<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2995682656102624692</id><updated>2012-01-29T15:56:23.080+07:00</updated><category term='Aggiornamento phishing Banco Posta'/><title type='text'>Edgar's Internet Tools</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default?start-index=101&amp;max-results=100'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2111</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4674517004140586046</id><published>2012-01-29T15:38:00.005+07:00</published><updated>2012-01-29T15:56:23.102+07:00</updated><title type='text'>Distribuzione eseguibili malware attraverso forum IT (29 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Su questo&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/distribuzione-eseguibili-malware.html"&gt; post del 24 gennaio&lt;/a&gt; veniva analizzata l'ennesima distribuzione malware attraverso &lt;span style="font-weight: bold;"&gt;posts su forum IT creati solo allo scopo di linkare siti dai contenuti malware &lt;/span&gt;sotto forma di fake players video,  install di flash player ecc...&lt;br /&gt;&lt;br /&gt;Vediamo qualche &lt;span style="font-weight: bold;"&gt;ulteriore dettaglio aggiornato ad oggi:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Come si nota dalla pagina dell'elenco dei posts viene &lt;span style="font-weight: bold;"&gt;indicata data odierna (today) &lt;/span&gt;che rivela un continuo 'aggiornamento' degli stessi in tempo reale&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-D2_i396euVY/TyUG2_JJuUI/AAAAAAAAoFc/_gGG4kkAC5o/s1600/forposts.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 171px;" src="http://4.bp.blogspot.com/-D2_i396euVY/TyUG2_JJuUI/AAAAAAAAoFc/_gGG4kkAC5o/s320/forposts.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972044867123522" border="0" /&gt;&lt;/a&gt;mentre ecco un tipico layout di uno dei messaggi postati attualmente.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-rf7191FzTHI/TyUG3Y_LXlI/AAAAAAAAoFk/BsyIL4Gj7sg/s1600/post.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 205.065px; height: 253.575px;" src="http://4.bp.blogspot.com/-rf7191FzTHI/TyUG3Y_LXlI/AAAAAAAAoFk/BsyIL4Gj7sg/s320/post.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972051804610130" border="0" /&gt;&lt;/a&gt;Il link presente punta, tramite &lt;span style="font-weight: bold;"&gt;redirects&lt;/span&gt; al fake player di filmati porno&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-R4GC6gNagwA/TyUG2oRhfsI/AAAAAAAAoFI/pTHgQsUewUA/s1600/fiddler.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 92px;" src="http://3.bp.blogspot.com/-R4GC6gNagwA/TyUG2oRhfsI/AAAAAAAAoFI/pTHgQsUewUA/s320/fiddler.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972038728220354" border="0" /&gt;&lt;/a&gt;A conferma dell'&lt;span style="font-weight: bold;"&gt;attuale stato attivo dell'azione di distribuzione malware notiamo alcune differenze&lt;/span&gt; sulla sequenza dei redirects sia con l'uso di&lt;span style="font-weight: bold;"&gt; snipr.com&lt;/span&gt; in sostituzione di &lt;span style="font-weight: bold;"&gt;tinyurl.com&lt;/span&gt; del 24/1&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-c7kp5gIA_zg/TyUG3sIbRCI/AAAAAAAAoFw/KoWEC1qpREI/s1600/snip.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 165px;" src="http://1.bp.blogspot.com/-c7kp5gIA_zg/TyUG3sIbRCI/AAAAAAAAoFw/KoWEC1qpREI/s320/snip.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972056943674402" border="0" /&gt;&lt;/a&gt;e di &lt;span style="font-weight: bold;"&gt;google.ru&lt;/span&gt; come &lt;span style="font-weight: bold;"&gt; redirect tramite l'uso di google &lt;/span&gt;rispetto a&lt;span style="font-weight: bold;"&gt; google.com&lt;/span&gt; usato la volta scorsa.&lt;br /&gt;&lt;br /&gt;Il&lt;span style="font-weight: bold;"&gt; malware linkato da&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-uCeJyBczkAs/TyUG2Q7cF7I/AAAAAAAAoFA/cIbUcJsJ6VM/s1600/fake%2Bplayer%2Bmissing.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 173px;" src="http://1.bp.blogspot.com/-uCeJyBczkAs/TyUG2Q7cF7I/AAAAAAAAoFA/cIbUcJsJ6VM/s320/fake%2Bplayer%2Bmissing.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972032461576114" border="0" /&gt;&lt;/a&gt;si presenta rispetto &lt;span style="font-weight: bold;"&gt;al 24 gennaio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-p6oXQyWWI50/Tx6MvrW3j2I/AAAAAAAAoAs/vRVLEBW1CNc/s1600/vt.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 189px; height: 320px;" src="http://2.bp.blogspot.com/-p6oXQyWWI50/Tx6MvrW3j2I/AAAAAAAAoAs/vRVLEBW1CNc/s320/vt.jpg" alt="" id="BLOGGER_PHOTO_ID_5701148929018007394" border="0" /&gt;&lt;/a&gt;ancora &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;meno riconosciuto&lt;/span&gt; (notare anche differente software AV che rileva il codice pericoloso)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-OtAnWPOiqGs/TyUHdx8ZuoI/AAAAAAAAoGY/ivmis_85A4c/s1600/vt%2Breport.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 174px; height: 320px;" src="http://4.bp.blogspot.com/-OtAnWPOiqGs/TyUHdx8ZuoI/AAAAAAAAoGY/ivmis_85A4c/s320/vt%2Breport.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972711338883714" border="0" /&gt;&lt;/a&gt;con solo&lt;span style="font-weight: bold;"&gt; 3 software che evidenziano i contenuti malevoli&lt;/span&gt; ( in realta'di  2 aziende, essendo presenti due versioni di software McAfee)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-qUfx8Z8EYQ0/TyUHdhsCwVI/AAAAAAAAoF8/yiTYRfYCzf0/s1600/vt%2Banalisi%2B2012-01-29_141627.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 89px;" src="http://4.bp.blogspot.com/-qUfx8Z8EYQ0/TyUHdhsCwVI/AAAAAAAAoF8/yiTYRfYCzf0/s320/vt%2Banalisi%2B2012-01-29_141627.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972706975301970" border="0" /&gt;&lt;/a&gt;&lt;a href="http://2.bp.blogspot.com/-hDukwHkatGI/TyUHdtHk7oI/AAAAAAAAoGI/5_UGphGjZmw/s1600/vt%2Blog.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 44px;" src="http://2.bp.blogspot.com/-hDukwHkatGI/TyUHdtHk7oI/AAAAAAAAoGI/5_UGphGjZmw/s320/vt%2Blog.jpg" alt="" id="BLOGGER_PHOTO_ID_5702972710043577986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Anche se sono&lt;span style="font-weight: bold;"&gt; ben noti i limiti dovuti ad una scansione online quale quella di Virus Total&lt;/span&gt; che potrebbe avere risposta diversa del software AV quando eseguito sul reale PC dell'utente, rimane il fatto che ci troviamo odi fronte ad un &lt;span style="font-weight: bold;"&gt;codice malware attualmente non rilevato dai softwares AV&lt;/span&gt; e quindi che potrebbe creare qualche problema a chi eseguisse il fake install di flash player sul PC.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4674517004140586046?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4674517004140586046/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4674517004140586046' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4674517004140586046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4674517004140586046'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/distribuzione-eseguibili-malware_29.html' title='Distribuzione eseguibili malware attraverso forum IT (29 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-D2_i396euVY/TyUG2_JJuUI/AAAAAAAAoFc/_gGG4kkAC5o/s72-c/forposts.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-957105525339884014</id><published>2012-01-27T08:22:00.003+07:00</published><updated>2012-01-27T08:30:59.305+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione regionale. Variazioni sul tema. Phishing Lottomatica (26  gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Nella &lt;span style="font-weight: bold;"&gt;giornata di ieri&lt;/span&gt; abbiamo avuto &lt;span style="font-weight: bold;"&gt;diversi attacchi di phishing ai danni di differenti banche IT&lt;/span&gt; &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/phishing-ai-danni-di-banche-it_26.html"&gt;documentati qui&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Di solito,&lt;/span&gt; se &lt;span style="font-weight: bold;"&gt;un sito presenta vulnerabilita' o comunque la possibilita' di uploadare in maniera semplice&lt;/span&gt; (vedi es. con l'uso di Asset Manager) contenuti di phishing, &lt;span style="font-weight: bold;"&gt;lo stesso viene  utilizzato a piu' riprese dai phishers.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;E' il&lt;span style="font-weight: bold;"&gt; caso di quello visto ieri che hostava i codici php relativi a phishing &lt;span style="color: rgb(255, 0, 0);"&gt;C.R. Bolzano&lt;/span&gt;&lt;/span&gt;, e che adesso ospita un semplice&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; phishing Lottomatica&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-nQFTBAK8Ir8/TyH8150b0YI/AAAAAAAAoD4/amAr7oR4Xvo/s1600/form.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 188px;" src="http://2.bp.blogspot.com/-nQFTBAK8Ir8/TyH8150b0YI/AAAAAAAAoD4/amAr7oR4Xvo/s320/form.jpg" alt="" id="BLOGGER_PHOTO_ID_5702116606211772802" border="0" /&gt;&lt;/a&gt;a cui si viene linkati da questa &lt;span style="font-weight: bold;"&gt;attuale mail segnalata in rete&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-MJq9l-8m9CI/TyH82N3xTYI/AAAAAAAAoEE/xk7XiV5Ed6U/s1600/mail%2Btesto.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 293px;" src="http://1.bp.blogspot.com/-MJq9l-8m9CI/TyH82N3xTYI/AAAAAAAAoEE/xk7XiV5Ed6U/s320/mail%2Btesto.jpg" alt="" id="BLOGGER_PHOTO_ID_5702116611594472834" border="0" /&gt;&lt;/a&gt;Questo un dettaglio della &lt;span style="font-weight: bold;"&gt;Asset Manager Innova Studio&lt;/span&gt; gia' analizzato ieri&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-0X9cHkZqDlE/TyH81nTnAwI/AAAAAAAAoDs/3qdCQEo14aQ/s1600/assetm.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 214px;" src="http://1.bp.blogspot.com/-0X9cHkZqDlE/TyH81nTnAwI/AAAAAAAAoDs/3qdCQEo14aQ/s320/assetm.jpg" alt="" id="BLOGGER_PHOTO_ID_5702116601242256130" border="0" /&gt;&lt;/a&gt;mentre qui vediamo il source del semplice &lt;span style="font-weight: bold;"&gt;codice php presente&lt;/span&gt;, che effettua l'invio al phisher dei dati eventualmente sottratti&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-TtZNyAOMk3Q/TyH82sRLzZI/AAAAAAAAoEQ/bWY9WHPYd0Q/s1600/php%2B2012-01-27_075236.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 207px;" src="http://1.bp.blogspot.com/-TtZNyAOMk3Q/TyH82sRLzZI/AAAAAAAAoEQ/bWY9WHPYd0Q/s320/php%2B2012-01-27_075236.jpg" alt="" id="BLOGGER_PHOTO_ID_5702116619754130834" border="0" /&gt;&lt;/a&gt;L'indirizzo mail conferma&lt;span style="font-weight: bold;"&gt; identico personaggio rispetto a quello visto ieri in phishing C.R.Bolzano&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Una volta acquisiti&lt;span style="font-weight: bold;"&gt; i dati si viene rediretti a questa reale pagina Lottomatica&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-2YVaBopL28M/TyH823L_6xI/AAAAAAAAoEc/nXo9gHNAdtM/s1600/real.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 225px;" src="http://2.bp.blogspot.com/-2YVaBopL28M/TyH823L_6xI/AAAAAAAAoEc/nXo9gHNAdtM/s320/real.jpg" alt="" id="BLOGGER_PHOTO_ID_5702116622685170450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-957105525339884014?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/957105525339884014/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=957105525339884014' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/957105525339884014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/957105525339884014'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-ai-danni-di-banche-it_27.html' title='Phishing ai danni di banche IT a diffusione regionale. Variazioni sul tema. Phishing Lottomatica (26  gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-nQFTBAK8Ir8/TyH8150b0YI/AAAAAAAAoD4/amAr7oR4Xvo/s72-c/form.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8483963480594268898</id><published>2012-01-26T11:03:00.009+07:00</published><updated>2012-01-26T12:29:23.644+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione regionale: Banca Popolare dell'Emilia Romagna , C.R. Bolzano, Banca Valsabbina (26  gennaio)</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Nella giornata di ieri&lt;/span&gt; abbiamo avuto &lt;span style="font-weight: bold;"&gt;diversi attacchi di phishing a banche IT diffusione prevalentemente locale o regionale.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Si e' iniziato con &lt;span style="font-weight: bold;"&gt;un phishing ai danni di &lt;span style="color: rgb(255, 0, 0);"&gt;Banca Valsabbina&lt;/span&gt; &lt;/span&gt;rilevato quando erano le &lt;span style="font-weight: bold;"&gt;prime ore del mattino in Thailandia (quindi notte in Italia)&lt;/span&gt; e che e' comunque stato &lt;span style="font-weight: bold;"&gt;contrastato dalla banca rendendolo praticamente inattivo dopo poche ore.&lt;/span&gt;&lt;br /&gt;Da notare come &lt;span style="font-weight: bold;"&gt;detto phishing pur avendo alcune caratteristiche &lt;/span&gt;(vedi es. redirect su &lt;span style="font-weight: bold;"&gt;Altervista&lt;/span&gt;) che lo accomunavano ai soliti di &lt;span style="font-weight: bold;"&gt;R-team&lt;/span&gt; presentasse comunque un redirect al clone che sfruttava sito UK compromesso&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-T-uWl95Bbf8/TyDSSJpDxmI/AAAAAAAAoCQ/XAK90oEuTj8/s1600/whois%2B2012-01-26_100724.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 176px;" src="http://2.bp.blogspot.com/-T-uWl95Bbf8/TyDSSJpDxmI/AAAAAAAAoCQ/XAK90oEuTj8/s320/whois%2B2012-01-26_100724.jpg" alt="" id="BLOGGER_PHOTO_ID_5701788337518659170" border="0" /&gt;&lt;/a&gt;ma senza  la possibilita' di rilevare l'utilizzo dei soliti files managers comuni in questi casi.&lt;br /&gt;&lt;br /&gt;Terminato&lt;span style="font-weight: bold;"&gt; l'attacco a Valsabbina&lt;/span&gt; sempre il medesimo sito di redirect e'&lt;span style="font-weight: bold;"&gt; passato ad ospitare direttamente un clone &lt;span style="color: rgb(255, 0, 0);"&gt;C.R. Bolzano&lt;/span&gt; (tuttora attivo) &lt;/span&gt;che, come rileva anche Denis Frati sul suo blog, presenta pero' forms con i codici&lt;span style="font-weight: bold;"&gt; di gestione php ospitati su altro sito.&lt;/span&gt;&lt;br /&gt;Da notare che, rispetto a quanto illustra &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.denisfrati.it/2012/01/25/cambio-di-rotta-la-bussola-torna-a-puntare-a-nord-est-sparkasse/#more-5378"&gt;Denis Frati sul clone da lui rilevato&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-RPxMDCrk14I/TyDijLm4gbI/AAAAAAAAoDU/6R9q8vSK7zI/s1600/frati%2Bfolder%2Bprecedente%2Bstesso%2Bclone%2Bcrbolz.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 212px;" src="http://3.bp.blogspot.com/-RPxMDCrk14I/TyDijLm4gbI/AAAAAAAAoDU/6R9q8vSK7zI/s320/frati%2Bfolder%2Bprecedente%2Bstesso%2Bclone%2Bcrbolz.png" alt="" id="BLOGGER_PHOTO_ID_5701806222290223538" border="0" /&gt;&lt;/a&gt;parrebbe adesso esserci &lt;span style="font-weight: bold;"&gt;diverso timestamp sui files htm &lt;/span&gt;(da &lt;span style="font-style: italic; font-weight: bold;"&gt;10:34 a 15:05&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-o2yO_EZ6Etw/TyDijJ61-TI/AAAAAAAAoDM/mh4X0DJA8kc/s1600/attuale%2Bclone%2Bfolder.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 220px;" src="http://4.bp.blogspot.com/-o2yO_EZ6Etw/TyDijJ61-TI/AAAAAAAAoDM/mh4X0DJA8kc/s320/attuale%2Bclone%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5701806221837072690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;e il &lt;span style="font-weight: bold;"&gt;link al sito che ospita i php di acquisizione credenziali eventualmente sottratte sia ora differente&lt;/span&gt; (si tratta di comune modifica dei redirects attuata dai phishers per evitare blacklisting ecc.....)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-D6_s9NaYL1g/TyDRrlqkXtI/AAAAAAAAoBQ/APKf-Nmtt-o/s1600/pho%2B%2Blink%2Bad%2Baltro%2Bhost.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 64px;" src="http://1.bp.blogspot.com/-D6_s9NaYL1g/TyDRrlqkXtI/AAAAAAAAoBQ/APKf-Nmtt-o/s320/pho%2B%2Blink%2Bad%2Baltro%2Bhost.jpg" alt="" id="BLOGGER_PHOTO_ID_5701787675026284242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;con un &lt;span style="font-weight: bold;"&gt;whois &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-FrW5sRCSheY/TyDRstM70MI/AAAAAAAAoCA/O9r8c8RnhCM/s1600/whhost%2B%2Bphp%2Bcrbolz%2Bsu%2Buk.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 126px;" src="http://4.bp.blogspot.com/-FrW5sRCSheY/TyDRstM70MI/AAAAAAAAoCA/O9r8c8RnhCM/s320/whhost%2B%2Bphp%2Bcrbolz%2Bsu%2Buk.jpg" alt="" id="BLOGGER_PHOTO_ID_5701787694229344450" border="0" /&gt;&lt;/a&gt;Una analisi del&lt;span style="font-weight: bold;"&gt; sito compromesso che ospita i codici php &lt;/span&gt;ritorna a proporre un &lt;span style="font-weight: bold;"&gt;Asset Manager Innova Studio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-qpvdjKK0a3I/TyDRr8fZqsI/AAAAAAAAoBY/2Y2-8LIZXv4/s1600/assetm%2Bsu%2Bhost%2B%2Bphp.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 171px;" src="http://3.bp.blogspot.com/-qpvdjKK0a3I/TyDRr8fZqsI/AAAAAAAAoBY/2Y2-8LIZXv4/s320/assetm%2Bsu%2Bhost%2B%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5701787681153460930" border="0" /&gt;&lt;/a&gt;che evidenzia&lt;span style="font-weight: bold;"&gt; la presenza , oltre ai php visti, anche di mailer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-U2dOomXpaJc/TyDRr0vTZMI/AAAAAAAAoBs/TawknNIdRps/s1600/mailer%2Bsu%2Bhost%2Bphp.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 215px;" src="http://1.bp.blogspot.com/-U2dOomXpaJc/TyDRr0vTZMI/AAAAAAAAoBs/TawknNIdRps/s320/mailer%2Bsu%2Bhost%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5701787679072675010" border="0" /&gt;&lt;/a&gt;Questo utilizzo di &lt;span style="font-weight: bold;"&gt;Asset Manager&lt;/span&gt; ricorda nuovamente gli attacchi &lt;span style="font-weight: bold;"&gt;R-Team &lt;/span&gt;ben noti ma una &lt;span style="font-weight: bold;"&gt;analisi dei sorgenti php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-kQ9DaIpWEww/TyDRsSBx3TI/AAAAAAAAoB0/wrkzAskxXrQ/s1600/php%2B%2Bno%2Brteam.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 270px;" src="http://1.bp.blogspot.com/-kQ9DaIpWEww/TyDRsSBx3TI/AAAAAAAAoB0/wrkzAskxXrQ/s320/php%2B%2Bno%2Brteam.jpg" alt="" id="BLOGGER_PHOTO_ID_5701787686934797618" border="0" /&gt;&lt;/a&gt;ci rivela indirizzo&lt;span style="font-weight: bold;"&gt; mail differente dall'usuale R-Team &lt;/span&gt;almeno rispetto a recenti attacchi di phishing, cosa che fa quindi rimanere &lt;span style="font-weight: bold;"&gt;qualche dubbio sugli attuali gestori degli stessi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Per di piu' &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;CR Bolzano &lt;/span&gt;e' coinvolta, &lt;span style="font-weight: bold;"&gt;questa mattina 26 gennaio (ora Thai) &lt;/span&gt;in altro attacco&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-Ir0uD791PPo/TyDS1iGhaLI/AAAAAAAAoCo/1qfXHF13nyo/s1600/home%2Bclone%2B2012-01-26_091100.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 138px;" src="http://2.bp.blogspot.com/-Ir0uD791PPo/TyDS1iGhaLI/AAAAAAAAoCo/1qfXHF13nyo/s320/home%2Bclone%2B2012-01-26_091100.jpg" alt="" id="BLOGGER_PHOTO_ID_5701788945380108466" border="0" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/-jkMvW_yJR-k/TyDS1axrx7I/AAAAAAAAoCc/IclMNduznkA/s1600/pin.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 198px;" src="http://3.bp.blogspot.com/-jkMvW_yJR-k/TyDS1axrx7I/AAAAAAAAoCc/IclMNduznkA/s320/pin.jpg" alt="" id="BLOGGER_PHOTO_ID_5701788943413659570" border="0" /&gt;&lt;/a&gt; che si sviluppa&lt;span style="font-weight: bold;"&gt; tramite sito &lt;/span&gt;&lt;span style="font-weight: bold;"&gt; compromesso&lt;/span&gt; &lt;span style="font-weight: bold;"&gt; USA, di Hotel&lt;/span&gt;, che &lt;span style="font-weight: bold;"&gt;punta tramite redirect &lt;/span&gt;a clone hostato &lt;span style="font-weight: bold;"&gt;su dominio creato in data odierna&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-nIyvqM7vc6U/TyDS18s4OmI/AAAAAAAAoC0/x3czMPAdPuI/s1600/creadom.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 151px;" src="http://2.bp.blogspot.com/-nIyvqM7vc6U/TyDS18s4OmI/AAAAAAAAoC0/x3czMPAdPuI/s320/creadom.jpg" alt="" id="BLOGGER_PHOTO_ID_5701788952520309346" border="0" /&gt;&lt;/a&gt;attraverso il&lt;span style="font-weight: bold;"&gt; 'solito' servizio di hosting usato molto in passato da r-team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In questo caso i form di login e richiesta pin hanno i codici php direttamente linkati nel medesimo folder che usa il clone&lt;br /&gt;&lt;br /&gt;C'e' comunque da rilevare che comparando i due sources htm &lt;span style="font-weight: bold;"&gt;sia del clone su sito UK &lt;/span&gt;che quello&lt;span style="font-weight: bold;"&gt; su hosting USA &lt;/span&gt;le differenze sono minime&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ZHG9M3jVE6E/TyDXfK4AnLI/AAAAAAAAoDA/-HNAsprWyTo/s1600/comp.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 171px;" src="http://3.bp.blogspot.com/-ZHG9M3jVE6E/TyDXfK4AnLI/AAAAAAAAoDA/-HNAsprWyTo/s320/comp.jpg" alt="" id="BLOGGER_PHOTO_ID_5701794058746240178" border="0" /&gt;&lt;/a&gt;ed abbiamo lo stesso nome di file tanto &lt;span style="font-weight: bold;"&gt;da far pensare a stesso kit di phishing&lt;/span&gt; se non,  ad origine comune dei due attacchi.&lt;br /&gt;&lt;br /&gt;Per  terminare abbiamo pure&lt;span style="font-weight: bold;"&gt; attivo al momento un phishing ai danni di  &lt;span style="color: rgb(255, 0, 0);"&gt;Banca Popolare dell'Emilia Romagna&lt;/span&gt;&lt;/span&gt; che sfrutta hosting su sito USA compromesso (sito di E-Commerce) &lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://edetools.blogspot.com/2012/01/phishing-ai-danni-di-banche-it_23.html"&gt;gia' analizzato in precedente post&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;L'unica differenza che, dal messaggio mail segnalato in rete, parrebbe esserci adesso link diretto al clone, senza che venga sfruttato il redirect intermedio visto in precedenza.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Questo il clone BPER&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-NpOmWmHs9yU/Tx0_MEjrtEI/AAAAAAAAn3I/gxQtlDS7Bw0/s1600/clone.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://3.bp.blogspot.com/-NpOmWmHs9yU/Tx0_MEjrtEI/AAAAAAAAn3I/gxQtlDS7Bw0/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5700782179935302722" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8483963480594268898?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8483963480594268898/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8483963480594268898' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8483963480594268898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8483963480594268898'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-ai-danni-di-banche-it_26.html' title='Phishing ai danni di banche IT a diffusione regionale: Banca Popolare dell&apos;Emilia Romagna , C.R. Bolzano, Banca Valsabbina (26  gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-T-uWl95Bbf8/TyDSSJpDxmI/AAAAAAAAoCQ/XAK90oEuTj8/s72-c/whois%2B2012-01-26_100724.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-3179940193258106744</id><published>2012-01-24T17:44:00.006+07:00</published><updated>2012-01-24T18:00:31.057+07:00</updated><title type='text'>Distribuzione eseguibili malware attraverso forum IT (24 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Anche se e' da qualche tempo che non viene trattato dal blog, l'argomento relativo a &lt;span style="font-weight: bold;"&gt; links a falsi siti di filmati online (quasi sempre di genere porno) utilizzando post creati allo scopo su forum poco o per niente amministrati, e' sempre di attualita'&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Questo un&lt;span style="font-weight: bold;"&gt; odierno forum IT &lt;/span&gt;dove notiamo una&lt;span style="font-weight: bold;"&gt; lunga sequenza di post aggiornati in tempo reale (in media dai 3 ai 5 al minuto) &lt;/span&gt;e comprendenti&lt;span style="font-weight: bold;"&gt; differenti links a fake sito di filmati porno&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-9xtGHEMDwiM/Tx6LxKsBGyI/AAAAAAAAn_o/0VKpQBSrH3E/s1600/postst%2Blist%2B2012-01-24_153518.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://2.bp.blogspot.com/-9xtGHEMDwiM/Tx6LxKsBGyI/AAAAAAAAn_o/0VKpQBSrH3E/s320/postst%2Blist%2B2012-01-24_153518.jpg" alt="" id="BLOGGER_PHOTO_ID_5701147855096453922" border="0" /&gt;&lt;/a&gt;Ecco un &lt;span style="font-weight: bold;"&gt;tipico post con immagine cliccabile&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-zifEi4LUm30/Tx6Lw5xznRI/AAAAAAAAn_M/OflR_zieBU4/s1600/post%2Bexample.