement for a more internationally conscious and applicable Internet, but it seems very delayed. How much has an English dominated Internet kept the rest of the world out of the loop? A couple of examples provided by ICANN documents bring up everyday situations many of us take for granted. If I read a billboard or advertisement that has an accompanying web address, I go there for more information. But what if that URL was in Chinese or Hindi? I wouldn't be able to remember the address or use my keyboard to even reproduce it. I would of course prefer to have the web address in the same language as everything else I'm reading. This change will be especially advantageous for script such as Arabic that reads from right to left. You can imagine how confusing that is currently for conveying a URL properly to international consumers.&lt;br /&gt;&lt;br /&gt;There are three programs for obtaining entire native language IDNs. The proposed launch date for the IDN ccTLD Fast Track Process is November 16, 2009.&lt;br /&gt;&lt;br /&gt;For some application and browser IDN handling issues, check out &lt;a href="http://www.idnnews.com/?p=8760" target="_blank"&gt;IDNnews.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Matt Sully&lt;br /&gt;Director&lt;br /&gt;Threat Research &amp; Analysis&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-2526271908911156004?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/2526271908911156004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=2526271908911156004' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2526271908911156004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2526271908911156004'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/10/icann-and-idns.html' title='ICANN and IDNs'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_nMx-DUJRrDc/SunFWVr3OkI/AAAAAAAAACo/_hfcgv2H7uc/s72-c/Picture+1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-5963485994507765996</id><published>2009-10-28T11:36:00.004-04:00</published><updated>2009-10-28T11:54:55.358-04:00</updated><title type='text'>Wireshark Plugin for Mariposa Botnet Command and Control</title><content type='html'>&lt;p&gt;"Yamata Li of the Palo Alto Networks Threat Research Team has developed a Wireshark plugin that will allow you to view obfuscated pcaps of traffic from a Mariposa infected client and actually decrypt them within Wireshark."&lt;br /&gt;&lt;/p&gt;&lt;br /&gt;&lt;a href="http://www.paloaltonetworks.com/researchcenter/2009/10/mariposa-tool/"&gt;http://www.paloaltonetworks.com/researchcenter/2009/10/mariposa-tool/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Thanks Yamata, the time and effort you have put into this plug-in is much appreciated. &lt;br /&gt;&lt;br /&gt;B.Kilrea&lt;br /&gt;Threat Analyst&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-5963485994507765996?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/5963485994507765996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=5963485994507765996' title='25 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5963485994507765996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5963485994507765996'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/10/yamata-li-of-palo-alto-networks-threat.html' title='Wireshark Plugin for Mariposa Botnet Command and Control'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>25</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-8473443038306248322</id><published>2009-10-09T16:24:00.009-04:00</published><updated>2010-03-02T19:46:28.749-05:00</updated><title type='text'>Mariposa Botnet Analysis</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;br /&gt;*** Update ***&lt;br /&gt;&lt;br /&gt;An updated version of the Mariposa Technical Analysis can be found at &lt;a href="http://defintel.com/docs/Mariposa_Analysis.pdf"&gt;http://defintel.com/docs/Mariposa_Analysis.pdf &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;***&lt;br /&gt;&lt;br /&gt;Mariposa was first observed in May of 2009 by &lt;a href="http://www.defintel.com/"&gt;Defence Intelligence&lt;/a&gt; as an emerging botnet. In recent months, Mariposa has shown a significant increase in beaconing traffic to its command and control servers. This is indicative of an increasingly high number of compromised computers actively participating in the Mariposa botnet.&lt;br /&gt;&lt;br /&gt;The most dangerous capability of this botnet is that arbitrary executable programs are downloaded and executed on command. This allows the bot master to infinitely extend the functionality of the malicious software beyond what is implemented during the initial compromise. In addition, the malware can be updated on command to a new variant of the binary, effectively reducing or eliminating the detection rates of traditional host detection methods.&lt;br /&gt;&lt;br /&gt;Commands from the botnet master may be directed at participants in a specific country, individual computers, or all computers. As a result, the observation of the live command and control channel may not include all of the activity and capabilities of Mariposa.&lt;br /&gt;&lt;br /&gt;The command and control channel employs custom encrypted UDP datagrams to receive instructions and transmit data.  A detailed analysis of the encryption and message formats used by the protocol are presented in this paper.&lt;br /&gt;&lt;br /&gt;During empirical analysis of internal controlled compromised systems, the following DNS domain names were observed as the command and control servers:&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;lalundelau.sinip.es&lt;/li&gt;&lt;li&gt;bf2back.sinip.es&lt;/li&gt;&lt;li&gt;thejacksonfive.mobi&lt;/li&gt;&lt;li&gt;butterfly.BigMoney.biz&lt;/li&gt;&lt;li&gt;bfisback.sinip.es&lt;/li&gt;&lt;li&gt;qwertasdfg.sinip.es&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Over the last two weeks of analysis, two unique malicious programs were downloaded and executed on the compromised computers. One malware update was received during this period,  introducing new command and control domain names, adding a ‘confirmation of download’ message, and renaming ASCII commands.&lt;br /&gt;&lt;br /&gt;It has also been observed that the botnet participants are receiving Google custom search engine URL fragments in a command from the bot master. This indicates a possible hijacking of Google AdSense advertisement revenue.&lt;br /&gt;&lt;br /&gt;This paper details the result of static binary analysis, a review of the command and control protocols including a breakdown of the encryption, and empirical behaviour analysis findings.&lt;br /&gt;&lt;br /&gt;The full Mariposa Botnet Analysis is available in PDF form at &lt;a href="http://defintel.com/docs/Mariposa_Analysis.pdf"&gt;defintel.com&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-8473443038306248322?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/8473443038306248322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=8473443038306248322' title='114 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8473443038306248322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8473443038306248322'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/10/mariposa-botnet-analysis.html' title='Mariposa Botnet Analysis'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>114</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-3389773380246893315</id><published>2009-10-01T10:30:00.004-04:00</published><updated>2009-11-02T15:53:38.392-05:00</updated><title type='text'>Mariposa Defined</title><content type='html'>&lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Defence Intelligence has received quite a few responses to our story on the Mariposa botnet. They have run the gamut from polite information inquiries to accusations of falsifying our findings for media coverage, and thinly veiled threats of legal action. A response of our own has become necessary and we hope it at least answers some common questions many of you have asked.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;Who is Defence Intelligence?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;To begin with we are not an anti-virus company. We have spent the last 14 years protecting companies from hackers, not viruses. Until just a few years ago a virus and a hacker had very little to do with each other. Viruses are annoying and at times destructive but pose very little actual threat to a company or government's information and its assets. A hacker's goal on the other hand is to stealthily gain control of a targeted system with the intent of stealing data, attacking the internal network, or using the controlled system to attack an external network.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;In the last few years these two distinct threats have blended. Hackers have discovered that direct external attacks are unnecessary and risky. It is now easier to engineer malicious software that is delivered to a system remotely through various means.  Once that malicious software is on an internal computer, it then communicates outbound to the hacker, handing them complete control of the affected system. &lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; text-align: center; text-indent: 13.1px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;i&gt;When a system is compromised in this manner the attack is all too often misunderstood and dismissed as a mere virus, not just by the victim but by those providing that victim’s system security.&lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;The Defence Intelligence team comes from an information security background, and not an anti-virus background, which means we view things differently. Within incident response, multiple events form an incident and events are constructed using various components. IP addresses, domain names, binaries, people, companies, and networks are all parts of this particular incident, which in this case, is a botnet.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;What is Mariposa?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Mariposa is a collection of compromised computers that are directly under the control of a single malicious entity. In the security industry we call this a botnet.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Mariposa is NOT a virus, or a worm, or a trojan or any other dated designation still inappropriately assigned to modern day malware. The malicious software used by Mariposa, and any other botnet, actively evolves to become whatever is needed by its controller and is not limited by the boundaries of antivirus labels. This means that a trojan can be told to spread like a worm. It means that malware designed to send spam can be instructed to steal banking information.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Modern malware can no longer be classified by its perceived purpose or propagation method because those change in an instant. This software is engineered to gain access to and maintain control over the victim machine, and infiltrating a user’s computer is not difficult. Using a variety of software exploits and social engineering tactics, an attacker will find a way to distribute his malware to his victims. &lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; text-align: center; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;i&gt;Panda Security released a report this week showing that almost &lt;/i&gt;&lt;/span&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: bold; line-height: normal; font-size-adjust: none; font-stretch: normal; letter-spacing: 0px;font-family:Helvetica;font-size:130%;"  &gt;60%&lt;/span&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;i&gt; of all PCs that scanned their computer this month had malware of some kind on their system. &lt;/i&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Once the malware is on the system it seeks communication with its controlling entity. With communication to the controlling entity, any compromised machine can be capable of carrying out any order issued by the botnet controller and any data on the compromised machine can be extracted for use, sale or distribution by the attacker.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;Why did you call it Mariposa?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Our naming of this botnet as Mariposa has been a cause of concern for some. The confusion comes when antivirus companies or those using antivirus, search for the Mariposa name only to find no results. This is because Mariposa refers to the botnet and not the malware it utilizes.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;The malware used by Mariposa goes by many names, and this is part of the problem. Even amongst antivirus groups and within their own companies it is difficult to find a common name for any one family of malware.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Below are some of the names attributed to binaries which are used within Mariposa that are detected by McAfee and Trend. This provides a quality example for the current confusion in botnet malware identification.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;table style="background-color: rgb(255, 255, 255); border-collapse: collapse;" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;McAfee&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica Neue;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;Trend&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Autorun.worm.zzq&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_AUTORUN.ZRO&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Virut.n.gen&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_Generic.DIT&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Downloader-BQP&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;TROJ_Generic.DIT&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Autorun.worm.zzk&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUX.A&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PWS-Zbot&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_PALEVO.T&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Generic.dx!dpk&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_PALEVO.AZ&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Downloader-BRW&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_PALEVO.AS&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Virut.j&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_AUTORUN.EUC&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Autorun.worm.fq&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;WORM_AUTORUN.EPB&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Autorun.worm.c&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;TSPY_ZBOT.SMQ&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;W32/Autorun.worm!bf&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUX.F-1&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Generic.dx!la&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUX.E&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Generic.dx!ha&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUX.D&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Generic.dx!dqe&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUX.C-1&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUX.A-3&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;PE_VIRUT.AP&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 167.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 145.8px; height: 11px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;BKDR_VOTWUP.D&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;It is our hope that perhaps not in our terminology, but with our methodology, that Defence Intelligence can provide some guidance to improve upon the multiple naming convention, allowing a clearer arena for botnet discussion and understanding.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;Why didn’t my AV pick this up?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Using signatures and automated classification, especially when involving heuristics, results in a cacophony of naming options for every distinct variant of a given piece of malware.  That said, many AV companies have had the ability to detect some variations of the malware behind Mariposa long before we became aware of this botnet’s activity.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;With our approach to compromise detection, utilized by our Nemesis software, we can detect the botnet which allows the organization to track down systems affected by the malware, regardless of the variant or antivirus identification ability. While AV companies look at single binaries and classify based upon discrete behavior of code, or the packer that is used to obfuscate the binary, we look at the threat holistically, a macro versus micro approach.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;At Defence Intelligence we consider the code used within Mariposa as only one identifying factor.  Command structure is another. This is defined by domain names, IP addresses, and communication protocols and the fluctuation of each. We also consider the end point organization or individual over the botnet, ultimately any indicator as to who is responsible for the formation and/or control of the hosts affected by this malware.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;With perpetual addition of variants and updates, the reliance on AV detection to keep pace is not advised. Virustotal is a free web based service that analyzes files through multiple antivirus engines, revealing their detection capability of any suspected malware. The following is a virustotal output on one of the malicious binaries related to Mariposa.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;table style="background-color: rgb(255, 255, 255); border-collapse: collapse;" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 89.9px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Antivirus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 77.2px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Version&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 54.6px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Last Update&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 204.9px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Result&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;a-squared&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.5.0.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;AhnLab-V3&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5.0.0.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;AntiVir&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.9.0.228&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Antiy-AVL&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2.0.3.7&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Authentium&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5.1.2.4&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Avast&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.8.1335.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;AVG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;8.5.0.387&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;BitDefender&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;CAT-QuickHeal&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;10&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;ClamAV&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;0.94.1&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Comodo&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;1742&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;DrWeb&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5.0.0.12182&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;eSafe&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.0.17.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Suspicious File&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;eTrust-Vet&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;31.6.6637&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;F-Prot&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.4.4.56&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;F-Secure&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;8.0.14470.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Fortinet&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.120.0.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;GData&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;19&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Ikarus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;T3.1.1.64.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Jiangmin&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;11.0.800&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;K7AntiVirus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.10.800&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Kaspersky&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.0.0.125&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;McAfee&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5686&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;McAfee+Artemis&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5686&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;McAfee-GW-Edition&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;6.8.5&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Heuristic.LooksLike.Worm.Palevo.B&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Microsoft&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;1.4903&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;NOD32&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4273&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Norman&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 1px 2px; width: 83.2px; height: 16px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.22&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;nProtect&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.1.8.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Panda&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;10.0.0.14&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;PCTools&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.4.2.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Prevx&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Rising&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;21.39.42.00&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan.Win32.DangerGL.a&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Sophos&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.44.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Mal/EncPk-IY&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Sunbelt&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.2.1858.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Symantec&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;1.4.4.12&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;TheHacker&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;6.3.4.3.373&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;TrendMicro&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;8.950.0.1094&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;PAK_Generic.001&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 26px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;VBA32&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 26px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.12.10.9&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 26px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 26px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;suspected of Malware-Cryptor.Win32.General.3&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;ViRobot&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.7.24.1851&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;VirusBuster&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.6.5.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.07.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;table style="background-color: rgb(255, 255, 255); border-collapse: collapse;" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td style="padding: 2.5px; width: 434px; height: 11px; background-color: rgb(255, 255, 255);" valign="top"&gt; &lt;p   style="margin: 0px; text-align: center; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;Additional information&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 2.5px; width: 434px; height: 11px; background-color: rgb(255, 255, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;File size: 123392 bytes&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 2.5px; width: 434px; height: 11px; background-color: rgb(255, 255, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;MD5   : 6939c088f59258da7410f66837c62192&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 2.5px; width: 434px; height: 11px; background-color: rgb(255, 255, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;SHA1  : 500bb963602d45584303a4dc3f6fd6052a6752d8&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="padding: 2.5px; width: 434px; height: 11px; background-color: rgb(255, 255, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;SHA256: 996c2667b2bcf86c9c7c20d7c79a3024131c84e0d82d5338db99812830ad778a&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;As you can see, only 6 of the 41 antivirus groups was able to detect the malware. Once again, the naming is inconsistent. Given time however, most antivirus companies are able to identify the same binary.