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 303px; height: 320px;" src="http://3.bp.blogspot.com/-zifEi4LUm30/Tx6Lw5xznRI/AAAAAAAAn_M/OflR_zieBU4/s320/post%2Bexample.jpg" alt="" id="BLOGGER_PHOTO_ID_5701147850557332754" border="0" /&gt;&lt;/a&gt;e lunga &lt;span style="font-weight: bold;"&gt;serie di termini relativi al medesimo argomento porno trattato con lo scopo di creare il maggior numero di link attraverso una ricerca in rete.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Kyje9bYtpZ8/Tx6LxABMs6I/AAAAAAAAn_U/DpxtZrk7fw8/s1600/words.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 196px; height: 320px;" src="http://1.bp.blogspot.com/-Kyje9bYtpZ8/Tx6LxABMs6I/AAAAAAAAn_U/DpxtZrk7fw8/s320/words.jpg" alt="" id="BLOGGER_PHOTO_ID_5701147852232504226" border="0" /&gt;&lt;/a&gt;E' interessante analizzare il link proposto con Fiddler ottenedo&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-aVVy_lei2Qk/Tx6Lxpa2KWI/AAAAAAAAn_w/Tr_IftOKTPk/s1600/redir%2Bfiddler.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 66px;" src="http://1.bp.blogspot.com/-aVVy_lei2Qk/Tx6Lxpa2KWI/AAAAAAAAn_w/Tr_IftOKTPk/s320/redir%2Bfiddler.jpg" alt="" id="BLOGGER_PHOTO_ID_5701147863345932642" border="0" /&gt;&lt;/a&gt;con &lt;span style="font-weight: bold;"&gt;un primo redirect utilizzando tinyurl &lt;/span&gt;seguito a sua volta da un&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt; redirect gestito attraverso URL che punta a Google&lt;/span&gt;.&lt;br /&gt;Si tratta di un tipico caso di '&lt;span style="font-style: italic; font-weight: bold;"&gt;Google Search URL Redirection'&lt;/span&gt; gai visto in passato.&lt;br /&gt;A sua volta verremo rediretti, senza che appaia alcun riferimento a Google nel browser, ad altro sito che successivamente puntera' ad &lt;span style="font-weight: bold;"&gt;uno dei  tanti layout di gestione filmati video in parte gia' visti altre volte&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-_Sre3m-AEtc/Tx6MtTKWJGI/AAAAAAAAoAE/xVQH9jPbwIM/s1600/allro%2Bflash.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 190px;" src="http://4.bp.blogspot.com/-_Sre3m-AEtc/Tx6MtTKWJGI/AAAAAAAAoAE/xVQH9jPbwIM/s320/allro%2Bflash.jpg" alt="" id="BLOGGER_PHOTO_ID_5701148888163296354" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-hIklIWQbtDs/Tx6MtKr5GnI/AAAAAAAAn_8/Ks-r1goEFz0/s1600/a2%2Bpage.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 187px;" src="http://2.bp.blogspot.com/-hIklIWQbtDs/Tx6MtKr5GnI/AAAAAAAAn_8/Ks-r1goEFz0/s320/a2%2Bpage.jpg" alt="" id="BLOGGER_PHOTO_ID_5701148885888080498" border="0" /&gt;&lt;/a&gt;ma anche con &lt;span style="font-weight: bold;"&gt;differente presentazione del fake player che parrebbe essere aggiornata.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-3Ztvq63B454/Tx6MtsBkIiI/AAAAAAAAoAY/OhaAiixkiZM/s1600/1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 168px;" src="http://3.bp.blogspot.com/-3Ztvq63B454/Tx6MtsBkIiI/AAAAAAAAoAY/OhaAiixkiZM/s320/1.jpg" alt="" id="BLOGGER_PHOTO_ID_5701148894837350946" border="0" /&gt;&lt;/a&gt;da cui&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ADfcYFgagnU/Tx6Mvt4cfII/AAAAAAAAoAg/qh4ShB-sAXU/s1600/flash%2Bplayer%2Bfake%2Bfile.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 197px;" src="http://3.bp.blogspot.com/-ADfcYFgagnU/Tx6Mvt4cfII/AAAAAAAAoAg/qh4ShB-sAXU/s320/flash%2Bplayer%2Bfake%2Bfile.jpg" alt="" id="BLOGGER_PHOTO_ID_5701148929695710338" border="0" /&gt;&lt;/a&gt;Naturalmente &lt;span style="font-weight: bold;"&gt;sara' necessario scaricare il programma di installazione del&lt;span style="color: rgb(255, 0, 0);"&gt; FAKE &lt;/span&gt; player flash &lt;/span&gt;che in realta' dimostrera' essere&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-p6oXQyWWI50/Tx6MvrW3j2I/AAAAAAAAoAs/vRVLEBW1CNc/s1600/vt.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 189px; height: 320px;" src="http://2.bp.blogspot.com/-p6oXQyWWI50/Tx6MvrW3j2I/AAAAAAAAoAs/vRVLEBW1CNc/s320/vt.jpg" alt="" id="BLOGGER_PHOTO_ID_5701148929018007394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Questo un whois del sito di falsi filmati:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-nRZMuQ_u75o/Tx6OjETttPI/AAAAAAAAoA4/YQfLzVK-hgc/s1600/wh%2B1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 146px;" src="http://2.bp.blogspot.com/-nRZMuQ_u75o/Tx6OjETttPI/AAAAAAAAoA4/YQfLzVK-hgc/s320/wh%2B1.jpg" alt="" id="BLOGGER_PHOTO_ID_5701150911400621298" border="0" /&gt;&lt;/a&gt;Da notare come in questi casi sfruttando&lt;span style="font-weight: bold;"&gt; differenti e multipli redirect&lt;/span&gt;, e post su forum pubblicati ad intervalli &lt;span style="font-weight: bold;"&gt;di tempo molto breve,&lt;/span&gt; chi vuole distribuire malware disponga di tutto l'occorrente per proporre eseguibili non facilmente individuabili dai sofwares AV e con possibilita' di utilizzare indirizzi web continuamente variati che rendono difficoltoso anche un blacklisting degli stessi.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-3179940193258106744?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/3179940193258106744/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=3179940193258106744' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3179940193258106744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3179940193258106744'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/distribuzione-eseguibili-malware.html' title='Distribuzione eseguibili malware attraverso forum IT (24 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-9xtGHEMDwiM/Tx6LxKsBGyI/AAAAAAAAn_o/0VKpQBSrH3E/s72-c/postst%2Blist%2B2012-01-24_153518.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-1384616543451307801</id><published>2012-01-24T12:06:00.005+07:00</published><updated>2012-01-24T12:34:22.087+07:00</updated><title type='text'>'Il vostro ordine di riferimento e' ...... '. Aggiornamenti (24 gennaio)</title><content type='html'>Chi segue il blog ricordera' certamente&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/il-vostro-ordine-di-riferimento-e.html"&gt; la segnalazione del 21 gennaio &lt;/a&gt;relativa a fake documento allegato a messaggio mail.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Tale documento, fatto passare &lt;span style="font-weight: bold;"&gt;per pdf , in realta' mostrava essere eseguibile malware&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Da segnalare che una analisi Virus Total il 21/1 &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;mostrava riconoscimento malware praticamente nullo sia per il file .zip che per quello estratto.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Attualmente,&lt;/span&gt; vediamo come, &lt;span style="font-weight: bold;"&gt;sia il file zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-FAPV7GtjzYw/Tx5CJmS7QzI/AAAAAAAAn-0/C0hrHeaj0ic/s1600/vt%2Bzip%2B2012-01-24_114459.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 263px; height: 320px;" src="http://2.bp.blogspot.com/-FAPV7GtjzYw/Tx5CJmS7QzI/AAAAAAAAn-0/C0hrHeaj0ic/s320/vt%2Bzip%2B2012-01-24_114459.jpg" alt="" id="BLOGGER_PHOTO_ID_5701066910963811122" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;che il file estratto .exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-6L9a87k2ksw/Tx5CQwOCjPI/AAAAAAAAn_A/mV08ITB1LlA/s1600/vt%2Bfattura%2Bunzip.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 250px; height: 320px;" src="http://2.bp.blogspot.com/-6L9a87k2ksw/Tx5CQwOCjPI/AAAAAAAAn_A/mV08ITB1LlA/s320/vt%2Bfattura%2Bunzip.jpg" alt="" id="BLOGGER_PHOTO_ID_5701067033886756082" border="0" /&gt;&lt;/a&gt;presentano un riconoscimento che&lt;span style="font-weight: bold;"&gt; incomincia ad essere significativo anche se alcuni noti AV&lt;/span&gt; parrebbero ancora&lt;span style="font-weight: bold;"&gt; non rilevare i contenuti pericolosi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Come gia' visto altre volte&lt;span style="font-weight: bold;"&gt; ci sono pure alcune differenze tra risposta AV su file zip e su file estratto exe&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Da ricordare, anche, gli eventuali limiti di una scansione online come quella VT, con possibile risposta ai contenuti pericolosi da parte dei  software AV che attualmente non individuano il malware, che potrebbero pero' allertare quando il fake pdf venisse eseguito sul PC .&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 102, 102);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-1384616543451307801?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/1384616543451307801/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=1384616543451307801' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1384616543451307801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1384616543451307801'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/il-vostro-ordine-di-riferimento-e_24.html' title='&apos;Il vostro ordine di riferimento e&apos; ...... &apos;. Aggiornamenti (24 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-FAPV7GtjzYw/Tx5CJmS7QzI/AAAAAAAAn-0/C0hrHeaj0ic/s72-c/vt%2Bzip%2B2012-01-24_114459.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2988008623313703261</id><published>2012-01-24T09:50:00.000+07:00</published><updated>2012-01-24T09:50:10.634+07:00</updated><title type='text'>Ancora phishing CartaSi  (24 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ancora mail&lt;span style="font-weight: bold;"&gt; di phishing &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-3elquF8Fw98/Tx4bRntYIdI/AAAAAAAAn4k/k4Ng6Gr9oGk/s1600/mail.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 169px;" src="http://3.bp.blogspot.com/-3elquF8Fw98/Tx4bRntYIdI/AAAAAAAAn4k/k4Ng6Gr9oGk/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5701024167828660690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;con allegato form&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-i7l6SjvHgRg/Tx4bRUIopJI/AAAAAAAAn4Q/073RojGf3jY/s1600/form%2B2012-01-24_091927.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 244px;" src="http://2.bp.blogspot.com/-i7l6SjvHgRg/Tx4bRUIopJI/AAAAAAAAn4Q/073RojGf3jY/s320/form%2B2012-01-24_091927.jpg" alt="" id="BLOGGER_PHOTO_ID_5701024162574279826" border="0" /&gt;&lt;/a&gt;che presenta link a&lt;span style="font-weight: bold;"&gt; codice php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-fPgVbVcPKc0/Tx4b8OjRlVI/AAAAAAAAn4s/x1WYVI0Av5A/s1600/form%2Baction.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 54px;" src="http://2.bp.blogspot.com/-fPgVbVcPKc0/Tx4b8OjRlVI/AAAAAAAAn4s/x1WYVI0Av5A/s320/form%2Baction.jpg" alt="" id="BLOGGER_PHOTO_ID_5701024899809776978" border="0" /&gt;&lt;/a&gt;hostato su sito sviluppato in &lt;span style="font-weight: bold;"&gt;WordPress con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-F45L0tsxswo/Tx4b8W7wsPI/AAAAAAAAn40/VR2JCuyEFcY/s1600/wh.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 148px;" src="http://2.bp.blogspot.com/-F45L0tsxswo/Tx4b8W7wsPI/AAAAAAAAn40/VR2JCuyEFcY/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5701024902059962610" border="0" /&gt;&lt;/a&gt;e che rivela anche &lt;span style="font-weight: bold;"&gt;la presenza online di file credenziali sottratte a chi fosse caduto nel tranello della falsa mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-DQCK3_4mWUA/Tx4bRfJuKkI/AAAAAAAAn4I/lUNoYnz-ULU/s1600/cred%2Bfolder.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 204px;" src="http://4.bp.blogspot.com/-DQCK3_4mWUA/Tx4bRfJuKkI/AAAAAAAAn4I/lUNoYnz-ULU/s320/cred%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5701024165531626050" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2988008623313703261?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2988008623313703261/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2988008623313703261' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2988008623313703261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2988008623313703261'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/ancora-phishing-cartasi-24-gennaio.html' title='Ancora phishing CartaSi  (24 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-3elquF8Fw98/Tx4bRntYIdI/AAAAAAAAn4k/k4Ng6Gr9oGk/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2703670735247890188</id><published>2012-01-23T18:05:00.003+07:00</published><updated>2012-01-23T18:11:23.240+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione regionale: Banca Popolare dell'Emilia Romagna (23 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ritorna il phishing&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;  Banca Popolare dell'Emilia Romagna&lt;/span&gt; tramite solita mail fake segnalata in rete e che sfrutta hosting su &lt;span style="font-weight: bold;"&gt;sito USA compromesso &lt;/span&gt;(sito di E-Commerce)&lt;br /&gt;&lt;br /&gt;Vediamo brevemente (considerato che&lt;span style="font-weight: bold;"&gt; oggi e' capodanno (cinese)&lt;/span&gt; in Thailadia e giorno festivo per molti) &lt;span style="font-weight: bold;"&gt;qualche dettaglio:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo il clone&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; BPER&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-NpOmWmHs9yU/Tx0_MEjrtEI/AAAAAAAAn3I/gxQtlDS7Bw0/s1600/clone.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://3.bp.blogspot.com/-NpOmWmHs9yU/Tx0_MEjrtEI/AAAAAAAAn3I/gxQtlDS7Bw0/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5700782179935302722" border="0" /&gt;&lt;/a&gt;mentre una occhiata &lt;span style="font-weight: bold;"&gt;al kit di phishing &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-0fpaFN42qO0/Tx0_MX9DrxI/AAAAAAAAn3Q/0bQFH2-dm9g/s1600/kit%2Bph2012-01-23_173827.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 172px;" src="http://4.bp.blogspot.com/-0fpaFN42qO0/Tx0_MX9DrxI/AAAAAAAAn3Q/0bQFH2-dm9g/s320/kit%2Bph2012-01-23_173827.jpg" alt="" id="BLOGGER_PHOTO_ID_5700782185142005522" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;mostra data attuale&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-3gh7-OhYpJk/Tx0_MT3ivyI/AAAAAAAAn3k/Zvrtz2dJPA0/s1600/kit.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 79px;" src="http://3.bp.blogspot.com/-3gh7-OhYpJk/Tx0_MT3ivyI/AAAAAAAAn3k/Zvrtz2dJPA0/s320/kit.jpg" alt="" id="BLOGGER_PHOTO_ID_5700782184045133602" border="0" /&gt;&lt;/a&gt;per il php &lt;span style="font-weight: bold;"&gt;che  esegue l'invio delle credenziali eventualmente sottratte&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-XCxWY149TeE/Tx0_NC_QqWI/AAAAAAAAn3w/bP8IlgkhZpg/s1600/php%2Bcode.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 267px;" src="http://4.bp.blogspot.com/-XCxWY149TeE/Tx0_NC_QqWI/AAAAAAAAn3w/bP8IlgkhZpg/s320/php%2Bcode.jpg" alt="" id="BLOGGER_PHOTO_ID_5700782196693969250" border="0" /&gt;&lt;/a&gt;Stessa data attuale nel subfolder &lt;span style="font-weight: bold;"&gt;files pagina clone di login relativamente al file thumbnail delle immagini&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-h8OKcZvUP6Y/Tx0_OAuHM3I/AAAAAAAAn34/pW84xmOXM-Q/s1600/thumb.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 210px;" src="http://3.bp.blogspot.com/-h8OKcZvUP6Y/Tx0_OAuHM3I/AAAAAAAAn34/pW84xmOXM-Q/s320/thumb.jpg" alt="" id="BLOGGER_PHOTO_ID_5700782213265044338" border="0" /&gt;&lt;/a&gt;L'indirizzo mail a cui vengono &lt;span style="font-weight: bold;"&gt;inviati i dati sottratti&lt;/span&gt; e' gia' stato rilevato,&lt;span style="font-weight: bold;"&gt; ma solo come parte del nome presente&lt;/span&gt;, in phishing&lt;span style="font-weight: bold;"&gt; Cariparma di inizio 2011&lt;/span&gt; e, cosa piu' interessante in&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; caso BPER nell' aprile 2011&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2703670735247890188?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2703670735247890188/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2703670735247890188' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2703670735247890188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2703670735247890188'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-ai-danni-di-banche-it_23.html' title='Phishing ai danni di banche IT a diffusione regionale: Banca Popolare dell&apos;Emilia Romagna (23 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-NpOmWmHs9yU/Tx0_MEjrtEI/AAAAAAAAn3I/gxQtlDS7Bw0/s72-c/clone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5746611592368528702</id><published>2012-01-22T21:58:00.009+07:00</published><updated>2012-01-22T22:25:28.285+07:00</updated><title type='text'>Phishing PayPal (22 gennaio)</title><content type='html'>Ancora phishing &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Paypal&lt;/span&gt;  con questa mail&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-iMBhWyce8bw/TxwkYSziE-I/AAAAAAAAn14/GtnvZvjcA08/s1600/mail.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 299px;" src="http://2.bp.blogspot.com/-iMBhWyce8bw/TxwkYSziE-I/AAAAAAAAn14/GtnvZvjcA08/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5700471228127646690" border="0" /&gt;&lt;/a&gt;dal layout accurato e dal logo in lingua francese, cosi come alcuni testi delle pagine clone e di variabili del codice php di invio credenziali sottratte, segno di possibile origine da sorgente di  phishing &lt;span style="font-weight: bold;"&gt;Paypal   &lt;/span&gt;in lingua francese.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il link in mail punta a redirect &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-VEkf40spEoI/TxwnPVKgNjI/AAAAAAAAn2w/oXx1rUfzqEA/s1600/redir%2Bdate%2Bfile.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 50px;" src="http://4.bp.blogspot.com/-VEkf40spEoI/TxwnPVKgNjI/AAAAAAAAn2w/oXx1rUfzqEA/s320/redir%2Bdate%2Bfile.jpg" alt="" id="BLOGGER_PHOTO_ID_5700474372676924978" border="0" /&gt;&lt;/a&gt;hostato su sito USA compromesso che propone anche diverse shells php incluse in folder utilizzato&lt;span style="font-weight: bold;"&gt; sia per hostare il redirect a clone Paypal IT che ad altro clone PayPal in lingua tedesca.(notate data odierna per il redirect a clone PayPal IT)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-7rIoK2gmukQ/Txwk8ynYKYI/AAAAAAAAn2Y/bl-jaP0HbBo/s1600/paypals%2Bit%2B%2Bted.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 172px;" src="http://2.bp.blogspot.com/-7rIoK2gmukQ/Txwk8ynYKYI/AAAAAAAAn2Y/bl-jaP0HbBo/s320/paypals%2Bit%2B%2Bted.jpg" alt="" id="BLOGGER_PHOTO_ID_5700471855141890434" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Il redirect punta a sito &lt;span style="font-weight: bold;"&gt;con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-fzZr96LLDE4/TxwkZQGxTkI/AAAAAAAAn2I/7SqgiHqcBWg/s1600/wh%2Bclone.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 102px;" src="http://1.bp.blogspot.com/-fzZr96LLDE4/TxwkZQGxTkI/AAAAAAAAn2I/7SqgiHqcBWg/s320/wh%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5700471244582899266" border="0" /&gt;&lt;/a&gt;con evidenti segni di compromissione come la presenza di diverse shells php.&lt;br /&gt;&lt;br /&gt;Sempre incluso nello stesso sito troviamo il clone&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-rJLiif5bNsQ/Txwl1dQqFMI/AAAAAAAAn2k/KQ6iSK0OuRU/s1600/phi%2Bsiite%2Bstruct.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 145px;" src="http://2.bp.blogspot.com/-rJLiif5bNsQ/Txwl1dQqFMI/AAAAAAAAn2k/KQ6iSK0OuRU/s320/phi%2Bsiite%2Bstruct.jpg" alt="" id="BLOGGER_PHOTO_ID_5700472828661994690" border="0" /&gt;&lt;/a&gt;ed il  kit di &lt;span style="font-weight: bold;"&gt;phishing &lt;span style="color: rgb(255, 0, 0);"&gt;PayPal&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Un confronto con &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/phishing-paypal-it-su-sito-sud.html"&gt;il precedente phishing PayPal &lt;/a&gt;descritto qualche giorno fa&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-_Nf-r8g6iH8/TxoNf6WS8bI/AAAAAAAAnw4/CZGWc9GFn98/s1600/php%2Bclone%2Bdate.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 166px;" src="http://2.bp.blogspot.com/-_Nf-r8g6iH8/TxoNf6WS8bI/AAAAAAAAnw4/CZGWc9GFn98/s320/php%2Bclone%2Bdate.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883120280662450" border="0" /&gt;&lt;/a&gt; mostra evidenti analogie&lt;span style="font-weight: bold;"&gt; sia con la struttura del sito copia che con i nomi dei codici che gestiscono il phishing.(es file  BiMAr.php)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;L'unica sostanziale differenza e' l'indirizzo mail a cui vengono inviati i dati eventualmente acquisiti e che consiste questa volta&lt;span style="font-weight: bold;"&gt; in ben tre  nominativi &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-UL7a7NmaNUA/TxwpheRnDwI/AAAAAAAAn28/ZtW6vH3SVK8/s1600/php%2Bsend%2Bmails.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 119px;" src="http://3.bp.blogspot.com/-UL7a7NmaNUA/TxwpheRnDwI/AAAAAAAAn28/ZtW6vH3SVK8/s320/php%2Bsend%2Bmails.jpg" alt="" id="BLOGGER_PHOTO_ID_5700476883383553794" border="0" /&gt;&lt;/a&gt;Da notare come  si cerchi sempre di&lt;span style="font-weight: bold;"&gt; acquisire il maggior numero di dati compreso una ampia scelta di differenti gestori di carte di credito.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-aGi3eVYCp4A/TxwkZHIKI6I/AAAAAAAAn2A/odsSMUes_wk/s1600/itlie%2Be%2Bcarte.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 142px;" src="http://1.bp.blogspot.com/-aGi3eVYCp4A/TxwkZHIKI6I/AAAAAAAAn2A/odsSMUes_wk/s320/itlie%2Be%2Bcarte.jpg" alt="" id="BLOGGER_PHOTO_ID_5700471242172801954" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5746611592368528702?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5746611592368528702/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5746611592368528702' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5746611592368528702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5746611592368528702'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-paypal-22-gennaio.html' title='Phishing PayPal (22 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-iMBhWyce8bw/TxwkYSziE-I/AAAAAAAAn14/GtnvZvjcA08/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2596598693924434787</id><published>2012-01-22T13:32:00.009+07:00</published><updated>2012-01-22T21:58:24.000+07:00</updated><title type='text'>'Il vostro ordine di riferimento e' ...... '. Altri dettagli (22 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;AVVISO       IMPORTANTE!     Ricordo che anche se alcuni links sono lasciati in       chiaro  negli    screenshot, evitate di visitare i siti elencati se non       avete preso     tutte le precauzioni del caso ! Si tratta di   pagine  e    siti  che potrebbero distribuire eseguibili MALWARE, tra l'altro,  anche poco    riconosciuti dai    software AV.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/il-vostro-ordine-di-riferimento-e.html"&gt;Dopo alcune ore dalla ricezione della mail&lt;/a&gt; con link a malware, abbiamo per quanto si riferisce al riconoscimento del file eseguibile, sempre&lt;span style="font-weight: bold;"&gt; risposta nulla per il file .exe mentre si e' passati da 3 a 4 AV che riconoscono lo zip come file malevolo o sospetto&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-0h5aG5QLWpg/TxuvDpUbBaI/AAAAAAAAn1c/Iwf3Abvylrk/s1600/vt.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 58px;" src="http://3.bp.blogspot.com/-0h5aG5QLWpg/TxuvDpUbBaI/AAAAAAAAn1c/Iwf3Abvylrk/s320/vt.jpg" alt="" id="BLOGGER_PHOTO_ID_5700342230533473698" border="0" /&gt;&lt;/a&gt;Una analisi Anubis mostra &lt;span style="font-weight: bold;"&gt;una connessione a&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-DWGeziXwlCQ/TxuuSX3zPsI/AAAAAAAAn0U/66d03JOKGQ4/s1600/anubis.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 79px;" src="http://2.bp.blogspot.com/-DWGeziXwlCQ/TxuuSX3zPsI/AAAAAAAAn0U/66d03JOKGQ4/s320/anubis.jpg" alt="" id="BLOGGER_PHOTO_ID_5700341384036433602" border="0" /&gt;&lt;/a&gt;confermata da &lt;span style="font-weight: bold;"&gt;Threath Expert&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-C-Tf84yb7Ug/TxuuzyV2EII/AAAAAAAAn1E/cuKmSD5wDKU/s1600/threath.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 113px;" src="http://3.bp.blogspot.com/-C-Tf84yb7Ug/TxuuzyV2EII/AAAAAAAAn1E/cuKmSD5wDKU/s320/threath.jpg" alt="" id="BLOGGER_PHOTO_ID_5700341958077452418" border="0" /&gt;&lt;/a&gt;quando l'eseguibile va' in run&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Lo stesso indirizzo web a cui si connetterebbe il malware  e relativo file .bin sono present in una segnalazione Sophos&lt;/span&gt;, anche se non parrebbe collegata al caso attuale.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-gk8QH1XJgaU/Txuuzz5sZKI/AAAAAAAAn1Q/OeqIy7K_bxM/s1600/sophos.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 208px;" src="http://1.bp.blogspot.com/-gk8QH1XJgaU/Txuuzz5sZKI/AAAAAAAAn1Q/OeqIy7K_bxM/s320/sophos.jpg" alt="" id="BLOGGER_PHOTO_ID_5700341958496248994" border="0" /&gt;&lt;/a&gt;Piu' interessante questa &lt;span style="font-weight: bold;"&gt;segnalazione Cisco&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-w4MTM8Mg_9s/TxuuSQ_Z-jI/AAAAAAAAn0c/IzSFx_lhObs/s1600/cisco%2B012-01-22_094132.