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;table style="background-color: rgb(255, 255, 255); border-collapse: collapse;" cellpadding="0" cellspacing="0"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 89.9px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Antivirus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 77.2px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Version&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 54.6px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Last Update&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 5px; width: 204.9px; height: 11px; background-color: rgb(239, 239, 239);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Result&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;a-squared&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.5.0.24&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;P2P-Worm.Win32.Palevo!IK&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;AhnLab-V3&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5.0.0.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;AntiVir&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.9.1.27&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Antiy-AVL&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2.0.3.7&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Authentium&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5.1.2.4&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Avast&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.8.1351.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.28&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Win32:MalOb-H&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;AVG&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;8.5.0.412&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;SHeur2.ASQE&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;BitDefender&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan.Generic.2263367&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;CAT-QuickHeal&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;10.00&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;ClamAV&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;0.94.1&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Comodo&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2469&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Heur.Suspicious&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;DrWeb&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5.0.0.12182&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan.Packed.541&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;eSafe&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.0.17.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Suspicious File&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;eTrust-Vet&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;31.6.6768&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;F-Prot&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.5.1.85&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;F-Secure&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;8.0.14470.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Packed.Win32.Krap.y&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Fortinet&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.120.0.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;GData&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;19&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan.Generic.2263367&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Ikarus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;T3.1.1.72.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;P2P-Worm.Win32.Palevo&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Jiangmin&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;11.0.800&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.27&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;K7AntiVirus&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.10.856&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;P2P-Worm.Win32.Palevo.jaz&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Kaspersky&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;7.0.0.125&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Packed.Win32.Krap.y&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;McAfee&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5755&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.28&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;W32/Autorun.worm.zzq&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;McAfee+Artemis&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;5755&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.28&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;W32/Autorun.worm.zzq&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;McAfee-GW-Edition&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;6.8.5&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Heuristic.LooksLike.Win32.NewMalware.B&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Microsoft&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;1.5005&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.23&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;VirTool:Win32/Obfuscator.FL&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;NOD32&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4467&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;a variant of Win32/Kryptik.LR&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Norman&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;6.01.09&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;nProtect&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.1.8.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan/W32.Agent.123392.EB&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Panda&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;10.0.2.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.28&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trj/CI.A&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;PCTools&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.4.2.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Prevx&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Medium Risk Malware&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Rising&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;21.49.14.00&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan.Win32.DangerGL.a&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Sophos&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.45.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Mal/EncPk-IY&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Sunbelt&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.2.1858.2&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Trojan.Win32.Generic!BT&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;Symantec&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;1.4.4.12&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Spyware.Screenspy&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;TheHacker&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;6.5.0.2.021&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.28&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;TrendMicro&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;8.500.0.1002&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;WORM_AUTORUN.ZRO&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;VBA32&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;3.12.10.11&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;Malware-Cryptor.Win32.General.3&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;ViRobot&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.9.29.1963&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px; background-color: rgb(227, 241, 255);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 91.9px; height: 10px; background-color: rgb(230, 230, 230);" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;b&gt;VirusBuster&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 79.2px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;4.6.5.0&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 56.6px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;2009.09.29&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;td style="border: 0.2px solid rgb(205, 205, 205); padding: 4px; width: 206.9px; height: 10px;" valign="top"&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Courier New;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;-&lt;/span&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Courier New;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;File size: 123392 bytes&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;MD5   : 6939c088f59258da7410f66837c62192&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;SHA1  : 500bb963602d45584303a4dc3f6fd6052a6752d8&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;SHA256: 996c2667b2bcf86c9c7c20d7c79a3024131c84e0d82d5338db99812830ad778a&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;So I just need to wait for an update to my AV then?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;If malware were to remain static and unchanged an identification and removal option would eventually be provided by  your antivirus of choice. At that point, however, the malware has likely fulfilled any of its initial goals and its removal would be a futile and meaningless task. Unfortunately, Mariposa does not use static malware.  &lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Malware authors often update their code to evade detection as well as try different configurations, all of which result in a new malware variant. Mariposa has over 70 variants, resulting in a persistent and dynamic botnet.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;One example is this update file recently dropped onto a compromised system as instructed by the Mariposa botnet controller. Virustotal shows that only two of the 41 AV groups currently detect it.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;File svc.exe received on 2009.09.29 15:27:36 (UTC)&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Current status: finished &lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Times;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;Result: &lt;/span&gt;&lt;span style="font-size:130%;"&gt;2&lt;/span&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;/41 (4.88%)&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Times;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;http://www.virustotal.com/analisis/7987d324cedbfeb9df94f7cbaf0ed2091431d6443c5b5fbff6ad7a7c380bf8d3-1254238056&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;A signature may soon come out for this code from your AV vendor, but by that time, a new piece of code may be written and downloaded that bypasses AV yet again.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;Well, how do I stop this thing?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;As IPs, ports, and domains involved in the command structure of Mariposa are changing, it becomes difficult for security administrators to mitigate the ability of this botnet. At this time we suggest an approach of tracking down the compromised systems rather than establish rules to block the communication to the botnet controller. UDP connections are still actively used for Mariposa communication, so observance of your network activity is the best place to start. If one system is frequently sending data across the outbound UDP protocol, regardless of port, mark it  as suspicious and consider removing it from the network. Your own remediation technique is up to you but reimaging, though time consuming, is the only confident way to cleanse a compromised machine.&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 11px;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt; &lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;&lt;b&gt;So what is Defence Intelligence doing about this?&lt;/b&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal; min-height: 14px;font-family:Helvetica;font-size:12px;"&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p   style="margin: 0px; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-size-adjust: none; font-stretch: normal;font-family:Helvetica;font-size:9px;"&gt;&lt;span style="letter-spacing: 0px;font-size:130%;" &gt;As before we are contacting companies that have been affected by Mariposa. We also have other researchers and companies looking to help out in this mitigation effort and the formation of a small working group with these individuals is taking place. Updates on this and other Mariposa details will follow.