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 221px;" src="http://4.bp.blogspot.com/-w4MTM8Mg_9s/TxuuSQ_Z-jI/AAAAAAAAn0c/IzSFx_lhObs/s320/cisco%2B012-01-22_094132.jpg" alt="" id="BLOGGER_PHOTO_ID_5700341382189283890" border="0" /&gt;&lt;/a&gt;che evidenzia&lt;span style="font-weight: bold;"&gt; stesso link a file zip ma su differente url IT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-upwyPIw2xJA/TxuuSuZin3I/AAAAAAAAn0s/tHQn__5ocuo/s1600/cisco%2Bdet.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 93px;" src="http://2.bp.blogspot.com/-upwyPIw2xJA/TxuuSuZin3I/AAAAAAAAn0s/tHQn__5ocuo/s320/cisco%2Bdet.jpg" alt="" id="BLOGGER_PHOTO_ID_5700341390083530610" border="0" /&gt;&lt;/a&gt;a conferma, come si legge, di&lt;span style="font-style: italic; color: rgb(0, 0, 153);"&gt; ....una significativa attivita' in relazione a messaggi di spam in lingua italiana......&lt;/span&gt;  (identici a quello visto nella  mail ricevuta ieri).&lt;br /&gt;&lt;br /&gt;Un ulteriore indizio della probabile diffusione di questo spam con allegato malware, lo abbiamo anche dalle &lt;span style="font-weight: bold;"&gt;statistiche del blog, con percentuale piu' alta di accessi nelle ultime ore proprio al post relativo al fake documento pdf online.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-L2la66xh538/TxuuS_VkJRI/AAAAAAAAn04/1w0fbuZTo5M/s1600/stat%2Bgoogle.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 98px;" src="http://1.bp.blogspot.com/-L2la66xh538/TxuuS_VkJRI/AAAAAAAAn04/1w0fbuZTo5M/s320/stat%2Bgoogle.jpg" alt="" id="BLOGGER_PHOTO_ID_5700341394630255890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold; font-style: italic;"&gt;Aggiornamento:&lt;/span&gt;&lt;br /&gt;Ulteriore segnalazione in rete di  spam che punta &lt;span style="font-weight: bold;"&gt; a differente sito IT&lt;/span&gt; e &lt;span style="font-weight: bold;"&gt;diverso nome di file zip e con fake estensione .doc quando estratto&lt;/span&gt;&lt;br /&gt;In realta' una analisi &lt;span style="font-weight: bold;"&gt;md5&lt;/span&gt; mostra&lt;span style="font-weight: bold;"&gt; identico contenuto sia per il file falso .doc che per il fake pdf visto in precedenza.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-lGe-Bp3O5r4/Txu8sFFKmTI/AAAAAAAAn1o/seFhHVTzff4/s1600/hash%2Bn%2Bf.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 33px;" src="http://4.bp.blogspot.com/-lGe-Bp3O5r4/Txu8sFFKmTI/AAAAAAAAn1o/seFhHVTzff4/s320/hash%2Bn%2Bf.jpg" alt="" id="BLOGGER_PHOTO_ID_5700357218831604018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2596598693924434787?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2596598693924434787/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2596598693924434787' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2596598693924434787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2596598693924434787'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/il-vostro-ordine-di-riferimento-e_22.html' title='&apos;Il vostro ordine di riferimento e&apos; ...... &apos;. Altri dettagli (22 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-0h5aG5QLWpg/TxuvDpUbBaI/AAAAAAAAn1c/Iwf3Abvylrk/s72-c/vt.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-7520161733988462512</id><published>2012-01-21T23:52:00.009+07:00</published><updated>2012-01-22T14:00:24.549+07:00</updated><title type='text'>'Il vostro ordine di riferimento e' ...... ' (21 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ritorna una nota distribuzione di malware attraverso mails come quella ricevuta da poco&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-pT-lvxU8TS4/TxrwTLSJNiI/AAAAAAAAn0I/75Ha6hx3KA0/s1600/mail.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 174px;" src="http://2.bp.blogspot.com/-pT-lvxU8TS4/TxrwTLSJNiI/AAAAAAAAn0I/75Ha6hx3KA0/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5700132490627855906" border="0" /&gt;&lt;/a&gt;che presenta link ad&lt;span style="font-weight: bold;"&gt; eseguibile ''mascherato' nel nome dall'uso di una lunga serie di caratteri underscore&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ecco come si presenta il contenuto del&lt;span style="font-weight: bold;"&gt; file zip linkato in mail prima&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-z7B0Af51Sck/TxruzxiChXI/AAAAAAAAnzA/Y92AWyr56gM/s1600/unzipped.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 87px;" src="http://2.bp.blogspot.com/-z7B0Af51Sck/TxruzxiChXI/AAAAAAAAnzA/Y92AWyr56gM/s320/unzipped.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130851627631986" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;e dopo&lt;/span&gt; aver&lt;span style="font-weight: bold;"&gt; ridimensionato la colonna relativa al nome del file&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-yFfy6mtDXMw/TxruPjufymI/AAAAAAAAny0/zvHfCwbR7xE/s1600/reale%2Bfile%2Bname.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 52px;" src="http://2.bp.blogspot.com/-yFfy6mtDXMw/TxruPjufymI/AAAAAAAAny0/zvHfCwbR7xE/s320/reale%2Bfile%2Bname.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130229446494818" border="0" /&gt;&lt;/a&gt;Una analisi &lt;span style="font-weight: bold;"&gt;Virus Total mostrava,  al momento della scrittura del post,  riconoscimento nullo per il file estratto dallo zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-_CPAY6-FLv0/Txrvhx9y1_I/AAAAAAAAnz8/_mjkktO3t3w/s1600/lafatturaexe%2Bvt%2Bdescrtop.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 144px;" src="http://2.bp.blogspot.com/-_CPAY6-FLv0/Txrvhx9y1_I/AAAAAAAAnz8/_mjkktO3t3w/s320/lafatturaexe%2Bvt%2Bdescrtop.jpg" alt="" id="BLOGGER_PHOTO_ID_5700131642018027506" border="0" /&gt;&lt;/a&gt;mentre&lt;span style="font-weight: bold;"&gt; il file nel formato zip viene riconosciuto come possibile malware da ben pochi softares AV&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-dtUkTJnYzsQ/TxrvJR24dFI/AAAAAAAAnzg/CDshEGWL_FM/s1600/lafattura%2B%2Bzip.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 146px;" src="http://2.bp.blogspot.com/-dtUkTJnYzsQ/TxrvJR24dFI/AAAAAAAAnzg/CDshEGWL_FM/s320/lafattura%2B%2Bzip.jpg" alt="" id="BLOGGER_PHOTO_ID_5700131221082240082" border="0" /&gt;&lt;/a&gt;&lt;a href="http://3.bp.blogspot.com/-yAGGilsrHJc/TxrvJDm6JmI/AAAAAAAAnzY/SbKiDSrL2GU/s1600/lafattura%2Bzip%2Bvt%2Breport%2B3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 45px;" src="http://3.bp.blogspot.com/-yAGGilsrHJc/TxrvJDm6JmI/AAAAAAAAnzY/SbKiDSrL2GU/s320/lafattura%2Bzip%2Bvt%2Breport%2B3.jpg" alt="" id="BLOGGER_PHOTO_ID_5700131217257145954" border="0" /&gt;&lt;/a&gt;Questi gli header in mail&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-MfqgADbFRTs/TxruOu0I1pI/AAAAAAAAnyY/Nd7jth_EYF8/s1600/headers.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 58px;" src="http://3.bp.blogspot.com/-MfqgADbFRTs/TxruOu0I1pI/AAAAAAAAnyY/Nd7jth_EYF8/s320/headers.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130215243077266" border="0" /&gt;&lt;/a&gt;mentre per quanto si riferisce all'hosting del file, probabile malware, vediamo alcuni ulteriori dettagli:&lt;br /&gt;&lt;br /&gt;Il lnk in mail punta &lt;span style="font-weight: bold;"&gt;a sito italiano compromesso di vendita 'caffe'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-d5xkiFNjUP4/TxruPFaw8JI/AAAAAAAAnyo/QV0t37o_tC8/s1600/home%2Bhsot%2Bmalw%2Bcaffe%2Btorref.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 219px;" src="http://1.bp.blogspot.com/-d5xkiFNjUP4/TxruPFaw8JI/AAAAAAAAnyo/QV0t37o_tC8/s320/home%2Bhsot%2Bmalw%2Bcaffe%2Btorref.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130221310668946" border="0" /&gt;&lt;/a&gt;con whois&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-V0iBSQftRB4/Txruz3V_LXI/AAAAAAAAnzI/nNGS1PwxhAw/s1600/whois.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 145px;" src="http://3.bp.blogspot.com/-V0iBSQftRB4/Txruz3V_LXI/AAAAAAAAnzI/nNGS1PwxhAw/s320/whois.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130853187693938" border="0" /&gt;&lt;/a&gt;Detto sito parrebbe &lt;span style="font-weight: bold;"&gt;ospitare due differenti folders che hostano l'eseguibile malware&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-Hqrrb0FJZHo/TxruOU1QQnI/AAAAAAAAnyM/9OneZ1OXTsM/s1600/folders%2Bfattura.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 45px;" src="http://2.bp.blogspot.com/-Hqrrb0FJZHo/TxruOU1QQnI/AAAAAAAAnyM/9OneZ1OXTsM/s320/folders%2Bfattura.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130208268436082" border="0" /&gt;&lt;/a&gt;ma non solo.&lt;br /&gt;&lt;br /&gt;Una ricerca piu' approfondita porta infatti a trovare &lt;span style="font-weight: bold;"&gt;alcuni codici relativi a questa 'nota' pagina fake dal layout di e-card&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-xIH_YFSZ36Y/TxruOQTXcfI/AAAAAAAAnyE/4RVuW-89hL4/s1600/cafeecards%2Bmalw.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 190px;" src="http://1.bp.blogspot.com/-xIH_YFSZ36Y/TxruOQTXcfI/AAAAAAAAnyE/4RVuW-89hL4/s320/cafeecards%2Bmalw.jpg" alt="" id="BLOGGER_PHOTO_ID_5700130207052558834" border="0" /&gt;&lt;/a&gt;gia' ampiamente vista e&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/e-cards-pericolose-una-cartolina.html"&gt; descritta in passato  in questo post.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Una breve analisi del codice offuscato indica che al momento l'indirizzo presente non e' piu' attivo.&lt;br /&gt;&lt;br /&gt;Ritornando al file eseguibile una sua analisi con Anubis mostra che lo stesso si connette ad indirizzo con whois&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-RYTsPGo06Ig/TxrvJSUagDI/AAAAAAAAnzw/uKbBUnHWPY0/s1600/wh%2Bconnection%2Bby%2Bmalw.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 138px;" src="http://4.bp.blogspot.com/-RYTsPGo06Ig/TxrvJSUagDI/AAAAAAAAnzw/uKbBUnHWPY0/s320/wh%2Bconnection%2Bby%2Bmalw.jpg" alt="" id="BLOGGER_PHOTO_ID_5700131221206106162" border="0" /&gt;&lt;/a&gt;e riferimento a file che ritroviamo gia' in una precedente analisi malware Sophos.&lt;br /&gt;In ogni caso si tratta di una azione di spam pericoloso che potrebbe, grazie al fake nome del file e la doppia estensione mascherata, far cliccare sull'eseguibile,tanto piu' che al momento detto codice sembra  praticamente sconosciuto ai piu' diffusi software AV anche se, come sempre, c'e'  da tenere conto dei limiti di una scansione on-line on-demand quale quella di Virus Total.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-7520161733988462512?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/7520161733988462512/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=7520161733988462512' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7520161733988462512'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7520161733988462512'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/il-vostro-ordine-di-riferimento-e.html' title='&apos;Il vostro ordine di riferimento e&apos; ...... &apos; (21 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-pT-lvxU8TS4/TxrwTLSJNiI/AAAAAAAAn0I/75Ha6hx3KA0/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-1371697490448764126</id><published>2012-01-21T07:54:00.005+07:00</published><updated>2012-01-21T08:11:20.933+07:00</updated><title type='text'>Phishing PayPal IT su sito sud americano (20 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Si tratta di un &lt;span style="font-weight: bold;"&gt;phishing &lt;span style="color: rgb(255, 0, 0);"&gt;PayPal &lt;/span&gt;ai danni di utenti IT&lt;/span&gt; strutturato con sequenza di form abbastanza dettagliati e con richiesta di numerosi dati relativi&lt;span style="font-weight: bold;"&gt; all'account &lt;span style="color: rgb(255, 0, 0);"&gt;PayPal.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Abbiamo (dopo la diffusa pagina che simula&lt;span style="font-weight: bold;"&gt; una attesa per connessione in corso&lt;/span&gt;) questo form&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-PR8gnEvMtMY/TxoNe3q4FII/AAAAAAAAnwI/xjkpSCH43ys/s1600/p1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://4.bp.blogspot.com/-PR8gnEvMtMY/TxoNe3q4FII/AAAAAAAAnwI/xjkpSCH43ys/s320/p1.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883102381806722" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-RiEiYQKznwE/TxoNe8tRW5I/AAAAAAAAnwU/Lmp3jWdraV0/s1600/p2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://1.bp.blogspot.com/-RiEiYQKznwE/TxoNe8tRW5I/AAAAAAAAnwU/Lmp3jWdraV0/s320/p2.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883103734029202" border="0" /&gt;&lt;/a&gt;ed a seguire&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-u3HRKlusF-I/TxoNfZzWmkI/AAAAAAAAnwg/tQlPEa8x1ow/s1600/p3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 304px;" src="http://4.bp.blogspot.com/-u3HRKlusF-I/TxoNfZzWmkI/AAAAAAAAnwg/tQlPEa8x1ow/s320/p3.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883111544166978" border="0" /&gt;&lt;/a&gt;Su certi campi (es. il numero di carta) viene eseguito il controllo sulla correttezza dei dati.&lt;br /&gt;&lt;br /&gt;Il sito compromesso che&lt;span style="font-weight: bold;"&gt; ospita il clone e' &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-711gKjuiF-k/TxoNfjd_CmI/AAAAAAAAnws/eQiDmJ4ZtZs/s1600/home.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 162px;" src="http://2.bp.blogspot.com/-711gKjuiF-k/TxoNfjd_CmI/AAAAAAAAnws/eQiDmJ4ZtZs/s320/home.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883114138896994" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con whois  cileno&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-r5vQxFLwNdQ/TxoOvXCbI5I/AAAAAAAAnx4/28TDtCglG5c/s1600/wh%2B2012-01-21_080215.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 133px;" src="http://1.bp.blogspot.com/-r5vQxFLwNdQ/TxoOvXCbI5I/AAAAAAAAnx4/28TDtCglG5c/s320/wh%2B2012-01-21_080215.jpg" alt="" id="BLOGGER_PHOTO_ID_5699884485191607186" border="0" /&gt;&lt;/a&gt;Il sito e' compromesso e presenta shells&lt;span style="font-weight: bold;"&gt; sia nel folder che ospita alcun files mp3 di musica &lt;/span&gt;eseguita in background nella homepage&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-9-hQQNRku4E/TxoNtN060eI/AAAAAAAAnxQ/R1cMk4_q9Dg/s1600/shell%2Bc.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 172px;" src="http://3.bp.blogspot.com/-9-hQQNRku4E/TxoNtN060eI/AAAAAAAAnxQ/R1cMk4_q9Dg/s320/shell%2Bc.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883348847677922" border="0" /&gt;&lt;/a&gt;che altra con&lt;span style="font-weight: bold;"&gt; password di accesso, in folder che ospita anche il clone &lt;span style="color: rgb(255, 0, 0);"&gt;PayPal&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-0f2yrsOcM8E/TxoNs5w58fI/AAAAAAAAnxI/MfO4GYqYGJY/s1600/sh%2Bobf.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 166px;" src="http://1.bp.blogspot.com/-0f2yrsOcM8E/TxoNs5w58fI/AAAAAAAAnxI/MfO4GYqYGJY/s320/sh%2Bobf.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883343462134258" border="0" /&gt;&lt;/a&gt;Un dettaglio delle date dei files presenti &lt;span style="font-weight: bold;"&gt;mostrano date recenti (19/1) &lt;/span&gt;per i  codici php di invio credenziali sottratte dal fake sito PayPal&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-_Nf-r8g6iH8/TxoNf6WS8bI/AAAAAAAAnw4/CZGWc9GFn98/s1600/php%2Bclone%2Bdate.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 166px;" src="http://2.bp.blogspot.com/-_Nf-r8g6iH8/TxoNf6WS8bI/AAAAAAAAnw4/CZGWc9GFn98/s320/php%2Bclone%2Bdate.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883120280662450" border="0" /&gt;&lt;/a&gt;Questo il codice php che mostra nomi delle variabili in lingua francese cosi'&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-g_JhuvSzDMQ/TxoNtp3mDVI/AAAAAAAAnxs/Vy5tU-hzkJM/s1600/php%2Bsen%2Bmail.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 153px;" src="http://1.bp.blogspot.com/-g_JhuvSzDMQ/TxoNtp3mDVI/AAAAAAAAnxs/Vy5tU-hzkJM/s320/php%2Bsen%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883356375092562" border="0" /&gt;&lt;/a&gt; come il reale sito a cui si dovrebbe venire rediretti risulta essere quello &lt;span style="font-weight: bold;"&gt;PayPal in lingua francese.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-t5uphBCoUZg/TxoNtLC0EmI/AAAAAAAAnxg/bW2UMEstOak/s1600/reale%2Bfrance.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 163px;" src="http://1.bp.blogspot.com/-t5uphBCoUZg/TxoNtLC0EmI/AAAAAAAAnxg/bW2UMEstOak/s320/reale%2Bfrance.jpg" alt="" id="BLOGGER_PHOTO_ID_5699883348100649570" border="0" /&gt;&lt;/a&gt;Ho scritto &lt;span style="font-style: italic;"&gt;'si dovrebbe venire rediretti'&lt;/span&gt; in quanto in realta' parrebbe esserci un errore  sul codice di redirect al reale sto&lt;span style="font-weight: bold;"&gt; PayPal.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-1371697490448764126?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/1371697490448764126/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=1371697490448764126' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1371697490448764126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1371697490448764126'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-paypal-it-su-sito-sud.html' title='Phishing PayPal IT su sito sud americano (20 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-PR8gnEvMtMY/TxoNe3q4FII/AAAAAAAAnwI/xjkpSCH43ys/s72-c/p1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-7606990842237812418</id><published>2012-01-20T10:05:00.009+07:00</published><updated>2012-01-20T10:34:40.805+07:00</updated><title type='text'>'Newsletter di Gennaio'. Phishing CartaSi e WIND accomunati da alcuni dettagli mail (20 gennaio)</title><content type='html'>Ricevute alcune mails di phishing ai danni sia di &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;CartaSi &lt;/span&gt;che &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;WIND&lt;/span&gt; con alcuni&lt;span style="font-weight: bold;"&gt; punti in comune, cosa che fa pensare anche a possibile origine da parte dello stesso gruppo di phishers.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Queste &lt;span style="font-weight: bold;"&gt;due delle mails ricevute&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-2jRhGGsae6I/TxjaV-RlAzI/AAAAAAAAnto/0bTUK4jJutI/s1600/le%2B2%2Bmails%2B2012-01-20_080328.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 36px;" src="http://3.bp.blogspot.com/-2jRhGGsae6I/TxjaV-RlAzI/AAAAAAAAnto/0bTUK4jJutI/s320/le%2B2%2Bmails%2B2012-01-20_080328.jpg" alt="" id="BLOGGER_PHOTO_ID_5699545399466197810" border="0" /&gt;&lt;/a&gt;nelle quali abbiamo sia  mittente&lt;span style="font-weight: bold;"&gt;  "Newsletter di Gennaio"&lt;/span&gt;  comune ai due messaggi mail ed anche che,  in entrambe le mails, si informa di una &lt;span style="font-weight: bold;"&gt;ricarica telefonica gratuita.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Vediamo alcuni dettagli:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;La prima mail che esaminiamo e' rivolta ad utenti&lt;span style="color: rgb(255, 0, 0);"&gt; CartaSi&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-bFYi_PVpmv0/TxjaV_hlUaI/AAAAAAAAntw/SzIJEkysSro/s1600/1%2Bmail.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 274px;" src="http://3.bp.blogspot.com/-bFYi_PVpmv0/TxjaV_hlUaI/AAAAAAAAntw/SzIJEkysSro/s320/1%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5699545399801762210" border="0" /&gt;&lt;/a&gt;ed avvisa di una “&lt;span style="color: rgb(51, 102, 102); font-style: italic;"&gt;........  ricarica telefonica del valore di € 75,00. .&lt;/span&gt;” in regalo.&lt;br /&gt;&lt;br /&gt;Questo&lt;span style="font-weight: bold;"&gt; l'header in mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-9JouhcPdiaE/TxjaWEYmjYI/AAAAAAAAnuA/oRpsrlfl3_I/s1600/1%2Bheaders.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 57px;" src="http://1.bp.blogspot.com/-9JouhcPdiaE/TxjaWEYmjYI/AAAAAAAAnuA/oRpsrlfl3_I/s320/1%2Bheaders.jpg" alt="" id="BLOGGER_PHOTO_ID_5699545401106271618" border="0" /&gt;&lt;/a&gt;Naturalmente, anche se non viene esplicitamente indicato, lo scopo e' quello di far effettuare, a chi riceve il fake messaggio,&lt;span style="font-weight: bold;"&gt; il login al sito clone CartaSi indicato in mail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il link presente esegue un &lt;span style="font-weight: bold;"&gt;redirect utilizzando un sito di Free  Subdomains USA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-ttPoe_qHeSI/TxjgrPouJGI/AAAAAAAAnv4/kkXIpkye678/s1600/1%2Bsub%2Bobfu.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 221px;" src="http://1.bp.blogspot.com/-ttPoe_qHeSI/TxjgrPouJGI/AAAAAAAAnv4/kkXIpkye678/s320/1%2Bsub%2Bobfu.jpg" alt="" id="BLOGGER_PHOTO_ID_5699552361973687394" border="0" /&gt;&lt;/a&gt;utilizzato sia per&lt;span style="font-weight: bold;"&gt; generare un nome ingannevole di url&lt;/span&gt; ma naturalmente anche per, nel caso di&lt;span style="font-weight: bold;"&gt; black-listing o sospensione dell'account su cui risiede il clone attualmente&lt;/span&gt;,  redirigere su&lt;span style="font-weight: bold;"&gt; clone hostato su diverso indirizzo.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-6gp4ZmObrSI/TxjaWeapl0I/AAAAAAAAnuQ/uwfmhPZGKu8/s1600/1%2Bfiddler.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 42px;" src="http://1.bp.blogspot.com/-6gp4ZmObrSI/TxjaWeapl0I/AAAAAAAAnuQ/uwfmhPZGKu8/s320/1%2Bfiddler.jpg" alt="" id="BLOGGER_PHOTO_ID_5699545408094181186" border="0" /&gt;&lt;/a&gt;Questo il  fake sito &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; CartaSi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-ORv2H68JaK8/TxjaW0mDrpI/AAAAAAAAnuY/SAgVC-EoSpc/s1600/1%2Bclone%2Balterv.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 214px;" src="http://1.bp.blogspot.com/-ORv2H68JaK8/TxjaW0mDrpI/AAAAAAAAnuY/SAgVC-EoSpc/s320/1%2Bclone%2Balterv.jpg" alt="" id="BLOGGER_PHOTO_ID_5699545414047608466" border="0" /&gt;&lt;/a&gt;ospitato su server &lt;span style="font-weight: bold;"&gt;Altervista (whois tedesco)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-7hemFUvTTWo/TxjbJPmHlFI/AAAAAAAAnu8/H4RqqokhGzs/s1600/1%2Bwh%2Balterv.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 142px;" src="http://2.bp.blogspot.com/-7hemFUvTTWo/TxjbJPmHlFI/AAAAAAAAnu8/H4RqqokhGzs/s320/1%2Bwh%2Balterv.jpg" alt="" id="BLOGGER_PHOTO_ID_5699546280289080402" border="0" /&gt;&lt;/a&gt;La registrazione del&lt;span style="font-weight: bold;"&gt; nuovo account Altervista utilizzato appare effettuata da alcun giorni.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-asU7gPgyEWU/TxjadM8nuiI/AAAAAAAAnuk/2gNBqzBNYhI/s1600/1%2Balterv%2Breg.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 183px;" src="http://2.bp.blogspot.com/-asU7gPgyEWU/TxjadM8nuiI/AAAAAAAAnuk/2gNBqzBNYhI/s320/1%2Balterv%2Breg.jpg" alt="" id="BLOGGER_PHOTO_ID_5699545523663911458" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Altra mail questa&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-8cS8bGal1Xk/Txjb2D_GPxI/AAAAAAAAnvI/Dfjt2Fu7cag/s1600/2%2Bmail%2Bw.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 176px;" src="http://1.bp.blogspot.com/-8cS8bGal1Xk/Txjb2D_GPxI/AAAAAAAAnvI/Dfjt2Fu7cag/s320/2%2Bmail%2Bw.jpg" alt="" id="BLOGGER_PHOTO_ID_5699547050266738450" border="0" /&gt;&lt;/a&gt;che a fronte del &lt;span style="font-weight: bold;"&gt;medesimo 'mittente' della precedente CartaSi &lt;/span&gt;informa di una possibilita' di &lt;span style="font-weight: bold;"&gt;effettuare una ricarica gratuita &lt;span style="color: rgb(204, 0, 0);"&gt;WIND&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo un &lt;span style="font-weight: bold;"&gt;dettaglio dell'header&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-iUdzUaAapzg/Txjb2odJpSI/AAAAAAAAnvg/MeYiy89QLa4/s1600/2%2Bheaders.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 66px;" src="http://2.bp.blogspot.com/-iUdzUaAapzg/Txjb2odJpSI/AAAAAAAAnvg/MeYiy89QLa4/s320/2%2Bheaders.jpg" alt="" id="BLOGGER_PHOTO_ID_5699547060056466722" border="0" /&gt;&lt;/a&gt;Come si vede anche in questo caso abbiamo l'uso dell'argomento&lt;span style="font-weight: bold;"&gt; ' ricarica telefonica gratis &lt;/span&gt;'  per cercare di sottrarre credenziali di carta di credito ed, in questo specifico caso &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;WIND &lt;/span&gt;anche di altri dati personali riservati.&lt;br /&gt;&lt;br /&gt;In effetti si tratta del medesimo&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; phishing WIND  &lt;/span&gt;visto il  17 gennaio        e &lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://edetools.blogspot.com/2012/01/wind-ricarica-gratuita-per-te-un-nuovo.html"&gt;descritto in maniera dettagliata  in questo post,&lt;/a&gt; dove pero', la mail non utilizzava allegato ma direttamente un layout ingannevole&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-lOTFtBg8nOs/TxTa0R-xZVI/AAAAAAAAnkk/ESoOmXtDs_4/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 274px;" src="http://1.bp.blogspot.com/-lOTFtBg8nOs/TxTa0R-xZVI/AAAAAAAAnkk/ESoOmXtDs_4/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5698420020245259602" border="0" /&gt;&lt;/a&gt;La differenza rispetto &lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://edetools.blogspot.com/2012/01/wind-ricarica-gratuita-per-te-un-nuovo.html"&gt;alla volta scorsa &lt;/a&gt;e' che ora il layout (logo e testo) sono inseriti in mail come allegato e non direttamente come layout del messaggio&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-FTQ36QLw2rU/Txjb2Z3jewI/AAAAAAAAnvU/Vs1Bv7FCbmY/s1600/2%2Blayout%2Ballegato.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 320px;" src="http://3.bp.blogspot.com/-FTQ36QLw2rU/Txjb2Z3jewI/AAAAAAAAnvU/Vs1Bv7FCbmY/s320/2%2Blayout%2Ballegato.jpg" alt="" id="BLOGGER_PHOTO_ID_5699547056140679938" border="0" /&gt;&lt;/a&gt;Il link presente punta comunque&lt;span style="font-weight: bold;"&gt; al medesimo sito visto in passato,  che presenta alcuni form&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-s1WLd2AkGAM/Txjb2yCb5eI/AAAAAAAAnvs/_Et2Px6Eaqg/s1600/2%2Bform%2Bsu%2Bsito.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 210px; height: 320px;" src="http://1.bp.blogspot.com/-s1WLd2AkGAM/Txjb2yCb5eI/AAAAAAAAnvs/_Et2Px6Eaqg/s320/2%2Bform%2Bsu%2Bsito.jpg" alt="" id="BLOGGER_PHOTO_ID_5699547062628771298" border="0" /&gt;&lt;/a&gt;che tentano di acquisire i dati di chi fosse caduto nel phishing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-7606990842237812418?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/7606990842237812418/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=7606990842237812418' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7606990842237812418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7606990842237812418'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/newsletter-di-gennaio-phishing-cartasi.html' title='&apos;Newsletter di Gennaio&apos;. Phishing CartaSi e WIND accomunati da alcuni dettagli mail (20 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-2jRhGGsae6I/TxjaV-RlAzI/AAAAAAAAnto/0bTUK4jJutI/s72-c/le%2B2%2Bmails%2B2012-01-20_080328.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8568929435120065142</id><published>2012-01-19T18:51:00.000+07:00</published><updated>2012-01-19T18:52:49.428+07:00</updated><title type='text'></title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;a href="http://4.bp.blogspot.com/-UJUb4UTkmYI/TxgD14lOvdI/AAAAAAAAntY/qm3TPLR7wcg/s1600/happy%2B2012.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 288px; height: 320px;" src="http://4.bp.blogspot.com/-UJUb4UTkmYI/TxgD14lOvdI/AAAAAAAAntY/qm3TPLR7wcg/s320/happy%2B2012.jpg" alt="" id="BLOGGER_PHOTO_ID_5699309552693853650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8568929435120065142?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8568929435120065142/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8568929435120065142' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8568929435120065142'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8568929435120065142'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/blog-post.html' title=''/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-UJUb4UTkmYI/TxgD14lOvdI/AAAAAAAAntY/qm3TPLR7wcg/s72-c/happy%2B2012.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6317573023178212272</id><published>2012-01-19T13:39:00.011+07:00</published><updated>2012-01-19T14:43:45.961+07:00</updated><title type='text'>Security Defender. Un fake AV sempre ben presente in rete (19 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Il  &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.bleepingcomputer.com/virus-removal/remove-security-defender"&gt; 10 febbraio 2011 www.bleepingcomputer.com&lt;/a&gt; pubblicava una guida su come rimuovere &lt;span style="font-weight: bold;"&gt;un fake Av denominato &lt;span style="color: rgb(255, 0, 0);"&gt;Security Defender&lt;/span&gt;&lt;/span&gt;,&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;&lt;/span&gt;come sono di quel periodo anche altre segnalazioni&lt;span style="font-weight: bold;"&gt; relative al fake AV.&lt;/span&gt;&lt;br /&gt;Caso abbastanza particolare,&lt;span style="font-weight: bold;"&gt; a distanza di quasi un anno, possiamo rilevare in rete decine di domini creati di recente, che si occupano della  'distribuzione' in rete di  &lt;span style="color: rgb(255, 0, 0);"&gt;Security Defender&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;, dimostrando che il&lt;span style="font-weight: bold;"&gt; fake Av e' ancora ben supportato da chi vuol distribuire questo genere di malware.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Vediamo alcuni dettagli:&lt;/span&gt;&lt;br /&gt;Questo un lungo elenco proposto sul forum di&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.malwaredomainlist.com/forums/"&gt; www.malwaredomainlist.com  &lt;/a&gt;con decine di indirizzi web attualmente attivi&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Id1z2TawUeY/Txe7wkDDL4I/AAAAAAAAnp0/wTVo1ppc8h0/s1600/lista.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 242px; height: 320px;" src="http://3.bp.blogspot.com/-Id1z2TawUeY/Txe7wkDDL4I/AAAAAAAAnp0/wTVo1ppc8h0/s320/lista.jpg" alt="" id="BLOGGER_PHOTO_ID_5699230296445235074" border="0" /&gt;&lt;/a&gt;tutti con dominio di primo livello come .IN (India). anche se comunque un&lt;span style="font-weight: bold;"&gt; whois punta a a server&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-kDnTubNUpBk/Txe8EZMuSLI/AAAAAAAAnqk/tyZ67rHsLIM/s1600/wh%2Be%2Bfile%2B2012-01-19_101518.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 173px;" src="http://1.bp.blogspot.com/-kDnTubNUpBk/Txe8EZMuSLI/AAAAAAAAnqk/tyZ67rHsLIM/s320/wh%2Be%2Bfile%2B2012-01-19_101518.jpg" alt="" id="BLOGGER_PHOTO_ID_5699230637130401970" border="0" /&gt;&lt;/a&gt;Da notare come a detta lista si aggiungano anche altri domini, rilevati attraverso diversi siti di analisi IP.&lt;br /&gt;&lt;br /&gt;Un whois mostra anche data recente di creazione dei domini che linkano al malware (dicembre 2011)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-2Quq70Ds0oo/Txe7w20r1mI/AAAAAAAAnqA/Y2HJHkzq15E/s1600/created.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 91px;" src="http://4.bp.blogspot.com/-2Quq70Ds0oo/Txe7w20r1mI/AAAAAAAAnqA/Y2HJHkzq15E/s320/created.jpg" alt="" id="BLOGGER_PHOTO_ID_5699230301485258338" border="0" /&gt;&lt;/a&gt;confermando cosi' che, nonostante  &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Security Defende&lt;/span&gt;r  sia ben noto da tempo, ci troviamo di fronte ad una nuova distribuzione dello stesso.&lt;br /&gt;&lt;br /&gt;Non sorprende quindi che&lt;span style="font-weight: bold;"&gt; VT mostri  un basso riconoscimento&lt;/span&gt; dell'eseguibile, dovuto anche al fatto che si tratta tutto o in parte solo di codice di loader e non di quello della falsa applicazione AV.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-zI5tPz0CaLQ/Txe7xeTTOnI/AAAAAAAAnqM/B7bpkvKphXo/s1600/top%2Bvt.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 132px;" src="http://2.bp.blogspot.com/-zI5tPz0CaLQ/Txe7xeTTOnI/AAAAAAAAnqM/B7bpkvKphXo/s320/top%2Bvt.jpg" alt="" id="BLOGGER_PHOTO_ID_5699230312082651762" border="0" /&gt;&lt;/a&gt;&lt;a href="http://1.bp.blogspot.com/-RR5nzXfL34E/Txe7xhOhnsI/AAAAAAAAnqY/JtYrZpKDTj4/s1600/vt%2Bposit.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 128px;" src="http://1.bp.blogspot.com/-RR5nzXfL34E/Txe7xhOhnsI/AAAAAAAAnqY/JtYrZpKDTj4/s320/vt%2Bposit.jpg" alt="" id="BLOGGER_PHOTO_ID_5699230312867929794" border="0" /&gt;&lt;/a&gt;Una analisi degli hash mostra inoltre che  i files scaricati variano spesso come contenuto, pratica abbastanza comune, per evitare maggiormente di essere rilevati dai reali software AV.&lt;br /&gt;&lt;br /&gt;Vediamo ora, a conferma dei contenuti  di fake AV,&lt;span style="font-weight: bold;"&gt; l'esecuzione (in vbox) di uno degli eseguibili scaricati:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Appena lanciato il file&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-dnnhs5mlpXM/TxfBQ09LX_I/AAAAAAAAnqw/SH75odQqijo/s1600/1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 223px;" src="http://4.bp.blogspot.com/-dnnhs5mlpXM/TxfBQ09LX_I/AAAAAAAAnqw/SH75odQqijo/s320/1.jpg" alt="" id="BLOGGER_PHOTO_ID_5699236348297961458" border="0" /&gt;&lt;/a&gt;abbiamo l'indicazione della fase&lt;span style="font-weight: bold;"&gt; di install con il download automatico del codice occorrente all'esecuzione del fake AV&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-8xD4BmzVoqk/TxfBRGH6XoI/AAAAAAAAnq8/yW1ZLIXHzBs/s1600/2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 188px;" src="http://4.bp.blogspot.com/-8xD4BmzVoqk/TxfBRGH6XoI/AAAAAAAAnq8/yW1ZLIXHzBs/s320/2.jpg" alt="" id="BLOGGER_PHOTO_ID_5699236352906387074" border="0" /&gt;&lt;/a&gt;e la successiva attivazione della fake &lt;span style="font-weight: bold;"&gt;scansione&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-PPO7U-Dt7y8/TxfBRcz6ZPI/AAAAAAAAnrM/BS3n2HdD4U4/s1600/3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 231px;" src="http://1.bp.blogspot.com/-PPO7U-Dt7y8/TxfBRcz6ZPI/AAAAAAAAnrM/BS3n2HdD4U4/s320/3.jpg" alt="" id="BLOGGER_PHOTO_ID_5699236358996518130" border="0" /&gt;&lt;/a&gt;Da notare come ci siano indicazioni estremamente dettagliate sulla natura del malware che sarebbe presente sul nostro PC.&lt;br /&gt;Una volta terminata la scansione fake ed il rilievo di codici malevoli (in realta' inesistenti ma la cui presenza e' ben simulata)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-q6jqhsxnWL4/TxfBR-CqNDI/AAAAAAAAnrU/tkiA9u7QGY0/s1600/4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 256px;" src="http://3.bp.blogspot.com/-q6jqhsxnWL4/TxfBR-CqNDI/AAAAAAAAnrU/tkiA9u7QGY0/s320/4.jpg" alt="" id="BLOGGER_PHOTO_ID_5699236367916741682" border="0" /&gt;&lt;/a&gt; troviamo una altrettanto dettagliata finestra con varie scelte sull'azione dell'antivirus (rimozione, messa in quarantena del file, ecc....) come  accade nei reali softwares AV&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-J3PgxM3ca9U/TxfBSBU8YkI/AAAAAAAAnrg/JVT0K5UggUA/s1600/5.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 286px;" src="http://2.bp.blogspot.com/-J3PgxM3ca9U/TxfBSBU8YkI/AAAAAAAAnrg/JVT0K5UggUA/s320/5.jpg" alt="" id="BLOGGER_PHOTO_ID_5699236368798736962" border="0" /&gt;&lt;/a&gt;Un tentativo di  rimuovere il malware segnalato dara' evidentemente esito negativo&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-BeFMFygdXb8/TxfCBDmnC2I/AAAAAAAAnrs/KcXg3MrNWpo/s1600/6.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 266px;" src="http://1.bp.blogspot.com/-BeFMFygdXb8/TxfCBDmnC2I/AAAAAAAAnrs/KcXg3MrNWpo/s320/6.jpg" alt="" id="BLOGGER_PHOTO_ID_5699237176863558498" border="0" /&gt;&lt;/a&gt; ed apparira' la proposta di registrazione del fake AV dietro relativo pagamento.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-CRUTPedPIqM/TxfCBRp6qoI/AAAAAAAAnr4/MDQ0SkkvSNg/s1600/7.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 262px;" src="http://1.bp.blogspot.com/-CRUTPedPIqM/TxfCBRp6qoI/AAAAAAAAnr4/MDQ0SkkvSNg/s320/7.jpg" alt="" id="BLOGGER_PHOTO_ID_5699237180635523714" border="0" /&gt;&lt;/a&gt;Ignorando la richiesta avremo, come succede in questi casi, sia la presenza di allerta sullo stato di 'infezione' del PC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-pVMe6iWK8fM/TxfCBn4d6uI/AAAAAAAAnsE/795QuTsSgIs/s1600/8.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 146px;" src="http://1.bp.blogspot.com/-pVMe6iWK8fM/TxfCBn4d6uI/AAAAAAAAnsE/795QuTsSgIs/s320/8.jpg" alt="" id="BLOGGER_PHOTO_ID_5699237186602134242" border="0" /&gt;&lt;/a&gt;ma anche , ad esempio all'apertura dei browser,  di messaggi di avviso e blocco della navigazione per motivi di sicurezza, es. con Firefox&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-4-c7AYk6O_Y/TxfCB4S7uAI/AAAAAAAAnsQ/g1GoEzGIoiA/s1600/9.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 250px;" src="http://4.bp.blogspot.com/-4-c7AYk6O_Y/TxfCB4S7uAI/AAAAAAAAnsQ/g1GoEzGIoiA/s320/9.jpg" alt="" id="BLOGGER_PHOTO_ID_5699237191008106498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;e con Explorer&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-0Rfa20rjr6Q/TxfCCKZh5EI/AAAAAAAAnsg/VNyCpw73W8I/s1600/10.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://3.bp.blogspot.com/-0Rfa20rjr6Q/TxfCCKZh5EI/AAAAAAAAnsg/VNyCpw73W8I/s320/10.jpg" alt="" id="BLOGGER_PHOTO_ID_5699237195867612226" border="0" /&gt;&lt;/a&gt;Altri messaggi appariranno ad intervalli piu' o meno regolari per indicarci dello stato compromesso del PC&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-a4gvDCiWzf8/TxfC2zLVP4I/AAAAAAAAnso/8JhKPalxfmI/s1600/11.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 182px;" src="http://2.bp.blogspot.com/-a4gvDCiWzf8/TxfC2zLVP4I/AAAAAAAAnso/8JhKPalxfmI/s320/11.jpg" alt="" id="BLOGGER_PHOTO_ID_5699238100167114626" border="0" /&gt;&lt;/a&gt;Caso abbastanza raro, abbiamo questa volta, la possibilita' di testare cosa succede in pratica attivando il fake AV.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-hIBBRmrOhvs/TxfC21bTICI/AAAAAAAAnsw/SwG4A-wDvsE/s1600/12.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://4.bp.blogspot.com/-hIBBRmrOhvs/TxfC21bTICI/AAAAAAAAnsw/SwG4A-wDvsE/s320/12.jpg" alt="" id="BLOGGER_PHOTO_ID_5699238100770955298" border="0" /&gt;&lt;/a&gt;E' stato infatti pubblicato in rete un codice di attivazione (al momento ancora valido) relativo proprio a Security Defender e che andiamo a provare.&lt;br /&gt;&lt;br /&gt;In effetti una volta inserito il codice abbiamo la conferma dell'avvenuta attivazione del fake AV e possiamo procedere alla rimozione (simulata) del malware trovato (in realta'  sempre rigorosamente inesistente')&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-z7HjiFEjuA8/TxfC3liHCdI/AAAAAAAAntM/ywmgV7pX4d4/s1600/14.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 234px;" src="http://3.bp.blogspot.com/-z7HjiFEjuA8/TxfC3liHCdI/AAAAAAAAntM/ywmgV7pX4d4/s320/14.jpg" alt="" id="BLOGGER_PHOTO_ID_5699238113684425170" border="0" /&gt;&lt;/a&gt;La rimozione termina con l'indicazione di avvenuta  completa bonifica del PC.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-ad69aqGx-zA/TxfC3PZzS-I/AAAAAAAAntA/PsgWAmT2AwI/s1600/13.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 226px;" src="http://1.bp.blogspot.com/-ad69aqGx-zA/TxfC3PZzS-I/AAAAAAAAntA/PsgWAmT2AwI/s320/13.jpg" alt="" id="BLOGGER_PHOTO_ID_5699238107743996898" border="0" /&gt;&lt;/a&gt;Caso particolare se reinstalliamo nuovamente il fake AV, otterremo ancora una volta l'allerta di presenza malware, con la ricomparsa di tutti i vari software malevoli che saranno cosi'   ritornati ad 'infestare' il nostro PC.&lt;br /&gt;&lt;br /&gt;Qui alcuni riferimenti a siti che trattano sia della rimozione del malware (post datato 2011)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.bleepingcomputer.com/virus-removal/remove-security-defender"&gt;&lt;span style="color: rgb(51, 102, 255);"&gt;http://www.bleepingcomputer.com/virus-removal/remove-security-defender&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;che della presenza attuale in rete&lt;span style="font-weight: bold;"&gt; di Security Defender&lt;/span&gt; che parrebbe aver trovato in questo &lt;span style="font-weight: bold;"&gt;inizio 2012&lt;/span&gt; un nuovo momento di 'notorieta''.&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 102, 255);" href="http://siri-urz.blogspot.com/2012/01/security-defender.html"&gt;http://siri-urz.blogspot.com/2012/01/security-defender.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;e con presente il codice &lt;span style="font-weight: bold;"&gt;usato per l'attivazione di test del fake AV.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Da notare che &lt;span style="font-weight: bold;"&gt;attivando il fake AV &lt;/span&gt;e' stato possibile usare &lt;span style="font-weight: bold;"&gt;l'opzione di default di un-install per i softwares in Windows, &lt;/span&gt;anche se sarebbe da &lt;span style="font-weight: bold;"&gt;verificare se realmente il software fake viene disinstallato o si tratti solo di una &lt;span style="font-style: italic;"&gt;'simulazione&lt;/span&gt;' di un-install.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Infatti, anche se apparentemente &lt;span style="font-weight: bold;"&gt;la disinstallazione di&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; Security Defender &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;e' andata a buon fine&lt;/span&gt;,  trattandosi di software di natura malware, non e' neppure da escludere che possano essere presenti e nascoste funzioni piu' pericolose (possibile codice trojan, backdoor ecc...)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6317573023178212272?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6317573023178212272/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6317573023178212272' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6317573023178212272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6317573023178212272'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/security-defender-un-fake-av-sempre-ben.html' title='Security Defender. Un fake AV sempre ben presente in rete (19 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Id1z2TawUeY/Txe7wkDDL4I/AAAAAAAAnp0/wTVo1ppc8h0/s72-c/lista.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-43601967825069605</id><published>2012-01-18T10:08:00.004+07:00</published><updated>2012-01-18T10:45:21.587+07:00</updated><title type='text'>Phishing PayPal con utilizzo di domini registrati allo scopo (18 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;L'alternativa all'uso di siti compromessi per ospitare redirect a phishing o cloni  di phishing, e' quella di registrare un nuovo dominio sul quale poi hostare i codici di  phishing o quelli di redirect al clone della banca.&lt;br /&gt;&lt;br /&gt;Per fare questo si possono utilizzare o servizi free (es. Altervista, molto utilizzato nei casi di phishing ai danni di banche IT a diffusione regionale) oppure servizi a pagamento di hosting (di solito a basso costo)&lt;br /&gt;&lt;br /&gt;Tra i vantaggi per i phishers ci sono la possibilita di creare nomi di dominio ed indirizzi web ingannevoli ma anche il fatto che, non essendo 'ospiti' su siti compromessi di 'terze parti', almeno in teoria, viene garantita una maggiore permanenza online dei cloni.&lt;br /&gt;&lt;br /&gt;Chiaramente, specialmente nel caso di servizi free, dato che chi mette online il clone od il redirect viola il regolamento del Free Hosting, la permanenza online in molti casi dura poco a causa della sospensione dell'account.&lt;br /&gt;&lt;br /&gt;Quello che vediamo ora e' un esempio di phishing&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; PayPal &lt;/span&gt;che sfrutta sia un servizio di &lt;span style="font-weight: bold;"&gt;hosting IT &lt;/span&gt;che&lt;span style="font-weight: bold;"&gt; un servizio free romeno per mettere online un clone in lingua inglese.&lt;/span&gt;&lt;br /&gt;Come si nota dalle date presenti sia di registrazione dei domini  che di upload  dei codici di phishing si tratta di &lt;span style="font-weight: bold;"&gt;phishing attuale e tuttora attivo.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ecco alcuni dettagli:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo il dominio usato &lt;span style="font-weight: bold;"&gt;per  il redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-r_3kuuQkOBI/TxY4QxKhLNI/AAAAAAAAnoU/WoRGbNicwfA/s1600/redir%2Bhome.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 147px;" src="http://1.bp.blogspot.com/-r_3kuuQkOBI/TxY4QxKhLNI/AAAAAAAAnoU/WoRGbNicwfA/s320/redir%2Bhome.jpg" alt="" id="BLOGGER_PHOTO_ID_5698804239210458322" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con  whois IT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-cIzUvMl8KWk/TxY4RPqIC6I/AAAAAAAAnog/Cdg2LcOokoc/s1600/wh%2Breir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 163px;" src="http://1.bp.blogspot.com/-cIzUvMl8KWk/TxY4RPqIC6I/AAAAAAAAnog/Cdg2LcOokoc/s320/wh%2Breir.jpg" alt="" id="BLOGGER_PHOTO_ID_5698804247396092834" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;e registrazione in data molto recente&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-QJyKyI2X88A/TxY4RRZcoqI/AAAAAAAAnos/FOQ1cV-Hlv8/s1600/reg%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 314px; height: 320px;" src="http://2.bp.blogspot.com/-QJyKyI2X88A/TxY4RRZcoqI/AAAAAAAAnos/FOQ1cV-Hlv8/s320/reg%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5698804247863009954" border="0" /&gt;&lt;/a&gt;L'alternativa al fatto che si tratti di dominio creato appositamente dai phishers, sarebbe l'avvenuta  compromissione dello stesso, a poche ore dalla sua attivazione da parte del provider IT.&lt;br /&gt;Cosa possibile ma comunque poco probabile anche alla luce dei dati del &lt;span style="font-weight: bold;"&gt;'registrant' &lt;/span&gt;che sembrano piu' di fantasia che reali.&lt;br /&gt;&lt;br /&gt;Altra obiezione al fatto che si tratti di &lt;span style="font-weight: bold;"&gt;dominio creato appositamente dai phishers&lt;/span&gt; e' perche' non si sia creato un nome ingannevole (di dominio),  per generare un indirizzo web piu legato al phishing &lt;span style="font-weight: bold;"&gt;PayPal, &lt;/span&gt;ma anche in questo caso si puo' obbiettare che essendo utilizzato per il redirect &lt;span style="font-weight: bold;"&gt;la relativa url non viene praticamente visualizzata nel browser&lt;/span&gt;, ma si passa subito a quella finale di hosting del clone.&lt;br /&gt;&lt;br /&gt;Sarebbe comunque interessante monitorare detto dominio per vedere se in futuro verra' usato per altre azioni di phishing anche non legate a PayPal.&lt;br /&gt;&lt;br /&gt;Tornando al  &lt;span style="font-weight: bold;"&gt;redirect, questo punta a dominio creato sfruttando un servizio free web romeno&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-vOL927rPYWk/TxY4RthRtoI/AAAAAAAAno4/ziz_iCFHUlI/s1600/home%2Bro%2B%2Breg%2B2012-01-18_090920.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 106px;" src="http://4.bp.blogspot.com/-vOL927rPYWk/TxY4RthRtoI/AAAAAAAAno4/ziz_iCFHUlI/s320/home%2Bro%2B%2Breg%2B2012-01-18_090920.jpg" alt="" id="BLOGGER_PHOTO_ID_5698804255412041346" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;su server&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-IqqcZkGJW7w/TxY4-2Qb8tI/AAAAAAAAnpQ/gLKNtJry_7E/s1600/clone%2Bwh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 149px;" src="http://3.bp.blogspot.com/-IqqcZkGJW7w/TxY4-2Qb8tI/AAAAAAAAnpQ/gLKNtJry_7E/s320/clone%2Bwh.jpg" alt="" id="BLOGGER_PHOTO_ID_5698805030851441362" border="0" /&gt;&lt;/a&gt;Un dettaglio della struttura del phishing mostra&lt;span style="font-weight: bold;"&gt; date di ieri (17/1) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-eFgNFUAD7cI/TxY4_r_d_xI/AAAAAAAAnpo/zM_hQv31PFM/s1600/stru%2B2%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 175px;" src="http://4.bp.blogspot.com/-eFgNFUAD7cI/TxY4_r_d_xI/AAAAAAAAnpo/zM_hQv31PFM/s320/stru%2B2%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5698805045275787026" border="0" /&gt;&lt;/a&gt;Il clone ripropone il consueto form di acquisizione dati &lt;span style="font-weight: bold;"&gt;sia anagrafici che di carta di credito,&lt;/span&gt; in linea con l'attuale tendenza del phishing che vede sempre piu' diffuso il furto di credenziali di carta di credito&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-tE0Iu2BurKM/TxY4_ENRsKI/AAAAAAAAnpg/7AC1yJ10DLA/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 289px; height: 320px;" src="http://2.bp.blogspot.com/-tE0Iu2BurKM/TxY4_ENRsKI/AAAAAAAAnpg/7AC1yJ10DLA/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5698805034596282530" border="0" /&gt;&lt;/a&gt;Il form non effettua particolari verifiche sui dati inseriti tranne che per la presenza o meno degli stessi e redige poi a reale pagina &lt;span style="font-weight: bold;"&gt;UK di PayPal.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-u1pOS1EudI4/TxY4SF0OhuI/AAAAAAAAnpE/hkNHkKv2h8U/s1600/reale%2Bredi%2Bpay.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 208px;" src="http://3.bp.blogspot.com/-u1pOS1EudI4/TxY4SF0OhuI/AAAAAAAAnpE/hkNHkKv2h8U/s320/reale%2Bredi%2Bpay.jpg" alt="" id="BLOGGER_PHOTO_ID_5698804261933975266" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-43601967825069605?