&lt;/span&gt;&lt;/p&gt;&lt;div&gt;&lt;span class="Apple-style-span" style=";font-family:Helvetica,serif;font-size:78%;"  &gt;&lt;span class="Apple-style-span"  style="font-size:9;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt;&lt;br /&gt;var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");&lt;br /&gt;document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;script type="text/javascript"&gt;&lt;br /&gt;try {&lt;br /&gt;var pageTracker = _gat._getTracker("UA-11400163-2");&lt;br /&gt;pageTracker._trackPageview();&lt;br /&gt;} catch(err) {}&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-3389773380246893315?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://defintel.com/mariposa.shtml' title='Mariposa Defined'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/3389773380246893315/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=3389773380246893315' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3389773380246893315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3389773380246893315'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/10/mariposa-defined_01.html' title='Mariposa Defined'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-6091611403563388355</id><published>2009-09-28T11:42:00.002-04:00</published><updated>2009-09-28T11:43:05.223-04:00</updated><title type='text'>Mariposa FAQ</title><content type='html'>&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;&lt;span style="color: rgb(0, 0, 0);"&gt;In response to a number of questions, we have prepared a short Q&amp;amp;A.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);"&gt;Q. How big is the botnet?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. We estimate there to be between 150 to 200k compromised systems across 40,000 unique networks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. What does it do?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. It is designed for information theft, stealing passwords and personal credentials, but malware like this can be configured to do anything the attacker wants.&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. Who created it?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. That is still being investigated and we will work with law enforcement on the details.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. What banks/companies are involved? Who have you talked with?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. We can't release any specific names. We have contacted or attempted to contact all critical groups affected.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. When did you find it?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. We have been tracking it since May of this year.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. What does Defence Intelligence do?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. We specialize in compromise detection and prevention. &lt;a href="http://www.defintel.com"&gt;www.defintel.com&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. How does it spread?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. By default, the malware is designed to spread across instant messenger programs, USB keys, and P2P networks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. What is Mariposa's growth rate?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. It's current growth rate is 7,000 new compromised systems each day.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. Does AV detect it?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. With 70 variants, some of them will be detected and some won't.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(102, 102, 102);font-family:arial;" &gt;Q. How to detect and fix it?&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;" &gt;A. Until AV catches up, removal techniques will have to be determined by the individual.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-6091611403563388355?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/6091611403563388355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=6091611403563388355' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6091611403563388355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6091611403563388355'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/09/mariposa-faq.html' title='Mariposa FAQ'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-4750633376422076986</id><published>2009-09-23T18:00:00.003-04:00</published><updated>2009-09-23T18:09:34.542-04:00</updated><title type='text'>Half of Fortune 100 Companies Compromised by New Information Stealing Trojan</title><content type='html'>&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;The Butterfly Effect: Say Hello to Mariposa&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Defence Intelligence has been tracking the growth of a new information stealing botnet we’ve named Mariposa. 50 of the world’s Fortune 100 companies are actively participating in this botnet as well as hundreds of government agencies, financial institutions, universities and corporate networks worldwide.&lt;br /&gt;&lt;br /&gt;Since its discovery in May of 2009 we’ve identified Mariposa activity in tens of thousands of unique corporate networks. Over 70 variants have been identified with varying degrees of security and purpose, including code injection into known processes,  email address harvesting, and additional malware downloads. The purpose behind so many variants may only be functionality differences or efforts at avoiding AV detection, but it does not reveal the number of controllers or the exact motivation behind the overall threat.&lt;br /&gt;&lt;br /&gt;Believed to stem from the butterfly bot kit, formerly sold at bfsecurity.net, this botnet is successfully spreading across thousands of corporate networks, just as it was designed to do. From the bfsecurity.net site, butterflybot is a&lt;br /&gt;&lt;br /&gt;“Security tool designed to stealthy run on winnt based systems (win2k to winvista) and to stealthy and efficiently spread with 3 spreaders, which were specially designed and improved compared to already known public methods.[sic]” The three spreaders are MSN, USB, and P2P. Listed P2P networks were “ares, bearshare, imesh, shareaza, kazaa, dcplusplus, emule, emuleplus, limewire.[sic]”&lt;br /&gt;&lt;br /&gt;Other methods may now be in place for propagation as well as capabilities for the bf botkit, but the original add-on features included Firefox and IE password harvesting, and TCP/UDP flooding. NetBIOS worm propagation and email address harvesting also appear to have become common additions.&lt;br /&gt;&lt;br /&gt;Detection&lt;br /&gt;&lt;br /&gt;Analysis of this botnet has revealed only one commonly identifiable piece of information.  Companies wishing to determine if they have been compromised can watch for DNS queries to the domain:&lt;br /&gt;&lt;br /&gt;butterfly.sinip.es&lt;br /&gt;&lt;br /&gt;Additionally, monitor for high DNS query volume to domains containing the keywords of “butterfly” or “bf” and/or mass UDP connection attempts to any of the following IPs:&lt;br /&gt;&lt;br /&gt;96.9.170.133&lt;br /&gt;62.128.52.191&lt;br /&gt;87.106.179.75&lt;br /&gt;82.165.205.104&lt;br /&gt;212.48.121.23&lt;br /&gt;66.96.201.74&lt;br /&gt;&lt;br /&gt;For further information regarding this botnet, please contact info@defintel.com.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-4750633376422076986?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/4750633376422076986/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=4750633376422076986' title='43 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4750633376422076986'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4750633376422076986'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/09/half-of-fortune-100-companies.html' title='Half of Fortune 100 Companies&lt;br&gt; Compromised by New Information &lt;br&gt;Stealing Trojan'/><author><name>Davis</name><uri>http://www.blogger.com/profile/13713470016162233081</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>43</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-4686032710573988998</id><published>2009-09-11T14:30:00.014-04:00</published><updated>2009-09-11T14:47:34.012-04:00</updated><title type='text'>Riding the Green Wave.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nMx-DUJRrDc/SqqaqvdjViI/AAAAAAAAACE/0eaH_JG1EmE/s1600-h/Picture+3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 62px;" src="http://2.bp.blogspot.com/_nMx-DUJRrDc/SqqaqvdjViI/AAAAAAAAACE/0eaH_JG1EmE/s320/Picture+3.png" alt="" id="BLOGGER_PHOTO_ID_5380282763933079074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;Considering how many people are talking about what is and is not good for the health of this planet and that everyone should be doing their part to help the environment, you shouldn't be surprised to hear that even cyber crime is going green.&lt;/span&gt;  &lt;p  style="margin-bottom: 0cm;font-family:arial;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_nMx-DUJRrDc/SqqaG2lpDDI/AAAAAAAAAB0/XmoyQ48W4xE/s1600-h/Picture+2.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 150px;" src="http://1.bp.blogspot.com/_nMx-DUJRrDc/SqqaG2lpDDI/AAAAAAAAAB0/XmoyQ48W4xE/s200/Picture+2.png" alt="" id="BLOGGER_PHOTO_ID_5380282147370765362" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;Staying relevant and socially aware are key in effective malware propagation, so criminals are adding `green` gimmickry to their rogue AV sales pitch. The cyber criminals' have marketing departments too. Cyber criminals have re-branded thei&lt;/span&gt;&lt;span style="font-size:100%;"&gt;r fake antivirus software so that it appeals to the environmentalists by having an "Environment care program. $2 from every &lt;/span&gt;&lt;span style="font-size:100%;"&gt;sale we make will be sent on saving green forests in Amazonia." It seems they need to work on their English&lt;/span&gt;&lt;span style="font-size:100%;"&gt; translat&lt;/span&gt;&lt;span style="font-size:100%;"&gt;ions.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0cm;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;They also claim that when your computer has malware on it, your machine slows down, which means that it takes you longer to do things, and it uses more power. Using Green AV, they say, will clean and speed up your computer so that you don't need to go out and buy a new one! Wow, that is really nice of them, and for only $99USD !!! What a deal! I am saving the environment one piece&lt;/span&gt;&lt;span style="font-size:100%;"&gt; of malware at a time.&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0cm;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;Of the people that do end up downloading the software it does an unrequested fake scan and shows you bogus results that indicate that your machine is infected with a plethora of various trojans and does the opposite of what they say it will do, opening up a backdoor for them to have complete control of your machine.&lt;/span&gt;&lt;/p&gt;   &lt;p  style="margin-bottom: 0cm;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;It's humorous that they have a pict&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_nMx-DUJRrDc/SqqaSV0k-jI/AAAAAAAAAB8/2ZD35sj1jE4/s1600-h/Picture+5.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 256px; height: 187px;" src="http://2.bp.blogspot.com/_nMx-DUJRrDc/SqqaSV0k-jI/AAAAAAAAAB8/2ZD35sj1jE4/s320/Picture+5.png" alt="" id="BLOGGER_PHOTO_ID_5380282344733473330" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;ure of a secure lock at the top of the page&lt;/span&gt;&lt;span style="font-size:100%;"&gt; that says "Secure SLL Connection 100% Privacy Guarantee." I am unsure what an SLL connection is but I believe &lt;/span&gt;&lt;span style="font-size:100%;"&gt;they mean SSL (Secure Socket Layer). 100% Privacy when giving your information to the criminals is also false security. I guess this is so &lt;i&gt;other&lt;/i&gt; criminals can't get your information... real secure.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0cm;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;The criminal underworld has evolved over the years, offering various product improvements like bug testing, constant updates to avoid detection, and even Windows-like "send error report" pop-ups that send crash information back to the malware creator so they can improve on their faults. I hate to give credit to the enemy, but they seem to be doing a better job than most of the good guys that are trying to stop them.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0cm;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;That being said, you should be scared, or if you are too proud to be scared, you should at least be concerned. With detection rates as low as they are, the AV companies are being overwhelmed by over thirty thousand new pieces of malware a day.