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/43601967825069605/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=43601967825069605' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/43601967825069605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/43601967825069605'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-paypal-con-utilizzo-di-domini.html' title='Phishing PayPal con utilizzo di domini registrati allo scopo (18 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-r_3kuuQkOBI/TxY4QxKhLNI/AAAAAAAAnoU/WoRGbNicwfA/s72-c/redir%2Bhome.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6704541359991468892</id><published>2012-01-17T17:47:00.003+07:00</published><updated>2012-01-17T17:58:30.051+07:00</updated><title type='text'>Verified by Visa (17 gennaio)</title><content type='html'>Ricevute diverse&lt;span style="font-weight: bold;"&gt; mails che propongono un messaggio &lt;span style="color: rgb(255, 0, 0);"&gt;Verified by Visa&lt;/span&gt; &lt;/span&gt;e tra le quali vediamo ad esempio questa&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-gxtX3RhzfOY/TxVSLNwcCkI/AAAAAAAAnng/h2U6PhSov_U/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 197px;" src="http://4.bp.blogspot.com/-gxtX3RhzfOY/TxVSLNwcCkI/AAAAAAAAnng/h2U6PhSov_U/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5698551256132094530" border="0" /&gt;&lt;/a&gt;Si tratta di mail con allegato (non htm ma &lt;span style="font-weight: bold;"&gt;.mht&lt;/span&gt;) che aperto nel browser mostra form&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-IPG-F9nXWos/TxVSK-6lRrI/AAAAAAAAnnY/tHG_yyBlyEw/s1600/form%2B2012-01-17_151012.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 285px; height: 320px;" src="http://4.bp.blogspot.com/-IPG-F9nXWos/TxVSK-6lRrI/AAAAAAAAnnY/tHG_yyBlyEw/s320/form%2B2012-01-17_151012.jpg" alt="" id="BLOGGER_PHOTO_ID_5698551252148111026" border="0" /&gt;&lt;/a&gt;ricco di campi di input che spaziano dai dati anagrafici sino ai dati di carta di credito,  password &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Verified by Visa&lt;/span&gt; ecc......&lt;br /&gt;&lt;br /&gt;In pratica si cerca di &lt;span style="font-weight: bold;"&gt;acquisire con l'ausilio di  un solo form&lt;/span&gt; tutta quella tipologia di dati che avevamo visto&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/wind-ricarica-gratuita-per-te-un-nuovo.html"&gt; acquisire con il phishing WIND questa mattina attraverso l'uso di diverse pagine &lt;/a&gt;  (in piu' anche la data di nascita probabilmente utile in caso di cambio password)&lt;br /&gt;&lt;br /&gt;Il codice php di gestione del form&lt;span style="font-weight: bold;"&gt; viene hostato su dominio USA &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-mMVNl68HLjY/TxVSL3LOyhI/AAAAAAAAnoI/GEmNMMGq7UY/s1600/wh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 125px;" src="http://1.bp.blogspot.com/-mMVNl68HLjY/TxVSL3LOyhI/AAAAAAAAnoI/GEmNMMGq7UY/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5698551267250326034" border="0" /&gt;&lt;/a&gt;creato in data attuale e sul quale e' presente anche una copia del form allegato in mail.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-1CELwhDg6fY/TxVSLffZXCI/AAAAAAAAnnw/9gtQlrgAQ9U/s1600/registr.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 272px;" src="http://2.bp.blogspot.com/-1CELwhDg6fY/TxVSLffZXCI/AAAAAAAAnnw/9gtQlrgAQ9U/s320/registr.jpg" alt="" id="BLOGGER_PHOTO_ID_5698551260892453922" border="0" /&gt;&lt;/a&gt;Questo un particolare del folder che ospita alcuni files.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-cT0UYqKFDE8/TxVSLnDcH2I/AAAAAAAAnn8/D0RIKdEOok8/s1600/stru%2B1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 299px;" src="http://2.bp.blogspot.com/-cT0UYqKFDE8/TxVSLnDcH2I/AAAAAAAAnn8/D0RIKdEOok8/s320/stru%2B1.jpg" alt="" id="BLOGGER_PHOTO_ID_5698551262922678114" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6704541359991468892?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6704541359991468892/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6704541359991468892' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6704541359991468892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6704541359991468892'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/verified-by-visa-17-gennaio.html' title='Verified by Visa (17 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-gxtX3RhzfOY/TxVSLNwcCkI/AAAAAAAAnng/h2U6PhSov_U/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5828359763695520256</id><published>2012-01-17T14:36:00.003+07:00</published><updated>2012-01-17T14:45:27.675+07:00</updated><title type='text'>Ancora  phishing Cassa di Risparmio di Bolzano (17 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Poche righe per informare delle&lt;span style="font-weight: bold;"&gt; numerose mail di phishing ricevute in data odierna&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-VrvmPji9uwM/TxUlUmHXOEI/AAAAAAAAnmo/Aet1Q6GEjB8/s1600/mails.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 47px;" src="http://1.bp.blogspot.com/-VrvmPji9uwM/TxUlUmHXOEI/AAAAAAAAnmo/Aet1Q6GEjB8/s320/mails.jpg" alt="" id="BLOGGER_PHOTO_ID_5698501939266271298" border="0" /&gt;&lt;/a&gt;e tutte ai danni di &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Cassa di Risparmio di Bolzano&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Z76FAAkFMFs/TxUlzT7HrkI/AAAAAAAAnnA/WEPhNmbceoA/s1600/clon.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 174px;" src="http://4.bp.blogspot.com/-Z76FAAkFMFs/TxUlzT7HrkI/AAAAAAAAnnA/WEPhNmbceoA/s320/clon.jpg" alt="" id="BLOGGER_PHOTO_ID_5698502466959027778" border="0" /&gt;&lt;/a&gt;Questo il dettaglio del messaggio&lt;span style="font-weight: bold;"&gt; in mail diverso da quello di ieri&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-aIMY_EPnJ9I/TxUlzU6NbsI/AAAAAAAAnnM/kEyg1eUe3EY/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 175px;" src="http://2.bp.blogspot.com/-aIMY_EPnJ9I/TxUlzU6NbsI/AAAAAAAAnnM/kEyg1eUe3EY/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5698502467223645890" border="0" /&gt;&lt;/a&gt;con link a redirect &lt;a style="color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/continua-il-phishing-ai-danni-della_16.html"&gt;&lt;span style="font-weight: bold;"&gt; sempre ospitato sul medesimo sito visto ieri.&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Al momento il clone&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Z76FAAkFMFs/TxUlzT7HrkI/AAAAAAAAnnA/WEPhNmbceoA/s1600/clon.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 174px;" src="http://4.bp.blogspot.com/-Z76FAAkFMFs/TxUlzT7HrkI/AAAAAAAAnnA/WEPhNmbceoA/s320/clon.jpg" alt="" id="BLOGGER_PHOTO_ID_5698502466959027778" border="0" /&gt;&lt;/a&gt;e' invece hostato nuovamente &lt;span style="font-weight: bold;"&gt;su dominio 'USA e getta' creato in data attuale.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-KCzIiMxEEMg/TxUlUyudolI/AAAAAAAAnm0/caaye_5CS9A/s1600/registr.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://4.bp.blogspot.com/-KCzIiMxEEMg/TxUlUyudolI/AAAAAAAAnm0/caaye_5CS9A/s320/registr.jpg" alt="" id="BLOGGER_PHOTO_ID_5698501942651494994" border="0" /&gt;&lt;/a&gt;Una analisi degli IP riferiti a chi visita il sito di phishing mostra nuovamente &lt;span style="font-weight: bold;"&gt;il 'solito' ip est europeo di ieri come primo IP registrato &lt;/span&gt;ed altri IP tra cui chiaramente alcuni IT.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-GzYmXeblBUI/TxUlUR8oBgI/AAAAAAAAnmc/94wMwdivC1A/s1600/logs%2B2012-01-17_140153.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 149px;" src="http://1.bp.blogspot.com/-GzYmXeblBUI/TxUlUR8oBgI/AAAAAAAAnmc/94wMwdivC1A/s320/logs%2B2012-01-17_140153.jpg" alt="" id="BLOGGER_PHOTO_ID_5698501933852526082" border="0" /&gt;&lt;/a&gt;Come al solito ci si aspettano cambiamenti sull'hosting del clone onde evitare  black-listing o la messa off-line del sito che ospita il clone.&lt;br /&gt;&lt;br /&gt;Da notare, come gia' accaduto ieri,  che pur avendo ricevuto diverse mails nelle prime ore della giornata, i link presenti puntavano ad old dominio usato in passato dai phishers e non piu'  online, per poi diventare attivi da poco.&lt;br /&gt;&lt;br /&gt;Puo trattarsi semplicemente di work in progress da parte dei phishers o, come accenna anche Denis Frati&lt;a href="http://www.denisfrati.it/2012/01/16/r-team-ancora-su-cr-bolzano/"&gt; in un suo post&lt;/a&gt;, ,di una tecnica per attivare i cloni solo al momento che le mail sono giunte a destinazione, per evitare quindi la messa off-line preventiva delle pagine di phishing.&lt;br /&gt;&lt;br /&gt;Inoltre, utilizzando sempre il medesimo indirizzo di redirect, anche tutte le mails inviate in precedenza nella giornata di ieri sono attualmente perfettamente attive nel linkare al nuovo clone &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Cassa di Risparmio di Bolzano.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5828359763695520256?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5828359763695520256/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5828359763695520256' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5828359763695520256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5828359763695520256'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/ancora-phishing-cassa-di-risparmio-di.html' title='Ancora  phishing Cassa di Risparmio di Bolzano (17 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-VrvmPji9uwM/TxUlUmHXOEI/AAAAAAAAnmo/Aet1Q6GEjB8/s72-c/mails.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8932486012866028642</id><published>2012-01-17T09:17:00.006+07:00</published><updated>2012-01-17T12:35:26.073+07:00</updated><title type='text'>'WIND Ricarica Gratuita per te!!' Un nuovo caso di phishing altamente ingannevole. (17 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Lo scopo degli attacchi di phishing e' di solito legato all'acquisizione di dati personali relativi ad accesso a conti bancari on-line, al furto di credenziali di carta di credito, al furto di altri dati personali riservati, come indirizzi mail (compreso la  password di accesso), dati anagrafici della persona bersaglio del phishing, ecc.... che potrebbero essere utili ai phishers per sviluppare un successivo attacco.&lt;br /&gt;&lt;br /&gt;Quello che si nota, e' che una mail di phishing&lt;span style="font-style: italic;"&gt; 'classica' &lt;/span&gt;essendo generalmente riferita ad una singola banca od azienda, ha dei limiti relativamente alla possibilita' di riuscita dell'attacco stesso (evidentemente se non sono cliente della banca target non saro' interessato a seguire i 'consigli' presenti in mail) ed anche i dati da acquisire si limitano,di solito, a  credenziali di carta di credito (molto di piu negli ultimi mesi che in passato), o di accesso al conto online.... (pratica ultimamente contrastata attraverso dispositivi hardware di verifica accesso al conto online).&lt;br /&gt;&lt;br /&gt;Oltre al fatto che il numero di possibili bersagli offerto da un fake messaggio che prenda di mira una compagnia di telefonia mobile e' certamente molto piu' ampio, &lt;span style="font-weight: bold;"&gt;(milioni di utenti)&lt;/span&gt;, una azione di phishing come quella che vedremo, si sviluppa, per sua stessa natura, con la &lt;span style="font-weight: bold;"&gt;richiesta sia di dati personali (in primo luogo il numero di telefono ma anche indirizzo, cod.fiscale o partiva IVA ecc... ) e con l'acquisizione di numeri di carta di credito relativamente al pagamento on-line della ricarica telefonica.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Un phishing quindi che spazia su un &lt;span style="font-weight: bold;"&gt;ampia scelta di possibili dati sensibili da acquisire&lt;/span&gt; e che puo' essere facilmente strutturato in maniera altamente ingannevole.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Vediamo alcuni dettagli:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questa una delle mail ricevute&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-lOTFtBg8nOs/TxTa0R-xZVI/AAAAAAAAnkk/ESoOmXtDs_4/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 274px;" src="http://1.bp.blogspot.com/-lOTFtBg8nOs/TxTa0R-xZVI/AAAAAAAAnkk/ESoOmXtDs_4/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5698420020245259602" border="0" /&gt;&lt;/a&gt;con semplice testo in buon italiano e con logo &lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt;WIND&lt;/span&gt; acquisito da sito IT che si occupa di tariffe di servizi telefonici&lt;br /&gt;Questo un dettaglio dei riferimenti ai nomi dei files logo gif  utilizzati dal messaggio e nel reale sito&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Gj_cMv8rfTc/TxTa08H9ldI/AAAAAAAAnk8/VK4rm9CdQ_A/s1600/img%2Blogo%2Bsource.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 174px;" src="http://3.bp.blogspot.com/-Gj_cMv8rfTc/TxTa08H9ldI/AAAAAAAAnk8/VK4rm9CdQ_A/s320/img%2Blogo%2Bsource.jpg" alt="" id="BLOGGER_PHOTO_ID_5698420031558096338" border="0" /&gt;&lt;/a&gt;Una analisi dell'header in mail presenta anche riferimenti ad IP italiani&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-wl1TfPIeNZE/TxTa0gN8ZrI/AAAAAAAAnkw/TOfLG3R8Adg/s1600/headers%2B2012-01-16_214905.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 68px;" src="http://1.bp.blogspot.com/-wl1TfPIeNZE/TxTa0gN8ZrI/AAAAAAAAnkw/TOfLG3R8Adg/s320/headers%2B2012-01-16_214905.jpg" alt="" id="BLOGGER_PHOTO_ID_5698420024066991794" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Il clone&lt;span style="color: rgb(255, 102, 0);"&gt; WIND &lt;/span&gt;linkato in mail &lt;/span&gt;utilizza hosting su server USA e dominio creato in data attuale per ospitare i fakes forms di richiesta dati (registrazione dominio a nome di italiano anche se dato non significativo)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-A6FxGylNDf0/TxTbuaqsxFI/AAAAAAAAnlI/mHt2ahFx-Uk/s1600/registraz.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 233px;" src="http://4.bp.blogspot.com/-A6FxGylNDf0/TxTbuaqsxFI/AAAAAAAAnlI/mHt2ahFx-Uk/s320/registraz.jpg" alt="" id="BLOGGER_PHOTO_ID_5698421019009401938" border="0" /&gt;&lt;/a&gt;Ecco invece alcuni dettagli &lt;span style="font-weight: bold;"&gt;dell'accurato form di richiesta dati&lt;/span&gt; che presenta nella prima parte quella   del numero telefonico e di una mail di riferimento (dato utile ai phishers per acquisire eventuali nuovi indirizzi mail se diversi da quello usato nel phishing attuale)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-A7qPrzQtQew/TxTa0JKeNxI/AAAAAAAAnkU/yYnxkHfltGw/s1600/1%2Btop.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 208px;" src="http://1.bp.blogspot.com/-A7qPrzQtQew/TxTa0JKeNxI/AAAAAAAAnkU/yYnxkHfltGw/s320/1%2Btop.jpg" alt="" id="BLOGGER_PHOTO_ID_5698420017878415122" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-pEnzVHrmY5k/TxTaz_BbUbI/AAAAAAAAnkM/vZ5aS9TidgE/s1600/1%2Bbottom.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://1.bp.blogspot.com/-pEnzVHrmY5k/TxTaz_BbUbI/AAAAAAAAnkM/vZ5aS9TidgE/s320/1%2Bbottom.jpg" alt="" id="BLOGGER_PHOTO_ID_5698420015156122034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Si passa poi alla richiesta di &lt;span style="font-weight: bold;"&gt;dati anagrafici e fiscali&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-IP29IohVe44/TxTbuX-kAUI/AAAAAAAAnlQ/NYfTVSBBBqI/s1600/attendere.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 214px;" src="http://4.bp.blogspot.com/-IP29IohVe44/TxTbuX-kAUI/AAAAAAAAnlQ/NYfTVSBBBqI/s320/attendere.jpg" alt="" id="BLOGGER_PHOTO_ID_5698421018287407426" border="0" /&gt;&lt;/a&gt;per proseguire (dopo&lt;span style="font-style: italic; font-weight: bold;"&gt; simulazione di ritardo&lt;/span&gt; dovuto alla connessione di trasferimento dato in corso) alla richiesta dei&lt;span style="font-weight: bold;"&gt; dati di carta di credito&lt;/span&gt; (ampia scelta)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-avlD5VHOyDI/TxTbukhGBKI/AAAAAAAAnlg/2fB3xERWEu4/s1600/carta%2Bdati.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 272px;" src="http://3.bp.blogspot.com/-avlD5VHOyDI/TxTbukhGBKI/AAAAAAAAnlg/2fB3xERWEu4/s320/carta%2Bdati.jpg" alt="" id="BLOGGER_PHOTO_ID_5698421021653468322" border="0" /&gt;&lt;/a&gt;Da notare come &lt;span style="font-weight: bold;"&gt;un confronto del presunto numero di ordine in due differenti sessioni di link al fake sito &lt;span style="color: rgb(255, 102, 0);"&gt;Wind &lt;/span&gt;mostri &lt;span style="color: rgb(204, 0, 0);"&gt;identico valore&lt;/span&gt;  !!!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-WFnJDguG5eg/TxTbuzbPkUI/AAAAAAAAnls/D9VDWygdcA8/s1600/ordine%2Bfake.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 138px;" src="http://1.bp.blogspot.com/-WFnJDguG5eg/TxTbuzbPkUI/AAAAAAAAnls/D9VDWygdcA8/s320/ordine%2Bfake.jpg" alt="" id="BLOGGER_PHOTO_ID_5698421025655460162" border="0" /&gt;&lt;/a&gt;Una volta acquisiti questi dati, viene richiesta anche la password relativa al servizio '&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Verified by VISA'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-rSrXwHcyTDg/TxTbvOd9CTI/AAAAAAAAnl0/eHhRUttP8-k/s1600/ulteriore%2Bby%2Bvisa.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 263px;" src="http://4.bp.blogspot.com/-rSrXwHcyTDg/TxTbvOd9CTI/AAAAAAAAnl0/eHhRUttP8-k/s320/ulteriore%2Bby%2Bvisa.jpg" alt="" id="BLOGGER_PHOTO_ID_5698421032914585906" border="0" /&gt;&lt;/a&gt;permettendo cosi' ai phishers di  completare l'acquisizione di una&lt;span style="font-weight: bold;"&gt; notevole quantita' di dati personali sensibili.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Si passa poi allo screen finale dove si &lt;span style="font-weight: bold;"&gt;conferma la ricarica free e l'invio all'indirizzo mail indicato nel form, di conferma della ricarica&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-DsAG4xEpW9A/TxTctLH43PI/AAAAAAAAnmQ/odh3-ogx4H0/s1600/finale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 231px;" src="http://3.bp.blogspot.com/-DsAG4xEpW9A/TxTctLH43PI/AAAAAAAAnmQ/odh3-ogx4H0/s320/finale.jpg" alt="" id="BLOGGER_PHOTO_ID_5698422097168620786" border="0" /&gt;&lt;/a&gt;Successivamente si viene rediretti al &lt;span style="font-weight: bold;"&gt;reale sito &lt;span style="color: rgb(255, 102, 0);"&gt;WIND&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Olw07K7e5pk/TxTcs_s1FFI/AAAAAAAAnmE/Y3dn8pAGT74/s1600/reale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 226px;" src="http://3.bp.blogspot.com/-Olw07K7e5pk/TxTcs_s1FFI/AAAAAAAAnmE/Y3dn8pAGT74/s320/reale.jpg" alt="" id="BLOGGER_PHOTO_ID_5698422094102336594" border="0" /&gt;&lt;/a&gt;Un phishing quindi &lt;span style="font-weight: bold;"&gt;altamente ingannevole &lt;/span&gt;e che presenta un livello di dettaglio di acquisizione dati personali &lt;span style="font-weight: bold;"&gt;estremante elevato.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Anche se probabilmente alcuni dati di chi cade nel phishing potrebbero essere richiesti solo per aumentare la natura ingannevole del sito, non e' neppure da escludere che gli stessi servano poi per ulteriori azioni ai danni di utenti&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt; Wind.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Come gia accaduto altre volte uno dei pochi&lt;span style="font-weight: bold;"&gt; 'punti deboli' &lt;/span&gt;di questo attacco potrebbe  essere l'indirizzo web utilizzato per il fake sito&lt;span style="color: rgb(255, 102, 0); font-weight: bold;"&gt; WIND &lt;/span&gt;che non ricorda quello del reale dominio Wind.&lt;br /&gt;&lt;br /&gt;Una ragione in piu' per &lt;span style="font-weight: bold;"&gt;verificare sempre accuratamente &lt;/span&gt;l'indirizzo web a cui si viene linkati da mail dubbie  e possibilmente anche l'IP number relativo al sito a cui si e' connessi.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8932486012866028642?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8932486012866028642/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8932486012866028642' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8932486012866028642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8932486012866028642'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/wind-ricarica-gratuita-per-te-un-nuovo.html' title='&apos;WIND Ricarica Gratuita per te!!&apos; Un nuovo caso di phishing altamente ingannevole. (17 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-lOTFtBg8nOs/TxTa0R-xZVI/AAAAAAAAnkk/ESoOmXtDs_4/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6601995545186990634</id><published>2012-01-16T17:34:00.007+07:00</published><updated>2012-01-16T18:36:46.013+07:00</updated><title type='text'>Continua il phishing ai danni della Cassa di Risparmio di Bolzano (16 gennaio) [aggiornato ore 18.30 thai]</title><content type='html'>A distanza ormai di qualche giorno dalla comparsa di un phishing ai danni di  &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Cassa di Risparmio di Bolzano&lt;/span&gt;, abbiamo nuovamente online un &lt;span style="font-weight: bold;"&gt;clone ospitato, in un primo momento su servizio free Altervista&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-EumgwxebMEc/TxP9w6Til6I/AAAAAAAAnic/PCVREJFA8es/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 181px;" src="http://3.bp.blogspot.com/-EumgwxebMEc/TxP9w6Til6I/AAAAAAAAnic/PCVREJFA8es/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5698176970280572834" border="0" /&gt;&lt;/a&gt;per passare poi, nel corso della giornata, &lt;span style="font-weight: bold;"&gt;su servizio USA di hosting a basso costo&lt;/span&gt; molto utilizzato in passato&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-cFY4acDDZT8/TxP9xmblvVI/AAAAAAAAnjA/xxNLb66W9qc/s1600/new%2Bclone%2Bsu%2Busa.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 278px;" src="http://1.bp.blogspot.com/-cFY4acDDZT8/TxP9xmblvVI/AAAAAAAAnjA/xxNLb66W9qc/s320/new%2Bclone%2Bsu%2Busa.jpg" alt="" id="BLOGGER_PHOTO_ID_5698176982125493586" border="0" /&gt;&lt;/a&gt;Una analisi del traffico IP sul server USA mostra in massima parte indirizzi di provenienza italiana a parte il consueto est europeo.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-BXQwpvl1C-4/TxQEOY4iNyI/AAAAAAAAnjk/xa6XMDNIuKc/s1600/ip.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 314px;" src="http://2.bp.blogspot.com/-BXQwpvl1C-4/TxQEOY4iNyI/AAAAAAAAnjk/xa6XMDNIuKc/s320/ip.jpg" alt="" id="BLOGGER_PHOTO_ID_5698184073774774050" border="0" /&gt;&lt;/a&gt;La cosa &lt;span style="font-style: italic; font-weight: bold;"&gt;'folcloristica' &lt;/span&gt;rispetto &lt;span style="font-weight: bold;"&gt;all'IP romeno estratto dai log &lt;/span&gt;e' che, &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;geo-localizzandolo otteniamo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-vj6wfyM6ReE/TxQIsme3PxI/AAAAAAAAnj8/_c-GUz7vwio/s1600/obf%2Bgeo.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 204px;" src="http://4.bp.blogspot.com/-vj6wfyM6ReE/TxQIsme3PxI/AAAAAAAAnj8/_c-GUz7vwio/s320/obf%2Bgeo.jpg" alt="" id="BLOGGER_PHOTO_ID_5698188990867783442" border="0" /&gt;&lt;/a&gt;che &lt;span style="font-weight: bold;"&gt;ricorda molto da vicino un articolo &lt;a style="color: rgb(51, 51, 255);" href="http://edetools.blogspot.com/2011/12/la-capitale-degli-hacker-e-in-romania.html"&gt;apparso su Le Monde &lt;/a&gt;&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://edetools.blogspot.com/2011/12/la-capitale-degli-hacker-e-in-romania.html"&gt;e riproposto da ANSA&lt;/a&gt; :&lt;br /&gt;&lt;br /&gt;“&lt;span style="font-style: italic; color: rgb(0, 0, 102);"&gt;.......... La capitale mondiale delle truffe via Internet si trova in Romania, ai piedi dei Carpazi: e' Ramnicu Valcea, meglio nota tra i cybercriminali come 'Hackerville'. Lo racconta il quotidiano francese Le Monde, che ha incontrato gli abitanti di questa cittadina immersa nel verde, ben poco fieri del motivo per cui e' diventata celebre. ''Ramnicu Valcea e' senza dubbio la citta' romena piu' conosciuta negli Usa - racconta Stelian Petrescu, professore di geografia - gli americani non ............ &lt;/span&gt; (da &lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.ansa.it/web/notizie/rubriche/mondo/2011/12/29/visualizza_new.html_19268508.html"&gt;Ansa&lt;/a&gt; it)“&lt;br /&gt;&lt;br /&gt;Le &lt;span style="font-weight: bold;"&gt;numerose  mail ricevute nelle prime ore della giornata,&lt;/span&gt; quando in Italia era ancora notte,&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-TF3FIs0ayck/TxP9xcjUTlI/AAAAAAAAni0/EflqUfbRyxc/s1600/mails.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 182px;" src="http://3.bp.blogspot.com/-TF3FIs0ayck/TxP9xcjUTlI/AAAAAAAAni0/EflqUfbRyxc/s320/mails.jpg" alt="" id="BLOGGER_PHOTO_ID_5698176979473550930" border="0" /&gt;&lt;/a&gt;hanno questo tipico &lt;span style="font-weight: bold;"&gt;layout&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-FIc22HffoS0/TxP9wxtMUdI/AAAAAAAAnis/-t9Be6vMajM/s1600/mail%2B2012-01-16_141606.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://1.bp.blogspot.com/-FIc22HffoS0/TxP9wxtMUdI/AAAAAAAAnis/-t9Be6vMajM/s320/mail%2B2012-01-16_141606.jpg" alt="" id="BLOGGER_PHOTO_ID_5698176967972245970" border="0" /&gt;&lt;/a&gt;e puntano tutte a redirect hostato su&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-DImCe99Ts18/TxP9x3eioRI/AAAAAAAAnjI/VdpS7IGh8Os/s1600/redir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 210px;" src="http://3.bp.blogspot.com/-DImCe99Ts18/TxP9x3eioRI/AAAAAAAAnjI/VdpS7IGh8Os/s320/redir.jpg" alt="" id="BLOGGER_PHOTO_ID_5698176986701275410" border="0" /&gt;&lt;/a&gt;C'e' da rilevare che al momento &lt;span style="font-weight: bold;"&gt;della ricezione dei messaggi, il redirect non era ancora stato attivato, cosa che e' avvenuta dopo qualche ora.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In effetti anche una analisi dei dati presenti&lt;span style="font-weight: bold;"&gt; sulla registrazione del dominio free Altervista &lt;/span&gt;mostrano che&lt;span style="font-weight: bold;"&gt; gia' da ieri era stato attivato l'account&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-f7cT4H1wS2Q/TxP94kT0DOI/AAAAAAAAnjY/E-N3ILUeibc/s1600/reg%2Baltervista.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 187px;" src="http://4.bp.blogspot.com/-f7cT4H1wS2Q/TxP94kT0DOI/AAAAAAAAnjY/E-N3ILUeibc/s320/reg%2Baltervista.jpg" alt="" id="BLOGGER_PHOTO_ID_5698177101815090402" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6601995545186990634?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6601995545186990634/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6601995545186990634' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6601995545186990634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6601995545186990634'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/continua-il-phishing-ai-danni-della_16.html' title='Continua il phishing ai danni della Cassa di Risparmio di Bolzano (16 gennaio) [aggiornato ore 18.30 thai]'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-EumgwxebMEc/TxP9w6Til6I/AAAAAAAAnic/PCVREJFA8es/s72-c/clone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6756718290856417153</id><published>2012-01-16T13:23:00.004+07:00</published><updated>2012-01-16T13:35:17.933+07:00</updated><title type='text'>Phishing PosteIT attraverso il 'solito' bonus (16 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Il 'bonus' in denaro nei messaggi di phishing ai danni di &lt;span style="color: rgb(255, 0, 0);"&gt;PosteIT&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;e' sicuramente un 'classico' che e' presente in rete ormai da anni.&lt;br /&gt;&lt;br /&gt;Questa &lt;span style="font-weight: bold;"&gt;l'odierna mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-PBwKaihyafQ/TxPC263NnnI/AAAAAAAAnhQ/Clof6W0uGNo/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 192px;" src="http://2.bp.blogspot.com/-PBwKaihyafQ/TxPC263NnnI/AAAAAAAAnhQ/Clof6W0uGNo/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5698112202323369586" border="0" /&gt;&lt;/a&gt;che vede un header con questi IP (uno IT)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-k3Ms9OiSDZY/TxPDDWxU94I/AAAAAAAAnhg/FhOiQHPDoGI/s1600/headers.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 55px;" src="http://3.bp.blogspot.com/-k3Ms9OiSDZY/TxPDDWxU94I/AAAAAAAAnhg/FhOiQHPDoGI/s320/headers.jpg" alt="" id="BLOGGER_PHOTO_ID_5698112415973308290" border="0" /&gt;&lt;/a&gt;Il &lt;span style="font-weight: bold;"&gt;redirect e hostato su&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-wkx4cx-JKro/TxPC2I-UoyI/AAAAAAAAngw/90lRAFCNQtk/s1600/redir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 162px;" src="http://2.bp.blogspot.com/-wkx4cx-JKro/TxPC2I-UoyI/AAAAAAAAngw/90lRAFCNQtk/s320/redir.jpg" alt="" id="BLOGGER_PHOTO_ID_5698112188931416866" border="0" /&gt;&lt;/a&gt;e punta a sito &lt;span style="font-weight: bold;"&gt;UK anche se con whois USA &lt;/span&gt;(sito di ricambi per moto), che utilizza&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-CGZNcLoyYtE/TxPC2d3ro7I/AAAAAAAAnhA/e4dEYfCgW1E/s1600/powered%2Bby.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 106px;" src="http://2.bp.blogspot.com/-CGZNcLoyYtE/TxPC2d3ro7I/AAAAAAAAnhA/e4dEYfCgW1E/s320/powered%2Bby.jpg" alt="" id="BLOGGER_PHOTO_ID_5698112194540708786" border="0" /&gt;&lt;/a&gt;per la gestione del&lt;span style="font-weight: bold;"&gt; catalogo e delle vendite.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Un ricerca in rete evidenzia &lt;span style="font-weight: bold;"&gt;diverse vulnerabilita' per questa piattaforma di e-commerce,&lt;/span&gt; e non e' escluso che proprio una di queste sia stata usata per compromettere il sito,&lt;br /&gt;&lt;br /&gt;In effetti nel &lt;span style="font-weight: bold;"&gt;folder principale dell'applicativo troviamo la presenza di shell php &lt;/span&gt;utilizzata probabilmente dai phishers.&lt;br /&gt;&lt;br /&gt;Questa la struttura del folder che mostra anche un KIT relativo al suddetto phishing PosteIT&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-AuKvVD_uVCU/TxPDrnsvjuI/AAAAAAAAnh8/3ZD_4B3MpFI/s1600/struct%2Bph%2B2012-01-16_105847.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 224px;" src="http://3.bp.blogspot.com/-AuKvVD_uVCU/TxPDrnsvjuI/AAAAAAAAnh8/3ZD_4B3MpFI/s320/struct%2Bph%2B2012-01-16_105847.jpg" alt="" id="BLOGGER_PHOTO_ID_5698113107712249570" border="0" /&gt;&lt;/a&gt;Kit che analizzato evidenzia &lt;span style="font-weight: bold;"&gt;data attuale per il codice php di invio attraverso mail di dati eventualmente acquisiti.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo invece, un dettaglio del folder sul sito compromesso&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-nIymRXBalsM/TxPDreYrseI/AAAAAAAAnhs/7-oVryF7VUs/s1600/struc%2Bfolder%2Bclone%2Be%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 294px;" src="http://2.bp.blogspot.com/-nIymRXBalsM/TxPDreYrseI/AAAAAAAAnhs/7-oVryF7VUs/s320/struc%2Bfolder%2Bclone%2Be%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5698113105212191202" border="0" /&gt;&lt;/a&gt;che ospita &lt;span style="font-weight: bold;"&gt;il clone PosteIT dal layout noto&lt;/span&gt; (notate le date dei files al 2007 tranne il php)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-OjSlBmbFb2M/TxPC2m2AimI/AAAAAAAAnhI/nPBnSqk24Ag/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 198px;" src="http://4.bp.blogspot.com/-OjSlBmbFb2M/TxPC2m2AimI/AAAAAAAAnhI/nPBnSqk24Ag/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5698112196949609058" border="0" /&gt;&lt;/a&gt;Il &lt;span style="font-weight: bold;"&gt;file php on-line sul sito compromesso&lt;/span&gt; mostra identici indirizzi mail a quelli del KIT,  per l'invio delle credenziali sottratte dal phishing (da notare che le mail a cui vengono inoltrati i dati sono 2 e presentano nominativi italiani anche se questa cosa non e' particolarmente significativa)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-OzRiaXtPQyo/TxPDsawCcFI/AAAAAAAAniE/h2-RJ8V_NIk/s1600/send%2Bcred%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 170px;" src="http://1.bp.blogspot.com/-OzRiaXtPQyo/TxPDsawCcFI/AAAAAAAAniE/h2-RJ8V_NIk/s320/send%2Bcred%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5698113121416278098" border="0" /&gt;&lt;/a&gt;Sempre lo steso php nella parte iniziale esegue dei controlli abbastanza approfonditi sui dati immessi come ad esempio quello che vediamo relativo a differente marchio di carta di credito.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-yXo0nebcpp4/TxPDskqLqVI/AAAAAAAAniQ/_-DJa5ViFFs/s1600/check%2Bcard%2Becc%2Bsame%2Bsend.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 306px;" src="http://3.bp.blogspot.com/-yXo0nebcpp4/TxPDskqLqVI/AAAAAAAAniQ/_-DJa5ViFFs/s320/check%2Bcard%2Becc%2Bsame%2Bsend.jpg" alt="" id="BLOGGER_PHOTO_ID_5698113124076071250" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6756718290856417153?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6756718290856417153/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6756718290856417153' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6756718290856417153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6756718290856417153'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-posteit-attraverso-il-solito.html' title='Phishing PosteIT attraverso il &apos;solito&apos; bonus (16 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-PBwKaihyafQ/TxPC263NnnI/AAAAAAAAnhQ/Clof6W0uGNo/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-1815067295194312656</id><published>2012-01-15T23:40:00.005+07:00</published><updated>2012-01-15T23:52:29.125+07:00</updated><title type='text'>Un bell'esempio di phishing multiplo su sito USA compromesso con utilizzo di probabile vulnerabilita' TinyMCE (16 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Si tratta di sito USA&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/--htwEOvA-Yk/TxMB-6gjoDI/AAAAAAAAngM/RlGKeOXxrtQ/s1600/wh.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 110px;" src="http://4.bp.blogspot.com/--htwEOvA-Yk/TxMB-6gjoDI/AAAAAAAAngM/RlGKeOXxrtQ/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5697900133923135538" border="0" /&gt;&lt;/a&gt;che utilizza &lt;span style="font-weight: bold;"&gt;TinyMCE   &lt;/span&gt;(da Wikipedia&lt;span style="font-style: italic;"&gt; : …...... also known as the Tiny Moxiecode Content Editor, is a platform-independent web-based JavaScript/HTML WYSIWYG editor control, released as open source software under the LGPL by Moxiecode Systems AB&lt;/span&gt;.)  e che presenta online ed utilizzabile senza restrizioni &lt;span style="font-weight: bold;"&gt;il gestore delle immagini&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-R4fyRFiHI1M/TxMB2h_7wOI/AAAAAAAAnfQ/bN8-45eagog/s1600/moxiecode%2Bim%2Bmanager%2B2012-01-15_222539.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 293px;" src="http://3.bp.blogspot.com/-R4fyRFiHI1M/TxMB2h_7wOI/AAAAAAAAnfQ/bN8-45eagog/s320/moxiecode%2Bim%2Bmanager%2B2012-01-15_222539.jpg" alt="" id="BLOGGER_PHOTO_ID_5697899989904900322" border="0" /&gt;&lt;/a&gt;Come si puo' notare e' &lt;span style="font-weight: bold;"&gt;possibile l'upload&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-4ZjyBXBxFA8/TxMB296Kw3I/AAAAAAAAnfc/4jA7I9DN--c/s1600/upload.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 191px;" src="http://3.bp.blogspot.com/-4ZjyBXBxFA8/TxMB296Kw3I/AAAAAAAAnfc/4jA7I9DN--c/s320/upload.jpg" alt="" id="BLOGGER_PHOTO_ID_5697899997396910962" border="0" /&gt;&lt;/a&gt; senza che venga richiesta una password di accesso ma non solo.&lt;br /&gt;Esiste, infatti, a possibilita' di caricare sul sito&lt;span style="font-weight: bold;"&gt; files con doppia estensione (ad esempio php.gif), che, nei folder proposti parrebbero poter essere eseguiti senza problemi&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;A riprova del possibile  uso di questa tecnica,&lt;span style="font-weight: bold;"&gt; troviamo  una shell php probabilmente uploadata da phishers &lt;/span&gt;utilizzando l'image manager&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-7bVVeRHxHbA/TxMDKYSD8aI/AAAAAAAAngk/BXYIpl26HTg/s1600/sh.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 173px;" src="http://2.bp.blogspot.com/-7bVVeRHxHbA/TxMDKYSD8aI/AAAAAAAAngk/BXYIpl26HTg/s320/sh.jpg" alt="" id="BLOGGER_PHOTO_ID_5697901430405591458" border="0" /&gt;&lt;/a&gt;Una analisi approfondita dei contenuti &lt;span style="font-weight: bold;"&gt;rivela oltre che il clone&lt;span style="color: rgb(255, 0, 0);"&gt; PayPal&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-AkgZmMLG09Q/TxMB3OUq-uI/AAAAAAAAnfk/6AbXDMLiSc4/s1600/payp.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 250px;" src="http://4.bp.blogspot.com/-AkgZmMLG09Q/TxMB3OUq-uI/AAAAAAAAnfk/6AbXDMLiSc4/s320/payp.jpg" alt="" id="BLOGGER_PHOTO_ID_5697900001803041506" border="0" /&gt;&lt;/a&gt;segnalato in rete, e da cui era iniziata l'analisi del sito, &lt;span style="font-weight: bold;"&gt;anche diversi altri cloni  che parrebbero avere date recenti di  attivazione&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo il clone&lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt; Wester Union&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-X1A4FRHgXD8/TxMB3idpuOI/AAAAAAAAngA/4P7Cm2o4bE8/s1600/westernu.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 253px;" src="http://1.bp.blogspot.com/-X1A4FRHgXD8/TxMB3idpuOI/AAAAAAAAngA/4P7Cm2o4bE8/s320/westernu.jpg" alt="" id="BLOGGER_PHOTO_ID_5697900007209416930" border="0" /&gt;&lt;/a&gt;mentre qui vediamo quello relativo a&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;  Chase&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-7h5sJH4KdpU/TxMB3RdQYII/AAAAAAAAnf0/FKmQrxQ6IRc/s1600/chase.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 246px;" src="http://3.bp.blogspot.com/-7h5sJH4KdpU/TxMB3RdQYII/AAAAAAAAnf0/FKmQrxQ6IRc/s320/chase.jpg" alt="" id="BLOGGER_PHOTO_ID_5697900002644353154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Sono inoltre presenti molti&lt;span style="font-weight: bold;"&gt; files zip contenti kit di phishing utilizzati per attivare i vari cloni&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-MrOLHGbV3i0/TxMB-1_dUKI/AAAAAAAAngY/G8Cc3aimTkI/s1600/stru%2Be%2Bkits.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 245px; height: 260px;" src="http://2.bp.blogspot.com/-MrOLHGbV3i0/TxMB-1_dUKI/AAAAAAAAngY/G8Cc3aimTkI/s320/stru%2Be%2Bkits.jpg" alt="" id="BLOGGER_PHOTO_ID_5697900132710568098" border="0" /&gt;&lt;/a&gt;Come si vede, ancora una volta vengono sfruttate possibilita' offerte da programmi che permetto la gestione dei contenuti  da remoto e che se male o per niente configurati possono essere sfruttati dai phishers per la gestione dei relativi cloni delle banche da colpire.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-1815067295194312656?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/1815067295194312656/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=1815067295194312656' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1815067295194312656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1815067295194312656'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/un-bellesempio-di-phishing-multiplo-su.html' title='Un bell&apos;esempio di phishing multiplo su sito USA compromesso con utilizzo di probabile vulnerabilita&apos; TinyMCE (16 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/--htwEOvA-Yk/TxMB-6gjoDI/AAAAAAAAngM/RlGKeOXxrtQ/s72-c/wh.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6443199498306027013</id><published>2012-01-13T17:29:00.007+07:00</published><updated>2012-01-13T18:06:01.026+07:00</updated><title type='text'>Continua il phishing ai danni della Cassa di Risparmio di Bolzano (13 gennaio)</title><content type='html'>Nella giornata di ieri&lt;span style="font-weight: bold;"&gt; segnalavo un&lt;a style="color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/phishing-cassa-di-risparmio-di-bolzano.html"&gt; attacco phishing a Cassa di Risparmio di Bolzano &lt;/a&gt;&lt;/span&gt;che vedeva un  &lt;span style="font-weight: bold;"&gt;redirect attraverso codice su sito vietnamita e clone su dominio Altervista creato per l'occasione.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;Il phishing aveva pero' corta durata&lt;/span&gt; in quanto non il sito di hosting del clone ma quello che ospitava&lt;span style="font-weight: bold;"&gt; il redirect veniva bloccato rendendo quindi inoperativi proprio i link presenti nei messaggi mail di phishing.&lt;/span&gt;&lt;br /&gt;Conseguenza di questo appare&lt;span style="font-weight: bold;"&gt; adesso on-line, a fronte di nuove mails di phishing,  un sito di redirect a clone C. R. Bolzano ospitato sempre su sito vietnamita ma con IP diverso da ieri&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-RbMAd6X_Gnk/TxAIfsfUkRI/AAAAAAAAneQ/1PL5sdyu_Gw/s1600/wh%2Bredir%2Bvn.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 143px;" src="http://1.bp.blogspot.com/-RbMAd6X_Gnk/TxAIfsfUkRI/AAAAAAAAneQ/1PL5sdyu_Gw/s320/wh%2Bredir%2Bvn.jpg" alt="" id="BLOGGER_PHOTO_ID_5697062869235175698" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;e sempre con &lt;span style="font-weight: bold;"&gt;Innova Studio Asset Manager&lt;/span&gt; come probabile mezzo per uploadare i codici di supporto al redirect&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-TmPdvm0-v74/TxAIfRrAY8I/AAAAAAAAnd8/BZJxE1fRPfU/s1600/asset%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 216px;" src="http://4.bp.blogspot.com/-TmPdvm0-v74/TxAIfRrAY8I/AAAAAAAAnd8/BZJxE1fRPfU/s320/asset%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5697062862036427714" border="0" /&gt;&lt;/a&gt;Questo un dettaglio&lt;span style="font-weight: bold;"&gt; della data recente del file&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-2_qGljHNKP0/TxAIfdA1RWI/AAAAAAAAneE/Zs3jXym4rjI/s1600/redir%2Bdata%2Bsh%2B2012-01-13_133902.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://1.bp.blogspot.com/-2_qGljHNKP0/TxAIfdA1RWI/AAAAAAAAneE/Zs3jXym4rjI/s320/redir%2Bdata%2Bsh%2B2012-01-13_133902.jpg" alt="" id="BLOGGER_PHOTO_ID_5697062865080763746" border="0" /&gt;&lt;/a&gt;La cosa particolare e' che, &lt;span style="font-weight: bold;"&gt;come hosting del clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-ugUeRn7P1P8/TxAJc35qfHI/AAAAAAAAnfE/Bcao0cy_R_8/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 198px;" src="http://4.bp.blogspot.com/-ugUeRn7P1P8/TxAJc35qfHI/AAAAAAAAnfE/Bcao0cy_R_8/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5697063920270474354" border="0" /&gt;&lt;/a&gt;veniva, &lt;span style="font-weight: bold;"&gt;sino a qualche minuto fa, utilizzato sito compromesso IT&lt;/span&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-23cR54bXw54/TxAIf_jl4BI/AAAAAAAAneg/l8q9H6E9Dqw/s1600/wh%2Bit%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 138px;" src="http://3.bp.blogspot.com/-23cR54bXw54/TxAIf_jl4BI/AAAAAAAAneg/l8q9H6E9Dqw/s320/wh%2Bit%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5697062874353360914" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; che&lt;/span&gt;, stranamente, non presentava tracce di &lt;span style="font-weight: bold;"&gt;Asset Manager Innova Studio o di altro file manager di solito usato in questi casi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;La cosa e' comunque durata poco, in quanto&lt;span style="font-weight: bold;"&gt; si e' gia' passati a clone ospitato su domino free Altervista&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-SPFSTi2tmp4/TxAJKsD7tbI/AAAAAAAAne8/9oaTGiinVps/s1600/altervista%2Bsecond%2Boredfir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 112px;" src="http://4.bp.blogspot.com/-SPFSTi2tmp4/TxAJKsD7tbI/AAAAAAAAne8/9oaTGiinVps/s320/altervista%2Bsecond%2Boredfir.jpg" alt="" id="BLOGGER_PHOTO_ID_5697063607854675378" border="0" /&gt;&lt;/a&gt;la cui registrazione risale ad ieri, come si nota dallo screenshot dei dettagli dell'account creato dai phishers.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-hwZ4wv67x94/TxAJKkneLFI/AAAAAAAAnes/lAO8ukIcBRI/s1600/o%2Bclone%2Bdomaltervista%2Breg%2Bnuovv.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 172px;" src="http://3.bp.blogspot.com/-hwZ4wv67x94/TxAJKkneLFI/AAAAAAAAnes/lAO8ukIcBRI/s320/o%2Bclone%2Bdomaltervista%2Breg%2Bnuovv.jpg" alt="" id="BLOGGER_PHOTO_ID_5697063605856250962" border="0" /&gt;&lt;/a&gt;Il fatto che in questi casi gli account siano creati, come visto altre volte, un giorno o piu' prima di mettere online il phishing fa pensare che ci sia una pianificazione abbastanza accurata di come procedere nell'azione di phishing e &lt;span style="font-weight: bold;"&gt;i nuovi domini non siano creati, &lt;/span&gt;es nel caso di Altervista, &lt;span style="font-weight: bold;"&gt;al momento che viene rilevato un problema (messa offline, balck-listing, sospensione dell'account ecc..) ma ben prima.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Capita anche spesso di trovare codici di cloni e redirect on-line ma che non sembrano ancora entrati a far parte di segnalazioni di phishing, come se in pratica  fossero 'parcheggiati' in attesa di attivazione.&lt;br /&gt;&lt;br /&gt;Una possibile spiegazione potrebbe anche essere il tempo che decorre dall'uso di mailers per l'invio di messaggi di phishing e la ricezione delle stesse da  parte degli utenti internet, cosa che potrebbe richiedere per la diffusione dello 'spam', in caso di grandi liste di indirizzi mails, un certo tempo.&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6443199498306027013?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6443199498306027013/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6443199498306027013' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6443199498306027013'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6443199498306027013'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/continua-il-phishing-ai-danni-della.html' title='Continua il phishing ai danni della Cassa di Risparmio di Bolzano (13 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-RbMAd6X_Gnk/TxAIfsfUkRI/AAAAAAAAneQ/1PL5sdyu_Gw/s72-c/wh%2Bredir%2Bvn.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-3277644170438092962</id><published>2012-01-13T12:19:00.007+07:00</published><updated>2012-01-13T12:37:14.075+07:00</updated><title type='text'>Phishing Banco Azzoaglio (13 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;In atto ormai &lt;span style="font-weight: bold;"&gt;da parecchi giorni&lt;/span&gt;, continua sostenuto il phishing ai danni di &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Banco Azzoaglio&lt;/span&gt; (ne ha scritto in&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;a style="color: rgb(51, 102, 255);" href="http://www.denisfrati.it/2012/01/09/r-team-ancora-su-banco-azzoaglio/#more-5292"&gt;&lt;span&gt;dettaglio Denis Frati sul suo blog&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;)&lt;/span&gt;.&lt;br /&gt;Era quindi probabile&lt;span style="font-style: italic; font-weight: bold;"&gt; 'prima o poi', &lt;/span&gt;considerato i molti giorni di attacco  a &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Banco Azzoaglio&lt;/span&gt;,  ricevere un messaggio di phishing ai danni di questa banca IT a diffusione regionale&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ecco la mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-C_IYRw8mSh0/Tw-_cWOhnAI/AAAAAAAAncE/kqn8e41Hpk0/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 190px;" src="http://4.bp.blogspot.com/-C_IYRw8mSh0/Tw-_cWOhnAI/AAAAAAAAncE/kqn8e41Hpk0/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5696982547370712066" border="0" /&gt;&lt;/a&gt;con logo della banca  direttamente&lt;span style="font-weight: bold;"&gt; linkato dal sito legittimo della stessa&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-W9efXmaSKms/Tw-_dODJEbI/AAAAAAAAncs/HseyIE2u9r8/s1600/logo%2Bazzo.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 158px;" src="http://3.bp.blogspot.com/-W9efXmaSKms/Tw-_dODJEbI/AAAAAAAAncs/HseyIE2u9r8/s320/logo%2Bazzo.jpg" alt="" id="BLOGGER_PHOTO_ID_5696982562355351986" border="0" /&gt;&lt;/a&gt;Questi invece gli IP&lt;span style="font-weight: bold;"&gt; nell'header mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-2zHAer5XV64/Tw_AM6NVQqI/AAAAAAAAndk/CfujqlNWFdg/s1600/headers.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 62px;" src="http://2.bp.blogspot.com/-2zHAer5XV64/Tw_AM6NVQqI/AAAAAAAAndk/CfujqlNWFdg/s320/headers.jpg" alt="" id="BLOGGER_PHOTO_ID_5696983381663105698" border="0" /&gt;&lt;/a&gt;Il link presente, punta a&lt;span style="font-weight: bold;"&gt; sito vietnamita ampiamente utilizzato in passato per azioni di phishing &lt;/span&gt;(vedi esempio &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/ritorna-il-phishing-ai-danni-di-banca.html"&gt;questo phishing ai danni di Banca MonteParma del 16 dicembre &lt;/a&gt;2011) e con  il 'solito' &lt;span style="font-weight: bold;"&gt;Asset Manager Innova Studio&lt;/span&gt; che permette di uploadare i codici di supporto al redirect&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Ia6KrSXEuDI/Tw-_cg1UtqI/AAAAAAAAncQ/4T-oX89BK1Q/s1600/redir%2Bvn%2Basset2012-01-13_104437.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 144px;" src="http://4.bp.blogspot.com/-Ia6KrSXEuDI/Tw-_cg1UtqI/AAAAAAAAncQ/4T-oX89BK1Q/s320/redir%2Bvn%2Basset2012-01-13_104437.jpg" alt="" id="BLOGGER_PHOTO_ID_5696982550217799330" border="0" /&gt;&lt;/a&gt;Si possono notare sia il codice&lt;span style="font-weight: bold;"&gt; di redirect usato nel link in mail che un file .php con codice che punta sempre al medesimo clone Banco Azzoaglio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-W5JswW8hwLs/Tw-_c7foe2I/AAAAAAAAncc/4AKbkSRmQCw/s1600/php%2Be%2Bhtm.