&lt;/span&gt;&lt;/p&gt;  &lt;p face="arial" style="margin-bottom: 0cm;"&gt;&lt;span style="font-size:100%;"&gt;A Finjan report from March estimated that fake antivirus distributors can make more than $10,000 a day. PandaLabs estimates there could be as many as 35 million computers infected per month with rogue antivirus programs.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0cm; font-family: arial;"&gt;&lt;span style="font-size:100%;"&gt;Fake antivirus software is everywhere and this environmentally focused approach will likely be 'recycled' by other criminal proponents of its spread. Remember though, just because it says it's `green` it doesn't mean it is good for you.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0cm; font-family: arial;"&gt;B.Kilrea&lt;br /&gt;Threat Analyst&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-4686032710573988998?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.defenceintelligence.ca' title='Riding the Green Wave.'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/4686032710573988998/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=4686032710573988998' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4686032710573988998'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4686032710573988998'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/09/riding-green-wave.html' title='Riding the Green Wave.'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_nMx-DUJRrDc/SqqaqvdjViI/AAAAAAAAACE/0eaH_JG1EmE/s72-c/Picture+3.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-105944000999532055</id><published>2009-09-04T14:45:00.009-04:00</published><updated>2009-09-22T10:06:30.887-04:00</updated><title type='text'>The Future is Friendly</title><content type='html'>&lt;div  style="text-align: justify; color: rgb(0, 0, 0);font-family:arial;"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;Just as so-called 'early adopters' and techno-geeks are always on the lookout for the latest and greatest in flashy technology, sophisticated botnet administration suites are the current must-have for cybercriminals. As bot malware becomes increasingly easy to propagate and successfully compromise massive network linked machines, the problem becomes not how to create a botnet, but how to control it. These administration suites provide better handling, control, and efficient management than their predecessors, giving their users a leg up on the competition.&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;The Fragus Exploit kit is a newcomer to the market, having improved upon the trend started by authors of such suites as the Liberty Exploit System and the Exp Eleonore Pack, Fragus is a grab bag of exploits for vulnerabilities in multiple software components. Similarities abound among these suites, from which vulnerabilities they exploit, to the layout and handling of the control panel, to the domains and IPs from which they can be downloaded. Liberty and Eleonore are both slightly older exploit kits whose latest versions have been updated to include much of the same functionality and easy-of-use as Fragus. &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;For the low price of 800 USD, Fragus is designed to simplify the administration of your bot network. It boasts support for English and Russian, statistical breakdowns of your botnet by browser, operating system (including version), by country, and by what's euphemistically referred to as your "clients".&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_nMx-DUJRrDc/SqFg8_0AaPI/AAAAAAAAAAc/nLX89b7L5pE/s1600-h/Blog_Fragus.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 310px; height: 320px;" src="http://3.bp.blogspot.com/_nMx-DUJRrDc/SqFg8_0AaPI/AAAAAAAAAAc/nLX89b7L5pE/s320/Blog_Fragus.png" alt="" id="BLOGGER_PHOTO_ID_5377686031095064818" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;font-size:100%;"&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Fragus comes pre-installed and ready to exploit:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MDAC&lt;/span&gt; - &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS07-009.mspx"&gt;MS07-009&lt;/a&gt;, a vulnerability in MS Data Access Components which can allow remote code execution.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;PDF&lt;/span&gt; - Targets 3 vulnerabilities in Acrobat Reader, util.printf, Collab.getIcon, and Collab.collectEmailInfo (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2992"&gt;CVE-2008-2992&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0927"&gt;CVE-2009-0927&lt;/a&gt;, and &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659"&gt;CVE-2007-5659&lt;/a&gt;, respectively)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;DirectShow&lt;/span&gt; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx"&gt;MS09-032&lt;/a&gt;, exploits the MS Video (DirectShow) ActiveX Control vulnerability.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Internet Explorer&lt;/span&gt; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/MS09-002.mspx"&gt;MS09-002&lt;/a&gt;, a critical vulnerability in IE7 that allows for memory corruption and remote code execution.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Spreadsheet&lt;/span&gt; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx"&gt;MS09-043&lt;/a&gt;, an ActiveX Control vulnerability is MS Office Web Components.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;AOL WinAmp&lt;/span&gt; - another system vulnerable to an ActiveX Control exploit, (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6250"&gt;CVE-2007-6250&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Snapshot&lt;/span&gt; - &lt;a href="http://www.microsoft.com/technet/security/bulletin/MS08-041.mspx"&gt;MS08-041&lt;/a&gt;, an exploit targeted at MS Access Snapshot Viewer's ActiveX Control vulnerability.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Flash&lt;/span&gt; - targets an integer flow vulnerability in Adobe Flash Player (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0071"&gt;CVE-2007-0071&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div  style="text-align: justify;font-family:arial;"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;Some of the vulnerabilities have been patched for months or even years but their inclusion here indicates a high probability that numerous systems remain unpatched. Of greater interest is the MS09-043 vulnerability which, as of Fragus' release, was only one month old. Increasingly, criminals are making use of recently released exploits. Obviously this tactic greatly increases their chances of success as many (if not most) people fall behind in their updates and will likely still be vulnerable to such a recent exploit. &lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;For people concerned over spending $800 on an exploit pack only to have its payload identified by antivirus programs, for an extra $150 you will receive a proprietary encryption program specifically designed to evade detection.&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;Unsurprisingly, many of the domains and IPs at which Fragus is available have at one time or another hosted other sorts of malware, including the LIberty Exploit System, the Zeus trojan, and various other PDF and flash exploits.&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;"&gt; The future of botnet administration is here now... and it sure is easy to use.&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="color: rgb(0, 0, 0);font-family:arial;font-size:100%;"&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;Meaghan Molloy&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;Threat Analyst&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;For a far more eloquent presentation of the facts, check out &lt;a href="http://blog.purewire.com/bid/19509/The-Fragus-Exploit-Kit"&gt;Paul Royal's&lt;/a&gt; work at Purewire.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-105944000999532055?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/105944000999532055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=105944000999532055' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/105944000999532055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/105944000999532055'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/09/fragus-exploit-kit.html' title='The Future is Friendly'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_nMx-DUJRrDc/SqFg8_0AaPI/AAAAAAAAAAc/nLX89b7L5pE/s72-c/Blog_Fragus.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-343520253975200420</id><published>2009-04-03T10:55:00.005-04:00</published><updated>2009-04-03T11:08:33.517-04:00</updated><title type='text'>ConfickerC Update</title><content type='html'>&lt;div&gt;OK just a quick update regarding ConfickerC numbers. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I have seen published numbers that are all over the place *cough IBM/ISS cough*. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Over the last 30 hours or so we recorded 9,795,101 raw (not unique IP) http connections to the sinkhole.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; As unique IPs go we recorded a total of 1,071,132 unique IPs from with in that 9+M. Now keep in mind, we have to think about DHCP churn, NAT (Firewalls, gateways, proxies, etc) So the number is obviously not a 100% true representation.  &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here is what the PER HOUR numbers look like from the sinkhole:&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_WzLs8uAsBGo/SdYj0waZDoI/AAAAAAAAAAM/5Rl9201IZGI/s1600-h/ConfickerC.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 245px;" src="http://1.bp.blogspot.com/_WzLs8uAsBGo/SdYj0waZDoI/AAAAAAAAAAM/5Rl9201IZGI/s400/ConfickerC.jpg" alt="" id="BLOGGER_PHOTO_ID_5320479399040585346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-343520253975200420?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/343520253975200420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=343520253975200420' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/343520253975200420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/343520253975200420'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/04/confickerc-update.html' title='ConfickerC Update'/><author><name>Davis</name><uri>http://www.blogger.com/profile/13713470016162233081</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_WzLs8uAsBGo/SdYj0waZDoI/AAAAAAAAAAM/5Rl9201IZGI/s72-c/ConfickerC.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-7134138707443663254</id><published>2009-03-10T12:55:00.007-04:00</published><updated>2009-03-11T10:46:49.165-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='anti virus'/><category scheme='http://www.blogger.com/atom/ns#' term='pifts'/><title type='text'>PIFTS</title><content type='html'>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;Something is rotten in the state of security.&lt;br /&gt;&lt;br /&gt;Users of Symantec's Norton AV have been reporting instances of a file named PIFTS.exe trying to connect out to the Norton updates.&lt;br /&gt;&lt;br /&gt;This wouldn't be news in and of itself, but it seems that Symantec doesn't want to discuss the issue. All questions regarding PIFTS are removed from the message board within minutes of being posted. Some users have been banned after attempting to repost.&lt;br /&gt;&lt;br /&gt;Since they can't turn to Symantec for answers, many users have turned to the communal knowledge of the web. Unfortunately, the bad guys have also noticed the influx of searches for PIFTS.exe and some of the top results in Google are actually malicious, attempting to infect any visitors with rogue anti-virus Malware. DO NOT DOWNLOAD ANYTHING from those sites.&lt;br /&gt;&lt;br /&gt;ThreatExpert has a breakdown of PIFTS and its attempt to phone home &lt;a href="http://www.threatexpert.com/report.aspx?md5=91b564d825a3487ae5b5fafe57260810"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;VirusTotal shows no &lt;a href="http://www.virustotal.com/analisis/734465e30a6ee6d6c493471d77940f4c"&gt;hits&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Brian Krebs @ The Washington Post is trying to get some &lt;a href="http://voices.washingtonpost.com/securityfix/2009/03/symantec_users_complain_of_mys.html#comments"&gt;answers&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;SANS Internet Storm Center &lt;a href="http://isc.sans.org/diary.html?storyid=5992"&gt;writes&lt;/a&gt; that they've been contacted by a Symantec employee who claimed ownership of the file and tried to make clear that it isn't intended to do any harm.