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 134px;" src="http://1.bp.blogspot.com/-W5JswW8hwLs/Tw-_c7foe2I/AAAAAAAAncc/4AKbkSRmQCw/s320/php%2Be%2Bhtm.jpg" alt="" id="BLOGGER_PHOTO_ID_5696982557374577506" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Il clone&lt;/span&gt; e' ospitato su&lt;span style="font-weight: bold;"&gt; sito con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-2P5qrPIKCcU/Tw_A1-JVN6I/AAAAAAAAndw/n9NbgwZxEHc/s1600/wh%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://2.bp.blogspot.com/-2P5qrPIKCcU/Tw_A1-JVN6I/AAAAAAAAndw/n9NbgwZxEHc/s320/wh%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5696984087094704034" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con Asset Manager&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-5s1zQGUsBuc/Tw_AIjbBGvI/AAAAAAAAndU/7OaulWx6CYw/s1600/clone%2Bsu%2Basset.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 162px;" src="http://1.bp.blogspot.com/-5s1zQGUsBuc/Tw_AIjbBGvI/AAAAAAAAndU/7OaulWx6CYw/s320/clone%2Bsu%2Basset.jpg" alt="" id="BLOGGER_PHOTO_ID_5696983306827012850" border="0" /&gt;&lt;/a&gt; che ha permesso&lt;span style="font-weight: bold;"&gt; l'upload del codice di phishing Banco Azzoaglio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-jU0_Boe9HBw/Tw_AHz3_0vI/AAAAAAAAnc0/2MqxIk6dlbY/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 214px;" src="http://4.bp.blogspot.com/-jU0_Boe9HBw/Tw_AHz3_0vI/AAAAAAAAnc0/2MqxIk6dlbY/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5696983294063661810" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Il  php utilizzato mostra  indirizzo mail che,  anche questa volta&lt;/span&gt; ( ma era praticamente scontato vista la struttura del phishing)&lt;span style="font-weight: bold;"&gt; e' attribuibile sempre ai soliti phishers (R-team)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-nK3nElNfkA4/Tw_AIQREdDI/AAAAAAAAndM/PsmkgFv8yOE/s1600/php%2Bazzo%2Bsend%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 199px;" src="http://3.bp.blogspot.com/-nK3nElNfkA4/Tw_AIQREdDI/AAAAAAAAndM/PsmkgFv8yOE/s320/php%2Bazzo%2Bsend%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5696983301685015602" border="0" /&gt;&lt;/a&gt;Lo stesso sito &lt;span style="font-weight: bold;"&gt;russo appare coinvolto, in passato, anche in altre azioni di phishing &lt;/span&gt;non legate probabilmente a R-team ma eseguite da altri phishers come denotano alcune segnalazioni &lt;span style="font-weight: bold;"&gt;Phishtank&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-xLM8O0bSmTc/Tw_AINxpA5I/AAAAAAAAndA/w-UgkyNtiUw/s1600/ru1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 210px;" src="http://3.bp.blogspot.com/-xLM8O0bSmTc/Tw_AINxpA5I/AAAAAAAAndA/w-UgkyNtiUw/s320/ru1.jpg" alt="" id="BLOGGER_PHOTO_ID_5696983301016322962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-3277644170438092962?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/3277644170438092962/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=3277644170438092962' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3277644170438092962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3277644170438092962'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-banco-azzoaglio-13-gennaio.html' title='Phishing Banco Azzoaglio (13 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-C_IYRw8mSh0/Tw-_cWOhnAI/AAAAAAAAncE/kqn8e41Hpk0/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5750772403557701685</id><published>2012-01-12T22:10:00.007+07:00</published><updated>2012-01-12T22:40:44.498+07:00</updated><title type='text'>Phishing Lottomatica. Molti i punti in comune con i recenti casi Banca Reale e Poste IT (12 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ritorna il &lt;span style="font-weight: bold;"&gt;phishing ai danni di Lottomatica tramite questa mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-9aCvPHVN0ec/Tw74cTCEnaI/AAAAAAAAnak/YburNG4CEKQ/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 279px;" src="http://2.bp.blogspot.com/-9aCvPHVN0ec/Tw74cTCEnaI/AAAAAAAAnak/YburNG4CEKQ/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5696763743699246498" border="0" /&gt;&lt;/a&gt;il cui messaggio &lt;span style="font-weight: bold;"&gt;e' interamente costituto da immagine png.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Caso particolare, si tratta&lt;span style="font-weight: bold;"&gt; di phishing la cui tecnica e' praticamente uguale a quella proposta in almeno altre due occasioni negli ultimi giorni.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo infatti &lt;span style="font-weight: bold;"&gt;il codice di redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-u9TKXiXDmHg/Tw74yQwOhfI/AAAAAAAAnbU/DaDaINXQJpI/s1600/redir%2Bcode%2B2012-01-12_204736.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 248px;" src="http://4.bp.blogspot.com/-u9TKXiXDmHg/Tw74yQwOhfI/AAAAAAAAnbU/DaDaINXQJpI/s320/redir%2Bcode%2B2012-01-12_204736.jpg" alt="" id="BLOGGER_PHOTO_ID_5696764121044649458" border="0" /&gt;&lt;/a&gt;identico  quello rilevato&lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://edetools.blogspot.com/2012/01/phishing-banca-reale-9-gennaio.html"&gt; in phishing Banca Reale il 9/1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-FWzjhf-zX3c/TwsBS0j5iJI/AAAAAAAAnT8/6kaYSqoeJB8/s1600/code%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 196px;" src="http://2.bp.blogspot.com/-FWzjhf-zX3c/TwsBS0j5iJI/AAAAAAAAnT8/6kaYSqoeJB8/s320/code%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5695647576598612114" border="0" /&gt;&lt;/a&gt;&lt;a style="color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/ulteriore-phishing-posteit-3-gennaio.html"&gt;&lt;span style="font-weight: bold;"&gt;e PosteIT il 3/1&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-3LyXdF1ROL4/TwKlOaHGQPI/AAAAAAAAnB0/v2Kenq8fc3c/s1600/det%2Bcina%2Bwh%2Be%2Bcode%2Bred.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 152px;" src="http://4.bp.blogspot.com/-3LyXdF1ROL4/TwKlOaHGQPI/AAAAAAAAnB0/v2Kenq8fc3c/s320/det%2Bcina%2Bwh%2Be%2Bcode%2Bred.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294545895571698" border="0" /&gt;&lt;/a&gt;Naturalmente  cambiano i link al clone che comunque nel caso odierno e' hostato sul medesimo dominio compromesso visto per Banca Reale&lt;br /&gt;&lt;br /&gt;A ulteriore &lt;span style="font-weight: bold;"&gt;conferma della probabile sorgente comune dei phishing, abbiamo l'utilizzo di 2 siti (creati in data odierna) sia per il redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-xDtnf1DYnqM/Tw74dZYMpFI/AAAAAAAAnbI/V21FNg-6WKI/s1600/reg%2Bdon%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 262px;" src="http://2.bp.blogspot.com/-xDtnf1DYnqM/Tw74dZYMpFI/AAAAAAAAnbI/V21FNg-6WKI/s320/reg%2Bdon%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5696763762582529106" border="0" /&gt;&lt;/a&gt;che per il clone&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-MUkjckjNIXU/Tw76OSkQ8II/AAAAAAAAnbo/YpB4NiBuOzg/s1600/domain%2Breg.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 266px;" src="http://2.bp.blogspot.com/-MUkjckjNIXU/Tw76OSkQ8II/AAAAAAAAnbo/YpB4NiBuOzg/s320/domain%2Breg.jpg" alt="" id="BLOGGER_PHOTO_ID_5696765702079312002" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;e &lt;span style="font-weight: bold;"&gt;dei quali vengono attivati &lt;/span&gt;&lt;span style="font-weight: bold;"&gt; due sottodomini  ma che propongono diverso IP rispetto ai rispettivi domini di cui fanno parte.&lt;/span&gt;(cosa gia' vista nei 2 casi citati in precedenza)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ecco i record DNS realtivi al redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ScYbeN8KoJ8/Tw74dJj2LbI/AAAAAAAAna8/E0b8DTA_zTk/s1600/dns%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 132px;" src="http://3.bp.blogspot.com/-ScYbeN8KoJ8/Tw74dJj2LbI/AAAAAAAAna8/E0b8DTA_zTk/s320/dns%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5696763758336421298" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;e al clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-olel9gJkFDI/Tw76OFojSFI/AAAAAAAAnbg/bVfGgEj9MNc/s1600/dns%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 85px;" src="http://4.bp.blogspot.com/-olel9gJkFDI/Tw76OFojSFI/AAAAAAAAnbg/bVfGgEj9MNc/s320/dns%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5696765698607630418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Per di piu',&lt;span style="font-weight: bold;"&gt; il sito compromesso che ospita il clone puntato dal sottodominio,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-0KwsarNKrqw/Tw74cj2qTRI/AAAAAAAAnaw/j8Vf823xmug/s1600/clone%2Blottomaticard.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://1.bp.blogspot.com/-0KwsarNKrqw/Tw74cj2qTRI/AAAAAAAAnaw/j8Vf823xmug/s320/clone%2Blottomaticard.jpg" alt="" id="BLOGGER_PHOTO_ID_5696763748214787346" border="0" /&gt;&lt;/a&gt; e' lo stesso &lt;span style="font-weight: bold;"&gt;gia' visto nel recente caso &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Banca Reale.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-g0mz2AenyWs/Tw78EpnHCvI/AAAAAAAAnb4/1mzmqR9i7iU/s1600/wh%2Blotto%2Bclon.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 107px;" src="http://2.bp.blogspot.com/-g0mz2AenyWs/Tw78EpnHCvI/AAAAAAAAnb4/1mzmqR9i7iU/s320/wh%2Blotto%2Bclon.jpg" alt="" id="BLOGGER_PHOTO_ID_5696767735489825522" border="0" /&gt;&lt;/a&gt;Oltre che a tecnica comune per differenti phishing ai danni di banche IT potrebbe quindi trattarsi, in questo caso, anche &lt;span style="font-weight: bold;"&gt;degli  stessi phishers dietro ai recenti attacchi PosteIT, Banca Reale e Lottomatica&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5750772403557701685?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5750772403557701685/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5750772403557701685' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5750772403557701685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5750772403557701685'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-lottomatica-molti-punti-in.html' title='Phishing Lottomatica. Molti i punti in comune con i recenti casi Banca Reale e Poste IT (12 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-9aCvPHVN0ec/Tw74cTCEnaI/AAAAAAAAnak/YburNG4CEKQ/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2693909459648599627</id><published>2012-01-12T14:25:00.003+07:00</published><updated>2012-01-12T14:51:14.685+07:00</updated><title type='text'>Phishing Cassa di Risparmio di Bolzano (12 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Tornata nel mirino dei&lt;span style="font-weight: bold;"&gt; 'soliti'&lt;/span&gt; phishers (almeno da quanto si puo' dedurre dalle modalita' operative utilizzate per questo phishing)  la&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt; Cassa di Risparmio di Bolzano.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-bV8T-wdijN8/Tw6LhqhH1pI/AAAAAAAAnZo/4P4Elrgzxjk/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 181px;" src="http://2.bp.blogspot.com/-bV8T-wdijN8/Tw6LhqhH1pI/AAAAAAAAnZo/4P4Elrgzxjk/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5696643989135414930" border="0" /&gt;&lt;/a&gt;La gestione del phishing vede il consueto&lt;span style="font-weight: bold;"&gt; redirect gestito attraverso l'uso di Asset Manager Innova Studio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-g2IfwqWuLpU/Tw6Lh2ZgpKI/AAAAAAAAnaA/qJCfw2tSfmo/s1600/asset%2Bm.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 245px;" src="http://4.bp.blogspot.com/-g2IfwqWuLpU/Tw6Lh2ZgpKI/AAAAAAAAnaA/qJCfw2tSfmo/s320/asset%2Bm.jpg" alt="" id="BLOGGER_PHOTO_ID_5696643992324711586" border="0" /&gt;&lt;/a&gt;presente e raggiungibile on-line senza restrizione,&lt;span style="font-weight: bold;"&gt; su  whois vietnamita.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-TaTdzRoDt68/Tw6Li1eFCOI/AAAAAAAAnac/jjo-L-xc1Ug/s1600/ip%2Bwh%2B2012-01-12_135421.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 121px;" src="http://1.bp.blogspot.com/-TaTdzRoDt68/Tw6Li1eFCOI/AAAAAAAAnac/jjo-L-xc1Ug/s320/ip%2Bwh%2B2012-01-12_135421.jpg" alt="" id="BLOGGER_PHOTO_ID_5696644009255307490" border="0" /&gt;&lt;/a&gt;Una analisi dell'IP mostra che sempre sul medesimo server,&lt;span style="font-weight: bold;"&gt; gia' il 27 luglio 2011, era stato utilizzato un altro sito .VN con Asset Manager per gestire un phishing&lt;/span&gt;&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/07/phishing-ai-danni-banche-it-regionali-o.html"&gt; banca Monte Parma&lt;/a&gt; mentre &lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://edetools.blogspot.com/2011/07/phishing-ai-danni-banche-locali-it.html"&gt;il 28 luglio,&lt;/a&gt; un nuovo redirects a &lt;span style="font-weight: bold;"&gt;Banca Friuladria - Credit Agricole&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo un dettaglio &lt;span style="font-weight: bold;"&gt;del db dei post pubblicati sul blog con i relativi dati:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-O_2_jq2TL6o/Tw6Lh-5ALsI/AAAAAAAAnZw/sVAvVAsPj2A/s1600/27%2B7%2Bparma%2Bgia%2Bip.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 43px;" src="http://4.bp.blogspot.com/-O_2_jq2TL6o/Tw6Lh-5ALsI/AAAAAAAAnZw/sVAvVAsPj2A/s320/27%2B7%2Bparma%2Bgia%2Bip.jpg" alt="" id="BLOGGER_PHOTO_ID_5696643994604285634" border="0" /&gt;&lt;/a&gt;E' evidente che, come accade spesso, una volta individuato un gruppo di siti, di solito sul medesimo server , e tutti che utilizzano &lt;span style="font-weight: bold;"&gt;Asset Manager,&lt;/span&gt; i phishers possano utilizzare queste &lt;span style="font-weight: bold;"&gt;risorse di hosting free anche a distanza di mesi, scegliendo un nuovo sito per il redirect.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Al momento il link presente redirige a&lt;span style="font-weight: bold;"&gt; dominio creato appositamente su servizio free web di Altervista.&lt;/span&gt;&lt;br /&gt;Una occhiata alla data &lt;span style="font-weight: bold;"&gt;di registrazione mostra quella di ieri per la creazione del clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-v9DdFKJQMt0/Tw6LiTLvKkI/AAAAAAAAnaM/2qxDBcRlqeA/s1600/alterv%2Bregistr.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 135px;" src="http://1.bp.blogspot.com/-v9DdFKJQMt0/Tw6LiTLvKkI/AAAAAAAAnaM/2qxDBcRlqeA/s320/alterv%2Bregistr.jpg" alt="" id="BLOGGER_PHOTO_ID_5696644000051571266" border="0" /&gt;&lt;/a&gt;con questo classico layout fake di &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Cassa di Risparmio di Bolzano.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-bV8T-wdijN8/Tw6LhqhH1pI/AAAAAAAAnZo/4P4Elrgzxjk/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 181px;" src="http://2.bp.blogspot.com/-bV8T-wdijN8/Tw6LhqhH1pI/AAAAAAAAnZo/4P4Elrgzxjk/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5696643989135414930" border="0" /&gt;&lt;/a&gt;E' altamente probabile che nelle prossime ore assisteremo, a meno che non venga messo off-line il redirect su sito VN, ad una modifica dell' indirizzo finale di phishing onde evitare il blocco del clone e/o la sua eventuale comparsa in blacklist.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2693909459648599627?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2693909459648599627/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2693909459648599627' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2693909459648599627'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2693909459648599627'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-cassa-di-risparmio-di-bolzano.html' title='Phishing Cassa di Risparmio di Bolzano (12 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-bV8T-wdijN8/Tw6LhqhH1pI/AAAAAAAAnZo/4P4Elrgzxjk/s72-c/clone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8852425700887916120</id><published>2012-01-11T23:58:00.005+07:00</published><updated>2012-01-12T00:12:54.033+07:00</updated><title type='text'>Phishing UniCredit (11 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ricevuta mail di phishing ai danni di &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Banca UniCredit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Ptvv5S-pTzg/Tw3AH4-C1wI/AAAAAAAAnYg/h7aWVxOV6Hw/s1600/mail%2B2012-01-11_230714.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 270px;" src="http://1.bp.blogspot.com/-Ptvv5S-pTzg/Tw3AH4-C1wI/AAAAAAAAnYg/h7aWVxOV6Hw/s320/mail%2B2012-01-11_230714.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420345477781250" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con header&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-d3vv33cDzhE/Tw3AHvGCDjI/AAAAAAAAnYY/E_PUU2ozi0g/s1600/headers.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 65px;" src="http://4.bp.blogspot.com/-d3vv33cDzhE/Tw3AHvGCDjI/AAAAAAAAnYY/E_PUU2ozi0g/s320/headers.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420342826929714" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il form allegato &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-YPVSYa0Yc1k/Tw3AR_GNeII/AAAAAAAAnZE/O7oTvSjwx_A/s1600/form.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 267px;" src="http://4.bp.blogspot.com/-YPVSYa0Yc1k/Tw3AR_GNeII/AAAAAAAAnZE/O7oTvSjwx_A/s320/form.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420518921336962" border="0" /&gt;&lt;/a&gt;dimostra ancora una volta&lt;span style="font-weight: bold;"&gt; la cura  posta nel layout di cloni ai danni di UniCredit &lt;/span&gt;anche se questo phishing, utilizzando solo un form allegato,&lt;span style="font-weight: bold;"&gt; non raggiunge i livelli di complessita' visti in precedenti attacchi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il codice php linkato dal form&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-dvFAYi8NCqA/Tw3AHbKH8pI/AAAAAAAAnYI/tlHqQnW-MVY/s1600/for%2Baction%2Bw%2Bcampi.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://4.bp.blogspot.com/-dvFAYi8NCqA/Tw3AHbKH8pI/AAAAAAAAnYI/tlHqQnW-MVY/s320/for%2Baction%2Bw%2Bcampi.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420337475383954" border="0" /&gt;&lt;/a&gt; e' hostato su &lt;span style="font-weight: bold;"&gt;sito compromesso con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-vCE1fyWFxJQ/Tw3AId3leGI/AAAAAAAAnY4/SfLr4q2fhjE/s1600/wh%2Bs%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 122px;" src="http://2.bp.blogspot.com/-vCE1fyWFxJQ/Tw3AId3leGI/AAAAAAAAnY4/SfLr4q2fhjE/s320/wh%2Bs%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420355382802530" border="0" /&gt;&lt;/a&gt;Sul medesimo sito troviamo oltre al codice denominato &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;v1.php&lt;/span&gt; anche un php denominato &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;v.php &lt;/span&gt;e che puntano&lt;span style="font-weight: bold;"&gt; entrambi al reale sito UniCredit.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-vcvky47UX3I/Tw3AIBW1ugI/AAAAAAAAnYs/ZreBCTh2uWs/s1600/v%2Bv1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 264px; height: 95px;" src="http://1.bp.blogspot.com/-vcvky47UX3I/Tw3AIBW1ugI/AAAAAAAAnYs/ZreBCTh2uWs/s320/v%2Bv1.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420347729263106" border="0" /&gt;&lt;/a&gt;Sempre sul medesimo sito compromesso,&lt;span style="font-weight: bold;"&gt; a riprova di un uso esteso dello stesso da parte dei phishers abbiamo anche un php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-kBIhkyJ-Gpg/Tw3AqY97DpI/AAAAAAAAnZc/ds2yFw3xcs8/s1600/php%2Bsparka.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 19px;" src="http://4.bp.blogspot.com/-kBIhkyJ-Gpg/Tw3AqY97DpI/AAAAAAAAnZc/ds2yFw3xcs8/s320/php%2Bsparka.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420938182758034" border="0" /&gt;&lt;/a&gt; che redirige a pagina in tedesco di&lt;span style="font-weight: bold;"&gt; Gruppo di Casse di Risparmio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-2N6pPXjsttY/Tw3AjxIr-3I/AAAAAAAAnZQ/9Cygqi2qg0w/s1600/sparkasse.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 193px;" src="http://2.bp.blogspot.com/-2N6pPXjsttY/Tw3AjxIr-3I/AAAAAAAAnZQ/9Cygqi2qg0w/s320/sparkasse.jpg" alt="" id="BLOGGER_PHOTO_ID_5696420824411274098" border="0" /&gt;&lt;/a&gt;segno di probabile &lt;span style="font-weight: bold;"&gt;attacco ad altra o altre banche.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8852425700887916120?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8852425700887916120/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8852425700887916120' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8852425700887916120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8852425700887916120'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-unicredit-11-gennaio.html' title='Phishing UniCredit (11 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Ptvv5S-pTzg/Tw3AH4-C1wI/AAAAAAAAnYg/h7aWVxOV6Hw/s72-c/mail%2B2012-01-11_230714.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-3405640828903032954</id><published>2012-01-11T10:25:00.004+07:00</published><updated>2012-01-11T10:42:02.154+07:00</updated><title type='text'>Phishing “ Verified by VISA” (11 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ancora attacchi di phishing a &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;VISA &lt;/span&gt;che, come vedremo, sono legati anche ad &lt;span style="font-weight: bold;"&gt;attacchi CartaSi.&lt;/span&gt;&lt;br /&gt;Questa la mail&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-qOvt9tatiB8/Tw0CIZPWweI/AAAAAAAAnXg/tzfWOZ95fYg/s1600/mail%2B2012-01-11_093459.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://3.bp.blogspot.com/-qOvt9tatiB8/Tw0CIZPWweI/AAAAAAAAnXg/tzfWOZ95fYg/s320/mail%2B2012-01-11_093459.jpg" alt="" id="BLOGGER_PHOTO_ID_5696211446931046882" border="0" /&gt;&lt;/a&gt;con allegato form dal layout noto ed utilizzato da tempo&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-_x3FceTg4J4/Tw0CI0cUosI/AAAAAAAAnXs/NISOBhU8R0E/s1600/form.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 165px; height: 320px;" src="http://3.bp.blogspot.com/-_x3FceTg4J4/Tw0CI0cUosI/AAAAAAAAnXs/NISOBhU8R0E/s320/form.jpg" alt="" id="BLOGGER_PHOTO_ID_5696211454233191106" border="0" /&gt;&lt;/a&gt;L' header in mail presenta primo IP come italiano&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-JfjguEHmTAA/Tw0CIH8J3VI/AAAAAAAAnXU/qsa52VxB8yE/s1600/header.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 56px;" src="http://1.bp.blogspot.com/-JfjguEHmTAA/Tw0CIH8J3VI/AAAAAAAAnXU/qsa52VxB8yE/s320/header.jpg" alt="" id="BLOGGER_PHOTO_ID_5696211442287107410" border="0" /&gt;&lt;/a&gt;Il codice php linkato dal form&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-aTCZWIY7_eU/Tw0CHquXoBI/AAAAAAAAnW8/keggy-5Ynjw/s1600/action%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 74px;" src="http://1.bp.blogspot.com/-aTCZWIY7_eU/Tw0CHquXoBI/AAAAAAAAnW8/keggy-5Ynjw/s320/action%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5696211434444660754" border="0" /&gt;&lt;/a&gt;e' ospitato su sito (whois canadese) compromesso, insieme ad un codice di form dal layout  identico a quello allegato alla mail&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-cWq4Udb3M_I/Tw0CH1v4-3I/AAAAAAAAnXE/42GZPYfsETU/s1600/fil%2Bstru%2Battuale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 159px;" src="http://3.bp.blogspot.com/-cWq4Udb3M_I/Tw0CH1v4-3I/AAAAAAAAnXE/42GZPYfsETU/s320/fil%2Bstru%2Battuale.jpg" alt="" id="BLOGGER_PHOTO_ID_5696211437403831154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Interessante la &lt;span style="font-weight: bold;"&gt;presenza sullo stesso sito di &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-qGW5ek6H4jA/Tw0CPGQ-PiI/AAAAAAAAnX4/g1f_x1qVIo4/s1600/stesso%2Bsito%2Bcsi.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 90px;" src="http://2.bp.blogspot.com/-qGW5ek6H4jA/Tw0CPGQ-PiI/AAAAAAAAnX4/g1f_x1qVIo4/s320/stesso%2Bsito%2Bcsi.jpg" alt="" id="BLOGGER_PHOTO_ID_5696211562096639522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;che ospita un &lt;span style="font-weight: bold;"&gt;phishing CartaSi tuttora attivo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Una ricerca in rete permette anche di rilevare &lt;span style="font-weight: bold;"&gt;un altro clone di phishing CartaSi, &lt;/span&gt;ma attualmente i relativi folders ed il clone non sono piu' raggiungibili.&lt;br /&gt;&lt;br /&gt;Come si nota dalla&lt;span style="font-weight: bold;"&gt; home del sito compromesso&lt;/span&gt; abbiamo un layout con  segnalazione di errori ed anche &lt;span style="font-weight: bold;"&gt;la stessa pagina home, in cache  Google risulta non correttamente visualizzata&lt;/span&gt;, facendo pensare a sito non piu' attivo che ha consentito e consente ai phishers di hostare i cloni &lt;span style="font-weight: bold;"&gt;CartaSi e VISA.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-3405640828903032954?