&lt;br /&gt;&lt;br /&gt;Nice of them to respond...&lt;br /&gt;&lt;br /&gt;But won't they let people talk about it on the msg boards?&lt;br /&gt;&lt;br /&gt;Why the secrecy Symantec?&lt;br /&gt;&lt;br /&gt;**Update** (courtesy of &lt;a href="http://blog.washingtonpost.com/securityfix/"&gt;Brian Krebs&lt;/a&gt; @ The Washington Post)&lt;br /&gt;&lt;br /&gt;"David Cole, senior director of product management at Symantec, said the PIFTS file was part of a 'diagnostics patch' shipped to Norton customers on Monday evening. The purpose of the update, Cole said, was to help determine how many customers would need to be migrated to newer versions of its software as more Windows users upgrade to Windows 7."&lt;br /&gt;&lt;br /&gt;As to why Symantec was deleting forums posts and banning users for mentioning PIFTS, Cole says, "hundreds of new users began registering on the forum, leaving inane and sometimes abusive comments."&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:Times New Roman,times,serif;font-size:100%;"  &gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;This is a lame excuse. Though the forums do seem to have been hit by the 4chan crowd, the first people to ask questions were very polite and straightforward. They asked simple questions, like 'hey, how come part of your software wants to access the Internet?'&lt;br /&gt;&lt;br /&gt;Not exactly ban-worthy behaviour.&lt;br /&gt;&lt;br /&gt;A forum moderator could have simply (easily!) answered the question and closed the thread. Wouldn't that have saved everyone a lot of trouble?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-7134138707443663254?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/7134138707443663254/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=7134138707443663254' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/7134138707443663254'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/7134138707443663254'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/03/pifts.html' title='PIFTS'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-3820513826894629802</id><published>2009-03-03T10:47:00.004-05:00</published><updated>2009-03-03T11:13:05.695-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='anti virus'/><title type='text'>Coin Toss</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: trebuchet ms;" href="http://tinyurl.com/akvagb" rel="nofollow" target="_blank"&gt;http://tinyurl.com/akvagb&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Go. Read the article.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Anti-virus software vendors like to proclaim that their products achieve success rates in the 90%+ range. This is false and misleading. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;It is inconceivable that end users (and many corporate entities) still believe that AV software is the catch all for security.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;A 50% success rate is unacceptable. It is a coin toss - 50/50 chance - that your network is secure. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;"&lt;/span&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;The average delay in detection and remediation was 54 days."&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;54 days?! Two months?!&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;The bottom line here is that Malware created for non-commercial purposes simply does not exist anymore. It hasn't in over two years. &lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;Modern Malware is specifically designed to operate quietly and unobtrusively for as long as possible. The bad guys are after our social insurance numbers, credit card numbers, bank account details, credit equity, customer lists, a jump on the quarterly earnings, our emails, online payment accounts, access to our social network of friends, ANYTHING they can get their hands on.&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;Think about it: the average delay in detection is 54 days. For almost two months the bad guys have access to your system. &lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;This isn't like having your house robbed. &lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;It's like having your house broken into and the robbers moving in and hiding in your closet for two months. &lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;From home users to large corporate networks, we must - MUST - move beyond our tired notions of network security. The bad guys are always evolving, adapting their Malware to evade detection and improve levels of compromise. Why haven't the good guys evolved?&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;The numbers speak for themselves:&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;"About 3 to 5 percent of all systems in an enterprise are infected with bot-related malware -- even within organizations running up-to-date antimalware tools."&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;"Antivirus software immediately discovered only 53 percent of malware samples."&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;"Another 32 percent were found later on, and 15 percent were not detected at all."&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;Now you may be thinking that 15% doesn't sound like a lot, that maybe that's an acceptable level of risk. Consider this:&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;Security researchers around the world analyze anywhere from 20-30,000 pieces of Malware every day. Every day!&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;The Shadowserver Foundation has analyzed over 19 million Malware samples in the past 12 months alone. &lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;15% of 19 million is a big number. &lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"  style="font-family:trebuchet ms;"&gt;You really want to take that chance?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="smalltext"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="smalltext"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-3820513826894629802?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/3820513826894629802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=3820513826894629802' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3820513826894629802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/3820513826894629802'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/03/coin-toss.html' title='Coin Toss'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-2056667683427461081</id><published>2009-02-20T16:30:00.003-05:00</published><updated>2009-02-20T19:01:44.148-05:00</updated><title type='text'>Building a Botnet</title><content type='html'>&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-7c5d1a61bfaacf45" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v14.nonxt6.googlevideo.com/videoplayback?id%3D7c5d1a61bfaacf45%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329868997%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D56D1C2A59ABC31F7C1D0D0378B42192FFAD8080B.4F4396A2A51E08FAF1AF828E935E017E7D317F8C%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D7c5d1a61bfaacf45%26offsetms%3D5000%26itag%3Dw160%26sigh%3D3ZgJyOpqL-G2jz6CDnxFr_hOEVM&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v14.nonxt6.googlevideo.com/videoplayback?id%3D7c5d1a61bfaacf45%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329868997%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D56D1C2A59ABC31F7C1D0D0378B42192FFAD8080B.4F4396A2A51E08FAF1AF828E935E017E7D317F8C%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D7c5d1a61bfaacf45%26offsetms%3D5000%26itag%3Dw160%26sigh%3D3ZgJyOpqL-G2jz6CDnxFr_hOEVM&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-2056667683427461081?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=7c5d1a61bfaacf45&amp;type=video%2Fmp4' length='0'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/2056667683427461081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=2056667683427461081' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2056667683427461081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2056667683427461081'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/02/building-botnet.html' title='Building a Botnet'/><author><name>Julie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-4381973278584186746</id><published>2009-01-30T12:12:00.003-05:00</published><updated>2009-01-30T12:18:34.163-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnets'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>Is your computer watching you?</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;a href="http://www.secureworks.com/research/blog/index.php/2009/01/20/ozdok-watching-the-watchers/"&gt;SecureWorks&lt;/a&gt; has a posting up discussing the Ozdok/Mega-D trojan and its ability to capture screenshots on the systems it's infected. We've been talking about this for months! Ozdok is certainly not the only trojan with this ability, and the researchers are specifically talking about screenshots, but what about systems with webcams?&lt;br /&gt;&lt;br /&gt;Think the bad guys know how to turn those on?&lt;br /&gt;&lt;br /&gt;Check out the video posted in our &lt;a href="http://www.facebook.com/"&gt;Facebook &lt;/a&gt;group and find out!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-4381973278584186746?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/4381973278584186746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=4381973278584186746' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4381973278584186746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4381973278584186746'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/01/is-your-computer-watching-you.html' title='Is your computer watching you?'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-6013144250259421409</id><published>2009-01-28T20:36:00.005-05:00</published><updated>2009-01-28T21:17:52.387-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='the team'/><category scheme='http://www.blogger.com/atom/ns#' term='defintel'/><category scheme='http://www.blogger.com/atom/ns#' term='facebook'/><category scheme='http://www.blogger.com/atom/ns#' term='twitter'/><title type='text'>24/7</title><content type='html'>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;&lt;br /&gt;We're opening the office doors:&lt;br /&gt;&lt;br /&gt;Defintel's on &lt;a href="http://twitter.com/defintel"&gt;Twitter&lt;/a&gt;. Check it out, drop us a line.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://facebook.com/"&gt;Facebook &lt;/a&gt;too. Join the Defintel group for botnet building videos, photos, and a chance to ask us questions about computers, security, videos games, comics, and just about anything else.&lt;br /&gt;&lt;br /&gt;From the whole Definel team:&lt;br /&gt;&lt;br /&gt;Welcome!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-6013144250259421409?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/6013144250259421409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=6013144250259421409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6013144250259421409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/6013144250259421409'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2009/01/247.html' title='24/7'/><author><name>Defence Intelligence</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-8361494055408225461</id><published>2008-12-17T07:36:00.006-05:00</published><updated>2009-01-22T15:25:27.689-05:00</updated><title type='text'>Explorer Exiled</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;There is a 0day exploit currently exploiting a critical flaw in Microsoft's Internet Explorer.&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;If this is the first you're hearing of this flaw, check out the link below to hear Defintel's CEO, Chris Davis explain the situation:&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;a href="http://watch.ctv.ca/news/library/#clip122262"&gt;CTV News - Exploiting Explorer&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;p&gt;Researchers estimate that more than 10,000 sites are compromised. While in-the-wild exploits are currently targeting IE 7 on Windows XP SP2 and SP3, Windows Server 2003 SP1 and SP2, Windows Vista (including SP1) and Windows Server 2008, it's important to remember that all versions of Internet Explorer, from IE5 all the way to IE8 Beta 2, are affected.&lt;/p&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;If a user visits a compromised site, malicious JavaScript code is injected into the browser, and Malware is downloaded onto the user's computer. The Malware that gets installed on the user's computer will likely remain nearly invisible to the average user. The goal of the attacker is not to disrupt a user's online experience, but rather to remain inconspicuous for as long as possible. The Malware allows the attacker complete access to user's computer and  allows him to track everything you type into your keyboard. &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Visit your legitimate online banking site and enter your user information? Now he's got it. &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Visit your favourite social networking site and chat with some friends? Now he's got that too.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Microsoft intends to release a critical patch today, the second patch coming on Exploit Wednesday instead of Patch Tuesday in as many months. Back in October, Microsoft was forced to release an out-of-band patch to mitigate the extremely critical flaw in several Windows OS'.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;In the meantime, users should use other browsers - FireFox, Chrome, Safari - whatever you like! Just not IE. &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;The general public is completely ill-equipped to deal with security events. Who knows how long it will be before the AV companies have signatures developed for this new exploit.  And Microsoft surely isn't losing any market share over yet another security debacle.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Why do we still treat online security as though the Internet only encompasses six guys at Berkeley? Everyone is online, from 5 year old girls to 95 year old men - they can't all be expected to keep up to date with these vulnerabilities and exploits. &lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;So, how do we help them?&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-8361494055408225461?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://watch.ctv.ca/news/top-picks/exploiting-explorer/' title='Explorer Exiled'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/8361494055408225461/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=8361494055408225461' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8361494055408225461'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/8361494055408225461'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2008/12/explorer-exiled.html' title='Explorer Exiled'/><author><name>defintel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-2153694152194629816</id><published>2008-11-30T20:48:00.003-05:00</published><updated>2008-11-30T21:46:57.876-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='anti virus'/><category scheme='http://www.blogger.com/atom/ns#' term='kaspersky'/><category scheme='http://www.blogger.com/atom/ns#' term='microsoft'/><title type='text'>The Enemy Within</title><content type='html'>&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;Two weeks ago, users of AVG's virus scanner awoke to a nasty surprise: their supposed security software had been updated to identify the file named user32.dll as malicious. Those people most keen to protect their computer systems followed the instructions as directed and deleted the file - only to find that they were now stuck in an endless cycle of reboots.&lt;br /&gt;&lt;br /&gt;User32.dll is a core Windows file; and not, as identified by AVG, a Trojan Horse named PSW.Banker4.APSA or Generic9TBN. This is not the first time AVG has struggled with misidentifying Malware, nor is it the first time an Anti Virus company has recommended users remove core Windows files.&lt;br /&gt;&lt;br /&gt;In December of last year, Anti Virus company Kaspersky Labs decided that a Virus existed within Windows Explorer, the graphical user interface for Windows itself. Thankfully, Kaspersky managed to catch the error before the damage was too widespread; though, I imagine the employees at the UK enterprise that was affected would tell a different story.&lt;br /&gt;&lt;br /&gt;Even Microsoft is guilty of such casual coding. In 2007, Microsoft's OneCare, an Anti Virus product, when used with Internet Explorer 7, was flagging Google's Gmail as a Virus. Even Microsoft's own product weren't safe, with OneCare regularly quarantining or deleting all of the email in a user's inbox.&lt;br /&gt;&lt;br /&gt;AV companies tout their wares as the silver bullet for personal protection. You know this isn't true. I know this isn't true. So, why doesn't everybody else?&lt;br /&gt;&lt;br /&gt;It was bad enough that the generic, non-technical computer user didn't know that his Anti Virus software is only protecting him from a small percentage of modern threats. Now we also have to let them in on the secret that their "protection" might sometimes do more harm than good.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-2153694152194629816?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://securityandthe.net/2008/11/10/avg-virus-scanner-removes-critical-windows-file/' title='The Enemy Within'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/2153694152194629816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=2153694152194629816' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2153694152194629816'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/2153694152194629816'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2008/11/enemy-within.html' title='The Enemy Within'/><author><name>defintel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-4632509646692587114</id><published>2008-10-27T12:45:00.005-04:00</published><updated>2008-10-27T13:18:27.388-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>Fun with Dick and Jane</title><content type='html'>&lt;div style="text-align: justify;"&gt;Fail too fast in bed?&lt;br /&gt;&lt;br /&gt;Looking to revive your sleep desires?&lt;br /&gt;&lt;br /&gt;What is money in comparison to your potency?&lt;br /&gt;&lt;br /&gt;To anyone with an email address those phrases might seem awfully familiar. I'm talking about spam: the scourge of system administrators, the friendly pharmacy to the misinformed. It arrives unrequested, unavoidable, unimaginably hilarious. Now, you too can get in on the game, spamming friends, family, and foes alike thanks to the user-friendly Set-X Mail Service, courtesy of the Set-X Corporation.&lt;br /&gt;&lt;br /&gt;Straight from the press release announcing the service:&lt;br /&gt;&lt;br /&gt;“- Flexible and convenient Web based interface, detailed statistics while sending, changing any settings (mail databases, texts, macros)&lt;br /&gt;&lt;br /&gt;- User-friendly web based interface - start spamming from day one&lt;br /&gt;&lt;br /&gt;- Automatic “spamming capabilities” assessments of the bot allowing you to think about your business and not about the technical details behind it&lt;br /&gt;&lt;br /&gt;- Daily malware updates, four programmers allocated for every server, sending automatic ICQ notifications whenever the malware gets updated&lt;br /&gt;&lt;br /&gt;- Automatic optimization of the spam campaign by first allocating the bots with clean IP reputation&lt;br /&gt;&lt;br /&gt;- Optional is the option to chose whether or not a dedicated “spamming engineer” should be allocated to your server&lt;br /&gt;&lt;br /&gt;- His responsibilities include introducing a higher number of bots if requested, ensuring that dead bots get disconnected from your server, and providing personal advice on optimizing your campaigns and bypassing anti-spam filtering through the built-in multi RBL checking feature&lt;br /&gt;&lt;br /&gt;A brief description of the system:&lt;br /&gt;&lt;br /&gt;1. The system is automatically harvesting the outgoing and incoming email addresses on the infected hosts and the associated accounting data, supporting the following clients :&lt;br /&gt;  - Mozilla Thunderbird&lt;br /&gt;  - Outlook Express&lt;br /&gt;  - MS Outlook&lt;br /&gt;  - The Bat&lt;br /&gt;  - Opera&lt;br /&gt;&lt;br /&gt;2. The bot automatically defines its MX and PTR records, if they are present it switches to Direct SMTP mailing which means that it can send the spam directly to the recipients using the MX and PTR DNS records of the bot, enforcing direct sending even without MX and PTR records is also possible&lt;br /&gt;&lt;br /&gt;3. The bot automatically defines its MX and PTR records, if they are present it switches to Direct SMTP mailing which means that it can send the spam directly to the recipients using the MX and PTR DNS records of the bot, enforcing direct sending even without MX and PTR records is also possible&lt;br /&gt;&lt;br /&gt;4. The central control server automatically assigns different regional servers to the bots, and rotates them periodically for security purposes&lt;br /&gt;&lt;br /&gt;5. All the information about the spam campaigns and the bots can be exported and syndicated with another regional server as requested, with the regional server dynamically establishing links with other regional servers so that it never really knows the address of the central command server&lt;br /&gt;&lt;br /&gt;6. There are several different ways of sending spam using this service :&lt;br /&gt;&lt;br /&gt;1) Direct spamming from the legitimate email accounts of the infected computers, with the system automatically syndicating all the available legitimate emails whose accounting data naturally stolen due to the malware infection is again, automatically integrated in a “unique legitimate senders” database. Full support for web based email accounts in the form of domain:username:password&lt;br /&gt;&lt;br /&gt;2) Sending via Direct SMTP: send messages directly using the MX and PTR records of the infected host’s gateway&lt;br /&gt;&lt;br /&gt;3) Sending to direct recipient&lt;br /&gt;&lt;br /&gt;4) Sending through open relays and socks servers, both of which can provided at an additional cost&lt;br /&gt;&lt;br /&gt;7. SET-X Mail System is highly modular, with unique features easily coded and implemented as requested by the customer&lt;br /&gt;&lt;br /&gt;The average speed from one server is 5000/7000 emails per minute, over 1 million emails per day, and if requested you can purchase as many servers as you would like. The price of rent per month is $2000 with additional $1000 for each additional server if the servers are ordered at the same time.”&lt;br /&gt;&lt;br /&gt;Capable of creating clever tag lines? Got a couple of thousand bucks lying around? Sign up now and you too can irritate millions of strangers every day.&lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://blogs.zdnet.com/security/?p=1899"&gt;Dancho Danchev&lt;/a&gt; for translating the material from Russian.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-4632509646692587114?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/4632509646692587114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=4632509646692587114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4632509646692587114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4632509646692587114'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2008/10/fun-with-dick-and-jane.html' title='Fun with Dick and Jane'/><author><name>defintel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-4995175547971547253</id><published>2008-09-08T11:31:00.006-04:00</published><updated>2008-11-30T11:08:34.477-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dns'/><category scheme='http://www.blogger.com/atom/ns#' term='cira'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='cygnos'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Cyber Security Event for the Government of Canada and IT Industry</title><content type='html'>&lt;div style="text-align: justify;"&gt;Dear Friends and Colleagues:&lt;br /&gt;&lt;br /&gt;On behalf of the Canadian Internet Registration Authority (CIRA), I am pleased to invite you to attend a special Cyber Security meeting to be held at the Crown Plaza Ottawa, September 23, 2008.&lt;br /&gt;&lt;br /&gt;Cyber Security is critical to ensuring the integrity of the network infrastructure of the federal government. This Cyber Security meeting offers an opportunity to discuss, share and learn what we can do and what we should do to respond to modern Cyber Security threats. It will be comprised of four sessions ranging from cyber-attacks, evolution of the modern malware, latest updates on the Kaminsky DNS Vulnerability and Electronic Espionage. Is the Government of Canada well safeguarded against these threats?&lt;br /&gt;&lt;br /&gt;Topics include:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update on the Kaminsky DNS Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Christopher Davis, CEO Defence Intelligence&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Evolution of the Threat: From Fun to Profit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Christopher Davis, CEO Defence Intelligence&lt;br /&gt;&lt;br /&gt;Meaghan Molloy, Threat Analyst Defence Intelligence&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Information Protection Capability Gap&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Aron Feuer/Wayne Boone, Cygnos IT Security&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cyber-Attacks: Experiences From the Trenches&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Bill Woodcock, Packet Clearing House&lt;br /&gt;&lt;br /&gt;We are delighted to welcome Mr. Bill Woodcockto this meeting. Bill Woodcock is research director of Packet Clearing House, a non-profit research institute dedicated to understanding and supporting Internet traffic exchange technology, policy, and economics. Bill has operated national and international Internet service provision and content delivery networks since 1989, and currently spends most of his time building Internet exchanges in developing countries.&lt;br /&gt;&lt;br /&gt;This is a meeting not to be missed!&lt;br /&gt;&lt;br /&gt;This CIRA Cyber Security event is limited to 60 participants. We urge you to register!&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;&lt;br /&gt;Norm Ritchie&lt;br /&gt;&lt;br /&gt;Chief Information Officer&lt;br /&gt;Canadian Internet Registration Authority (CIRA)&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-4995175547971547253?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='https://www.dns-oarc.net/oarc/workshop-2008' title='Cyber Security Event for the Government of Canada and IT Industry'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/4995175547971547253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=4995175547971547253' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4995175547971547253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/4995175547971547253'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2008/09/cyber-security-event-for-government-of.html' title='Cyber Security Event for the Government of Canada and IT Industry'/><author><name>defintel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-5493089720505149855</id><published>2008-08-20T12:27:00.001-04:00</published><updated>2008-10-27T13:17:55.222-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dns'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Kaminsky'/><title type='text'>Web experts scrambling to patch security flaw</title><content type='html'>&lt;div style="text-align: justify;" class="storysubhead"&gt;Code published that could allow hackers to direct surfers to fake websites&lt;/div&gt;&lt;table style="text-align: left; margin-left: 0px; margin-right: 0px;" border="0" width="100%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;span class="storybyline"&gt;Jessey Bird&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;span class="storypub"&gt;The Ottawa Citizen&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;" class="storydate"&gt;&lt;br /&gt;Thursday, July 24, 2008&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;" class="storytext"&gt;&lt;p&gt;Security experts are urging Internet server administrators to act quickly to head off what they are calling the "single largest threat to Internet security."&lt;/p&gt;&lt;p&gt;They say a critical flaw in the system used to route Internet traffic could let hackers redirect users to dangerous websites, and then steal their personal information.&lt;/p&gt;&lt;p&gt;While the flaw was discovered six months ago, and a fix released two weeks ago, the exact nature of the problem was kept secret.&lt;/p&gt;&lt;p&gt;That was until yesterday, when a program to exploit the flaw was posted on the Internet, allowing anyone around the world to simply download it and run it.&lt;/p&gt;&lt;p&gt;According to Christopher Davis, chief executive of Ottawa-based Defence Intelligence, the "exploit" allows hackers to replace search engines, social-networking sites and even banking websites with their own "malicious" content.&lt;/p&gt;&lt;p&gt;So far, government and Internet service provider officials say they are taking the threat to their domain-name servers seriously, but do not have any actual examples of the attack, which is called "DNS cache poisoning," to report.&lt;/p&gt;&lt;p&gt;The attack is aimed at how Internet addresses function, particularly the domain-name servers (DNS) that route Internet traffic.&lt;/p&gt;&lt;p&gt;While websites are all identified by addresses using words that are easy for people to remember -- like google.ca or facebook.com -- they are also identified by addresses of just numbers. Domain-name servers serve as the translator in between -- connecting a user that types in a web address to the correct computer.&lt;/p&gt;&lt;p&gt;"DNS is kind of the 411 for the Internet," said IOActive security researcher Dan Kaminsky, who discovered the flaw six months ago.&lt;/p&gt;&lt;p&gt;What he realized was that in just seconds, a malicious hacker could poison a domain-name server and reroute users to different websites from the ones they are seeking. Hackers could also route people to copycat websites that would enable them to steal people's personal information.&lt;/p&gt;&lt;p&gt;"This attack works very, very well," he said. "Any website that you trust is not necessarily the website that you are looking for. Every e-mail you send is not necessarily going where you think." Even people who take precautions could be fooled.&lt;/p&gt;&lt;p&gt;At the time of the discovery, Mr. Kaminsky and industry giants such as Microsoft and Cisco acted quickly to create a patch for the flaw, while keeping the exact nature of the problem secret. They released their fix two weeks ago.&lt;/p&gt;&lt;p&gt;Mr. Kaminsky promised to discuss the problem at a technical conference in August, so other security experts could learn from his work; that would give Internet providers about a month to install the fix. But after another expert's public speculation on the details of the DNS flaw hit too close to home on Monday and the details of the flaw were leaked, Mr. Kaminsky and Mr. Davis say they are worried hackers might know enough to cause problems -- and service providers haven't had enough time to install the patch.&lt;/p&gt;&lt;p&gt;"The majority of DNS servers have not yet been patched," said Mr. Kaminsky.&lt;/p&gt;&lt;p&gt;"It is a serious vulnerability," said Bruce Schneier, chief security technology officer for British Telecom. "It is one that can be used by criminals to steal identity."&lt;/p&gt;&lt;p&gt;Mr. Schneier also stressed that there is no need for the public to panic.&lt;/p&gt;&lt;p&gt;"Kaminsky was hoping there would be a full month for people to patch their system," said Mr. Schneier, adding that the leak has made Internet users "more vulnerable."&lt;/p&gt;&lt;p&gt;"But let's face it -- you're not going to die," he said. "Money is stolen out of banks every day. This is another way to do that.&lt;/p&gt;&lt;p&gt;"Is it a worse way than all the other ways? Probably not," he continued. "Is it a serious way? Yes. Have there been other serious ways? Yes. Are we still here? Yes."&lt;/p&gt;&lt;p&gt;"It is not armageddon," he said. "We are not going to die."&lt;/p&gt;&lt;p&gt;Officials from Rogers Cable Inc., one of Ontario's major Internet providers, said they haven't detected any problems with their system.&lt;/p&gt;&lt;p&gt;"Built into our network today are intrusion detection and prevention systems," said Nancy Cottenden, director of communications for Rogers Cable, adding that Rogers monitors vulnerabilities on a "regular basis."&lt;/p&gt;&lt;p&gt;Ms. Cottenden also said Rogers is in the midst of installing Mr. Kaminsky's patch.&lt;/p&gt;&lt;p&gt;"It takes some time," said Ms. Cottenden. "Any vendor will tell you it takes some time. The good news is, it is being loaded."&lt;/p&gt;&lt;p&gt;Bernard Beckhoff, spokesman for Public Safety Canada, said there have been "no confirmed incidences of the threat being applied in Canada or elsewhere."&lt;/p&gt;&lt;p&gt;The Canadian Cyber Incident Response Centre will continue to monitor the threat, said Mr. Beckhoff.&lt;/p&gt;&lt;p&gt;Mr. Davis said that while the Canadian government has been quick to respond, many are still downplaying the issue.&lt;/p&gt;&lt;p&gt;He urged Internet users to contact their service providers to find out whether they've patched their systems.&lt;/p&gt;&lt;p&gt;"It scares the hell out of us," said Mr. Davis. "And we know what we're doing."&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-5493089720505149855?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.canada.com/ottawacitizen/news/story.html?id=7731a0eb-eaf5-46d7-987f-3b13ad7be2ac' title='Web experts scrambling to patch security flaw'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/5493089720505149855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=5493089720505149855' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5493089720505149855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/5493089720505149855'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2008/08/web-experts-scrambling-to-patch.html' title='Web experts scrambling to patch security flaw'/><author><name>defintel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9202429674312578040.post-259928747057293442</id><published>2008-08-20T12:25:00.001-04:00</published><updated>2008-10-27T13:18:08.147-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dns'/><category scheme='http://www.blogger.com/atom/ns#' term='internet'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Kaminsky'/><title type='text'>Major Security Flaw Discovered: Internet Privacy Compromised at All Levels</title><content type='html'>&lt;div style="text-align: justify;"&gt;OTTAWA, ONTARIO--(Marketwire - July 22, 2008) - Yesterday, details were leaked of possibly the single largest threat to Internet security. Earlier this year, Dan Kaminsky, director of penetration testing for IOactive, discovered a major flaw in how Internet addresses function. The issue is in the design of the Domain Name System (DNS) and is not limited to any single product. An attacker could easily take over portions of the Internet and redirect users to arbitrary and malicious locations to engage in identity theft. For example, an attacker could target an Internet Service Provider (ISP) replacing search engines, social networks, banks, and other sites with their own malicious content. Against corporate or government environments, an attacker could disrupt or monitor operations by rerouting network traffic, capturing emails and other sensitive data.&lt;br /&gt;&lt;br /&gt;Kaminsky immediately reported the issue to major authorities, including the United States Computer Emergency Response Team (part of the Department of Homeland Security), and began working on a coordinated fix; a patch was released July 8th, 2008. Chris Davis, CEO of Ottawa-based Defence Intelligence, has been working in coordination with Kaminsky to brief key agencies in the Canadian government. Details of the vulnerability were to remain a closely held secret until Kaminsky's public presentation on August 6th, 2008 in order to provide organizations with enough time to protect themselves. However, this window was drastically reduced due to the accidental posting of the details by an uninvolved party.&lt;br /&gt;&lt;br /&gt;Defence Intelligence is determined to make Canadian companies fully aware of the flaw and the steps they can take to protect themselves. The general public should be particularly vigilant while conducting business online. Kaminsky is urging people to act quickly, "Patch. Today. Now. Yes, stay late."&lt;br /&gt;&lt;br /&gt;"This may be the worst information security vulnerability ever, and I'm very impressed at the speed and agility with which the Canadian government is responding," said Davis. The common goal of all involved parties is the implementation of the patch and monitoring of networks to ensure security.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9202429674312578040-259928747057293442?l=defintel.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.marketwire.com/press-release/Defence-Intelligence-Inc-881685.html' title='Major Security Flaw Discovered: Internet Privacy Compromised at All Levels'/><link rel='replies' type='application/atom+xml' href='http://defintel.blogspot.com/feeds/259928747057293442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9202429674312578040&amp;postID=259928747057293442' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/259928747057293442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9202429674312578040/posts/default/259928747057293442'/><link rel='alternate' type='text/html' href='http://defintel.blogspot.com/2008/08/major-security-flaw-discovered-internet.html' title='Major Security Flaw Discovered: Internet Privacy Compromised at All Levels'/><author><name>defintel</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