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/3405640828903032954/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=3405640828903032954' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3405640828903032954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3405640828903032954'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-verified-by-visa-11-gennaio.html' title='Phishing “ Verified by VISA” (11 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-qOvt9tatiB8/Tw0CIZPWweI/AAAAAAAAnXg/tzfWOZ95fYg/s72-c/mail%2B2012-01-11_093459.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-977285262375538358</id><published>2012-01-10T17:53:00.004+07:00</published><updated>2012-01-10T18:13:57.841+07:00</updated><title type='text'>Phishing 'Verified by VISA” (10 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Insieme a &lt;span style="font-weight: bold;"&gt;PayPal ed eBay, &lt;span style="color: rgb(255, 0, 0);"&gt;Visa&lt;/span&gt; &lt;/span&gt;e' un altro obbiettivo molto presente in attacchi di phishing.&lt;br /&gt;&lt;br /&gt;Questa l'attuale struttura di &lt;span style="font-weight: bold;"&gt;folder incluso all'interno di sito ampiamente compromesso,&lt;/span&gt; e che mostra alcuni particolari dell'attuale phishing.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-fSnDCwH5-kg/TwwZPqNRaFI/AAAAAAAAnVY/bWFpHSa8zgA/s1600/folder%2Bvisa.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 166px;" src="http://2.bp.blogspot.com/-fSnDCwH5-kg/TwwZPqNRaFI/AAAAAAAAnVY/bWFpHSa8zgA/s320/folder%2Bvisa.jpg" alt="" id="BLOGGER_PHOTO_ID_5695955385535522898" border="0" /&gt;&lt;/a&gt;In questo screenshot, invece,&lt;span style="font-weight: bold;"&gt;  l'attuale homepage del sito compromesso&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-sXRRDP7RtzU/TwwZPazHzJI/AAAAAAAAnVQ/97uYsMRafs8/s1600/home%2Bclone%2Bhacked%2B2012-01-10_164729.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 302px; height: 320px;" src="http://3.bp.blogspot.com/-sXRRDP7RtzU/TwwZPazHzJI/AAAAAAAAnVQ/97uYsMRafs8/s320/home%2Bclone%2Bhacked%2B2012-01-10_164729.jpg" alt="" id="BLOGGER_PHOTO_ID_5695955381399309458" border="0" /&gt;&lt;/a&gt;che, da una analisi della &lt;span style="font-weight: bold;"&gt;cache Google&lt;/span&gt;, parrebbe essere stato preso di mira &lt;span style="font-weight: bold;"&gt;gia' da qualche giorno, senza che chi lo amministra sia intervenuto. (sito non piu attivo ?)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-oeXaj10gIjs/TwwZPtHrK3I/AAAAAAAAnVo/_1Dl5DjZGAo/s1600/snap%2B30%2Bdic%2Bgia%2Bhack.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 274px;" src="http://4.bp.blogspot.com/-oeXaj10gIjs/TwwZPtHrK3I/AAAAAAAAnVo/_1Dl5DjZGAo/s320/snap%2B30%2Bdic%2Bgia%2Bhack.jpg" alt="" id="BLOGGER_PHOTO_ID_5695955386317351794" border="0" /&gt;&lt;/a&gt;Il dettaglio del&lt;span style="font-weight: bold;"&gt; clone VISA &lt;/span&gt;mostra testo in italiano ma con alcuni menu' e nomi di campi di input &lt;span style="font-weight: bold;"&gt;del form in lingua francese&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-t-RFEMRC8u4/TwwZQexx1bI/AAAAAAAAnV8/ij5Y0s6VtlE/s1600/italie.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 265px;" src="http://1.bp.blogspot.com/-t-RFEMRC8u4/TwwZQexx1bI/AAAAAAAAnV8/ij5Y0s6VtlE/s320/italie.jpg" alt="" id="BLOGGER_PHOTO_ID_5695955399647286706" border="0" /&gt;&lt;/a&gt;Una analisi del source delle pagine clone,&lt;span style="font-weight: bold;"&gt; oltre ad evidenziare che le stesse presentano il codice interamente offuscato,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-A8z9Y8JL1RU/TwwZQHudFKI/AAAAAAAAnV0/XZtzCyummH0/s1600/offu.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 215px;" src="http://4.bp.blogspot.com/-A8z9Y8JL1RU/TwwZQHudFKI/AAAAAAAAnV0/XZtzCyummH0/s320/offu.jpg" alt="" id="BLOGGER_PHOTO_ID_5695955393459328162" border="0" /&gt;&lt;/a&gt;conferma, deoffuscandole, sources&lt;span style="font-weight: bold;"&gt; originari da  sito VISA .CH in lingua francese,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/--Y2OrVnbV84/TwwZ_lT4iPI/AAAAAAAAnWw/tvlTigOlkRw/s1600/dec%2Bfr.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 218px;" src="http://1.bp.blogspot.com/--Y2OrVnbV84/TwwZ_lT4iPI/AAAAAAAAnWw/tvlTigOlkRw/s320/dec%2Bfr.jpg" alt="" id="BLOGGER_PHOTO_ID_5695956208854796530" border="0" /&gt;&lt;/a&gt;Questa la sequenza delle pagine clone proposte, sulle quali viene effettuato solo una verifica della presenza dei dati nei vari campi di input ma non della loro correttezza formale come visto altre volte (n.carta di credito, ecc....)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-4EoJS10L7MM/TwwZ--_GrFI/AAAAAAAAnWM/IDDGaS318Lk/s1600/1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 259px;" src="http://4.bp.blogspot.com/-4EoJS10L7MM/TwwZ--_GrFI/AAAAAAAAnWM/IDDGaS318Lk/s320/1.jpg" alt="" id="BLOGGER_PHOTO_ID_5695956198567095378" border="0" /&gt;&lt;/a&gt;da cui&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-IYXEDbxMNNM/TwwZ_KX67dI/AAAAAAAAnWU/AIo1A2UIeJ8/s1600/2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 272px;" src="http://1.bp.blogspot.com/-IYXEDbxMNNM/TwwZ_KX67dI/AAAAAAAAnWU/AIo1A2UIeJ8/s320/2.jpg" alt="" id="BLOGGER_PHOTO_ID_5695956201623973330" border="0" /&gt;&lt;/a&gt;Una volta acquisiti i dati si viene  &lt;span style="font-weight: bold;"&gt;reindirizzati al reale sito VISA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Sl6aR9n-2jw/TwwZ_Z8DJzI/AAAAAAAAnWg/n15HHgyQ0l0/s1600/redir%2Breale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 187px;" src="http://3.bp.blogspot.com/-Sl6aR9n-2jw/TwwZ_Z8DJzI/AAAAAAAAnWg/n15HHgyQ0l0/s320/redir%2Breale.jpg" alt="" id="BLOGGER_PHOTO_ID_5695956205802039090" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-977285262375538358?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/977285262375538358/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=977285262375538358' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/977285262375538358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/977285262375538358'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-verified-by-visa-10-gennaio.html' title='Phishing &apos;Verified by VISA” (10 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-fSnDCwH5-kg/TwwZPqNRaFI/AAAAAAAAnVY/bWFpHSa8zgA/s72-c/folder%2Bvisa.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4481859871930850933</id><published>2012-01-09T21:54:00.007+07:00</published><updated>2012-01-09T22:19:52.271+07:00</updated><title type='text'>Phishing Banca Reale (9 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ricevuta mail di phishing &lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Banca Reale&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-IQ4u3fiF1D8/TwsAk8OKHVI/AAAAAAAAnTY/jFQz_b3WALE/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 227px;" src="http://3.bp.blogspot.com/-IQ4u3fiF1D8/TwsAk8OKHVI/AAAAAAAAnTY/jFQz_b3WALE/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5695646788380925266" border="0" /&gt;&lt;/a&gt;Contrariamente ai consueti utilizzi di &lt;span style="font-weight: bold;"&gt;Asset Manager&lt;/span&gt; questo caso presenta&lt;span style="font-weight: bold;"&gt; l'uso di due siti creati allo scopo e che a loro volta vengono utilizzati per creare sotto-domini&lt;/span&gt; che puntano a differenti &lt;span style="font-weight: bold;"&gt;Ip appartenenti a siti compromessi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Tra l'altro, come vedremo,&lt;span style="font-weight: bold;"&gt; il sito utilizzato per l'hosting del clone ha incluso un codice php usato in passato per phishing CartaSi ed attualmente ancora attivo.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questi i &lt;span style="font-weight: bold;"&gt;dns relativi al redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-W-3pMhZ0tIM/TwsA6PoTXLI/AAAAAAAAnTk/kTSjJWrl6sE/s1600/dns%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 133px;" src="http://1.bp.blogspot.com/-W-3pMhZ0tIM/TwsA6PoTXLI/AAAAAAAAnTk/kTSjJWrl6sE/s320/dns%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5695647154368109746" border="0" /&gt;&lt;/a&gt;che mostrano sito creato in data odierna&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-lQ100OBI0O4/TwsA6PUQw_I/AAAAAAAAnTs/c-qS_ffliq0/s1600/dom%2Bredir%2B012-01-09_201402.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 258px;" src="http://2.bp.blogspot.com/-lQ100OBI0O4/TwsA6PUQw_I/AAAAAAAAnTs/c-qS_ffliq0/s320/dom%2Bredir%2B012-01-09_201402.jpg" alt="" id="BLOGGER_PHOTO_ID_5695647154284053490" border="0" /&gt;&lt;/a&gt;e redirect attivo su &lt;span style="font-weight: bold;"&gt;sotto-dominio dello stesso con differente IP&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;L'implementazione del&lt;span style="font-weight: bold;"&gt; phishing, l'uso di redirects tramite sotto-domini  e la particolare struttura del codice di redirect presente&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-FWzjhf-zX3c/TwsBS0j5iJI/AAAAAAAAnT8/6kaYSqoeJB8/s1600/code%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 196px;" src="http://2.bp.blogspot.com/-FWzjhf-zX3c/TwsBS0j5iJI/AAAAAAAAnT8/6kaYSqoeJB8/s320/code%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5695647576598612114" border="0" /&gt;&lt;/a&gt;ricordano questo phishing&lt;a style="font-weight: bold;" href="http://edetools.blogspot.com/2012/01/ulteriore-phishing-posteit-3-gennaio.html"&gt;  PosteIT di inizio 2012&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-3LyXdF1ROL4/TwKlOaHGQPI/AAAAAAAAnB0/v2Kenq8fc3c/s1600/det%2Bcina%2Bwh%2Be%2Bcode%2Bred.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 152px;" src="http://4.bp.blogspot.com/-3LyXdF1ROL4/TwKlOaHGQPI/AAAAAAAAnB0/v2Kenq8fc3c/s320/det%2Bcina%2Bwh%2Be%2Bcode%2Bred.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294545895571698" border="0" /&gt;&lt;/a&gt;Anche l'hosting del clone come si &lt;span style="font-weight: bold;"&gt;vede dai DNS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-igZ9XjYXmJ4/TwsB8rwfYNI/AAAAAAAAnUI/eEAFtsI5QxQ/s1600/domai%2Be%2Bsub%2Bph%2Bsite.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 154px;" src="http://3.bp.blogspot.com/-igZ9XjYXmJ4/TwsB8rwfYNI/AAAAAAAAnUI/eEAFtsI5QxQ/s320/domai%2Be%2Bsub%2Bph%2Bsite.jpg" alt="" id="BLOGGER_PHOTO_ID_5695648295790010578" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;usa dominio&lt;/span&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-NUCinjk2h3Y/TwsB8mQJrtI/AAAAAAAAnUQ/FoYk43oywVo/s1600/domain%2Bclone%2Bcreated.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 310px;" src="http://1.bp.blogspot.com/-NUCinjk2h3Y/TwsB8mQJrtI/AAAAAAAAnUQ/FoYk43oywVo/s320/domain%2Bclone%2Bcreated.jpg" alt="" id="BLOGGER_PHOTO_ID_5695648294312193746" border="0" /&gt;&lt;/a&gt;e sotto-dominio che&lt;span style="font-weight: bold;"&gt; propone diverso IP&lt;/span&gt; con incluso anche questo php, servito in passato a supporto di  phishing &lt;span style="font-weight: bold;"&gt;CartaSi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-iQdL66azHc4/TwsB8-EjVHI/AAAAAAAAnUg/C9BgOFoPsu0/s1600/a%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 45px;" src="http://4.bp.blogspot.com/-iQdL66azHc4/TwsB8-EjVHI/AAAAAAAAnUg/C9BgOFoPsu0/s320/a%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5695648300705993842" border="0" /&gt;&lt;/a&gt;Questo il clone &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Banca Reale&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-JptMCg0Q4C4/TwsDxe8mKII/AAAAAAAAnVE/MKbbVWYJU0o/s1600/clonw%2Bhome.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 250px;" src="http://1.bp.blogspot.com/-JptMCg0Q4C4/TwsDxe8mKII/AAAAAAAAnVE/MKbbVWYJU0o/s320/clonw%2Bhome.jpg" alt="" id="BLOGGER_PHOTO_ID_5695650302395820162" border="0" /&gt;&lt;/a&gt;con relativa pagina di richiesta pin&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-QJOC1k4TO7o/TwsDxNG_oBI/AAAAAAAAnU4/YzdgXb3bwSQ/s1600/clone2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 173px;" src="http://1.bp.blogspot.com/-QJOC1k4TO7o/TwsDxNG_oBI/AAAAAAAAnU4/YzdgXb3bwSQ/s320/clone2.jpg" alt="" id="BLOGGER_PHOTO_ID_5695650297607594002" border="0" /&gt;&lt;/a&gt;e che redirige poi al reale sito &lt;span style="font-weight: bold;"&gt;Banca Reale&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-iuRTRMrliJ4/TwsDxLCdXdI/AAAAAAAAnUs/cpvANatftGQ/s1600/reale%2Breale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 258px;" src="http://3.bp.blogspot.com/-iuRTRMrliJ4/TwsDxLCdXdI/AAAAAAAAnUs/cpvANatftGQ/s320/reale%2Breale.jpg" alt="" id="BLOGGER_PHOTO_ID_5695650297051700690" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4481859871930850933?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4481859871930850933/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4481859871930850933' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4481859871930850933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4481859871930850933'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-banca-reale-9-gennaio.html' title='Phishing Banca Reale (9 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-IQ4u3fiF1D8/TwsAk8OKHVI/AAAAAAAAnTY/jFQz_b3WALE/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-9194396931418567715</id><published>2012-01-09T18:09:00.003+07:00</published><updated>2012-01-09T18:25:04.362+07:00</updated><title type='text'>Phishing CartaSi (9 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ancora phishing&lt;span style="font-weight: bold;"&gt; ai danni di &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt; &lt;/span&gt;segnalato in rete e che vede&lt;span style="font-weight: bold;"&gt; il clone ospitato su sito compromesso con dominio .nl ma con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-adEmZqda0AM/TwrLlshHI6I/AAAAAAAAnQQ/ioXFxzIiE5A/s1600/wh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 182px;" src="http://2.bp.blogspot.com/-adEmZqda0AM/TwrLlshHI6I/AAAAAAAAnQQ/ioXFxzIiE5A/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5695588527229051810" border="0" /&gt;&lt;/a&gt;La struttura del sito rivela la presenza di folder con contenuti php tipici di &lt;span style="font-weight: bold;"&gt;shells con accesso anche attraverso password, ed alcuni subfolders&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-NJJWtB8kA_Y/TwrLmqS9KgI/AAAAAAAAnRE/-idQc3aUo-Q/s1600/2%2Bfolders.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 182px;" src="http://4.bp.blogspot.com/-NJJWtB8kA_Y/TwrLmqS9KgI/AAAAAAAAnRE/-idQc3aUo-Q/s320/2%2Bfolders.jpg" alt="" id="BLOGGER_PHOTO_ID_5695588543812676098" border="0" /&gt;&lt;/a&gt;utilizzati sia &lt;span style="font-weight: bold;"&gt;per hostare il phishing CartaSi ma anche kit di phishing con data recente&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-5_Or6ikgXMU/TwrMnB84wLI/AAAAAAAAnRk/tXX80evYYJA/s1600/rc%2Bkit.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 154px;" src="http://1.bp.blogspot.com/-5_Or6ikgXMU/TwrMnB84wLI/AAAAAAAAnRk/tXX80evYYJA/s320/rc%2Bkit.jpg" alt="" id="BLOGGER_PHOTO_ID_5695589649674191026" border="0" /&gt;&lt;/a&gt;ai danni di&lt;span style="font-weight: bold;"&gt;  &lt;span style="color: rgb(255, 102, 102);"&gt;RBC &lt;/span&gt;( Royal Bank of Canada. - da Wikipedia)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-WkEJqGW__rU/TwrMmyYxzqI/AAAAAAAAnRU/8RMeieXS2dY/s1600/rbc%2Bkit%2Bpage.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 201px;" src="http://1.bp.blogspot.com/-WkEJqGW__rU/TwrMmyYxzqI/AAAAAAAAnRU/8RMeieXS2dY/s320/rbc%2Bkit%2Bpage.jpg" alt="" id="BLOGGER_PHOTO_ID_5695589645496209058" border="0" /&gt;&lt;/a&gt;Per quanto si riferisce al &lt;span style="font-weight: bold;"&gt;clone &lt;span style="color: rgb(255, 102, 102);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt; questo appare con layout non recente e con pagina di form di acquisizione credenziali&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-lL1OEZbwFVs/TwrLmOfBjxI/AAAAAAAAnQk/8EAyR4oj4d8/s1600/form.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 278px;" src="http://2.bp.blogspot.com/-lL1OEZbwFVs/TwrLmOfBjxI/AAAAAAAAnQk/8EAyR4oj4d8/s320/form.jpg" alt="" id="BLOGGER_PHOTO_ID_5695588536347102994" border="0" /&gt;&lt;/a&gt;che utilizza codice php di invio dati,&lt;span style="font-weight: bold;"&gt; ad indirizzo mail differente da quelli visti nei recenti attacchi a CartaSi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-acShtI5jF4U/TwrMm8fHaoI/AAAAAAAAnRM/RG69P7iDHCE/s1600/php%2Bform%2Bsend%2Bcred.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 319px; height: 320px;" src="http://3.bp.blogspot.com/-acShtI5jF4U/TwrMm8fHaoI/AAAAAAAAnRM/RG69P7iDHCE/s320/php%2Bform%2Bsend%2Bcred.jpg" alt="" id="BLOGGER_PHOTO_ID_5695589648207145602" border="0" /&gt;&lt;/a&gt;Sono inoltre presenti &lt;span style="font-weight: bold;"&gt;mailer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-6IO24QiJJ0E/TwrLl67l0ZI/AAAAAAAAnQc/dAsV4IOgfrE/s1600/mas%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 298px;" src="http://1.bp.blogspot.com/-6IO24QiJJ0E/TwrLl67l0ZI/AAAAAAAAnQc/dAsV4IOgfrE/s320/mas%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5695588531098210706" border="0" /&gt;&lt;/a&gt;ed un altro codice php &lt;span style="font-weight: bold;"&gt;collegato a probabile phishing AOL o Yahoo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-kJt7addnVgY/TwrLmd7asPI/AAAAAAAAnQ0/VWqR6dHizzc/s1600/code%2Bphp%2Bsen%2Baol%2Bo%2Byahoo.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 270px;" src="http://4.bp.blogspot.com/-kJt7addnVgY/TwrLmd7asPI/AAAAAAAAnQ0/VWqR6dHizzc/s320/code%2Bphp%2Bsen%2Baol%2Bo%2Byahoo.jpg" alt="" id="BLOGGER_PHOTO_ID_5695588540492722418" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-9194396931418567715?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/9194396931418567715/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=9194396931418567715' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/9194396931418567715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/9194396931418567715'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-cartasi-9-gennaio.html' title='Phishing CartaSi (9 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-adEmZqda0AM/TwrLlshHI6I/AAAAAAAAnQQ/ioXFxzIiE5A/s72-c/wh.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8489200621535886379</id><published>2012-01-07T11:51:00.011+07:00</published><updated>2012-01-08T17:36:19.272+07:00</updated><title type='text'>Siti IT compromessi con inclusione di script pericolosi (7 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;AVVISO      IMPORTANTE!     Ricordo che anche se alcuni links sono lasciati in      chiaro  negli    screenshot, evitate di visitare i siti elencati se non      avete preso     tutte le precauzioni del caso ! Si tratta di  pagine  e    siti  che distribuiscono eseguibili MALWARE, tra l'altro, anche poco    riconosciuti dai    software AV.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Una analisi&lt;span style="font-weight: bold;"&gt; Webscanner&lt;/span&gt; su siti trovati&lt;span style="font-weight: bold;"&gt; con reverse IP di&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-rm8srwRommI/TwfQGYiRpdI/AAAAAAAAnMU/Xho1oINOqw8/s1600/wh%2Bit%2Bsiti%2Bcompro.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 173px;" src="http://4.bp.blogspot.com/-rm8srwRommI/TwfQGYiRpdI/AAAAAAAAnMU/Xho1oINOqw8/s320/wh%2Bit%2Bsiti%2Bcompro.jpg" alt="" id="BLOGGER_PHOTO_ID_5694749061917287890" border="0" /&gt;&lt;/a&gt;evidenzia che praticamente&lt;span style="font-weight: bold;"&gt; tutti  i domini e relativi sotto-domini presenti&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-AvdGCkx3N7M/TwfP6PRpeUI/AAAAAAAAnLY/mdybf_sSTl8/s1600/webfolderscanner%2B2012-01-07_104621.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 242px;" src="http://3.bp.blogspot.com/-AvdGCkx3N7M/TwfP6PRpeUI/AAAAAAAAnLY/mdybf_sSTl8/s320/webfolderscanner%2B2012-01-07_104621.jpg" alt="" id="BLOGGER_PHOTO_ID_5694748853273196866" border="0" /&gt;&lt;/a&gt;hanno &lt;span style="font-weight: bold;"&gt;incluso (in homepage ma anche in altre pagine)  il codice offuscato che vediamo in dettaglio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-V2k7BIrhINc/TwfP6GdgDGI/AAAAAAAAnLg/fwTnzYfVAqY/s1600/scrip%2Bsu%2Bhome.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 210px;" src="http://2.bp.blogspot.com/-V2k7BIrhINc/TwfP6GdgDGI/AAAAAAAAnLg/fwTnzYfVAqY/s320/scrip%2Bsu%2Bhome.jpg" alt="" id="BLOGGER_PHOTO_ID_5694748850906991714" border="0" /&gt;&lt;/a&gt;Una volta&lt;span style="font-weight: bold;"&gt; de-offuscato, possiamo notare link a sito su dominio ......&lt;span style="color: rgb(255, 0, 0);"&gt;osa.pl&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Hwb1OQACsuQ/TwfP6fK-ceI/AAAAAAAAnL0/nvd4EBjusg0/s1600/decoded.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 163px;" src="http://1.bp.blogspot.com/-Hwb1OQACsuQ/TwfP6fK-ceI/AAAAAAAAnL0/nvd4EBjusg0/s320/decoded.jpg" alt="" id="BLOGGER_PHOTO_ID_5694748857540178402" border="0" /&gt;&lt;/a&gt;In realta' possiamo facilmente&lt;span style="font-weight: bold;"&gt; identificare il dominio &lt;span style="color: rgb(255, 0, 0);"&gt;osa.pl &lt;/span&gt;come appartenente a&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-T12zIUE-q18/TwfP66TajjI/AAAAAAAAnL8/e4GzooylS-8/s1600/wh%2Bosa%2Bpl.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 104px;" src="http://3.bp.blogspot.com/-T12zIUE-q18/TwfP66TajjI/AAAAAAAAnL8/e4GzooylS-8/s320/wh%2Bosa%2Bpl.jpg" alt="" id="BLOGGER_PHOTO_ID_5694748864823332402" border="0" /&gt;&lt;/a&gt;che evidenzia un servizio di free web domains ed alias polacco.&lt;br /&gt;&lt;br /&gt;Questo un dettaglio del sito in questione&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-0AjdsPrpnZ4/TwfP7BlVkQI/AAAAAAAAnMI/VMp-D_Vwma4/s1600/alias%2Bosa%2Bpl.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 275px;" src="http://3.bp.blogspot.com/-0AjdsPrpnZ4/TwfP7BlVkQI/AAAAAAAAnMI/VMp-D_Vwma4/s320/alias%2Bosa%2Bpl.jpg" alt="" id="BLOGGER_PHOTO_ID_5694748866777551106" border="0" /&gt;&lt;/a&gt;con evidente uso del nome&lt;span style="font-weight: bold;"&gt; di dominio osa.pl&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Detto dominio parrebbe essere molto utilizzato&lt;span style="font-style: italic; font-weight: bold;"&gt; per 'mascherare' distribuzione malware&lt;/span&gt; come denota ad esempio Norton Safe Webscanner&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-tFkM76pZD3w/TwfQt6NvjxI/AAAAAAAAnMg/GysPdIiKVzw/s1600/norton%2Bsafe%2Bweb.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 192px;" src="http://4.bp.blogspot.com/-tFkM76pZD3w/TwfQt6NvjxI/AAAAAAAAnMg/GysPdIiKVzw/s320/norton%2Bsafe%2Bweb.jpg" alt="" id="BLOGGER_PHOTO_ID_5694749740972871442" border="0" /&gt;&lt;/a&gt;Il &lt;span style="font-weight: bold;"&gt;reale IP puntato dall'indirizzo presente nello script e'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-74q4i_HbUyg/TwfQuj2X5hI/AAAAAAAAnNE/4ETvG9ns3MM/s1600/whredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://3.bp.blogspot.com/-74q4i_HbUyg/TwfQuj2X5hI/AAAAAAAAnNE/4ETvG9ns3MM/s320/whredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5694749752149141010" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con pagina&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-WeNKbtvgRxU/TwfQuD_k2wI/AAAAAAAAnM4/27xKvGBJMfc/s1600/oa%2Bpl%2Blinkato%2Bsito%2Bit.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 163px;" src="http://2.bp.blogspot.com/-WeNKbtvgRxU/TwfQuD_k2wI/AAAAAAAAnM4/27xKvGBJMfc/s320/oa%2Bpl%2Blinkato%2Bsito%2Bit.jpg" alt="" id="BLOGGER_PHOTO_ID_5694749743597804290" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;e codice&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-sTW5seE3vEc/TwfRUeuslcI/AAAAAAAAnNU/41uQOWHHz3M/s1600/code%2Bsito%2Bru%2Bredirected.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 56px;" src="http://3.bp.blogspot.com/-sTW5seE3vEc/TwfRUeuslcI/AAAAAAAAnNU/41uQOWHHz3M/s320/code%2Bsito%2Bru%2Bredirected.jpg" alt="" id="BLOGGER_PHOTO_ID_5694750403609793986" border="0" /&gt;&lt;/a&gt;Una analisi del source consente di&lt;span style="font-weight: bold;"&gt; individuare due download di files .jar&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-RZNm-UBMwKc/TwfQuMG-35I/AAAAAAAAnMo/C1_lzfIE_uw/s1600/jars.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 83px;" src="http://4.bp.blogspot.com/-RZNm-UBMwKc/TwfQuMG-35I/AAAAAAAAnMo/C1_lzfIE_uw/s320/jars.jpg" alt="" id="BLOGGER_PHOTO_ID_5694749745776353170" border="0" /&gt;&lt;/a&gt;che una volta scaricati passiamo &lt;span style="font-weight: bold;"&gt;a Virus Total.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I risultati dimostrano che&lt;span style="font-weight: bold;"&gt; entrambi i files&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-hGdjUAF9R_A/TwfRUj9eTsI/AAAAAAAAnNc/ONV4fJJoPcY/s1600/topattuale%2Bjar1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 78px;" src="http://2.bp.blogspot.com/-hGdjUAF9R_A/TwfRUj9eTsI/AAAAAAAAnNc/ONV4fJJoPcY/s320/topattuale%2Bjar1.jpg" alt="" id="BLOGGER_PHOTO_ID_5694750405013950146" border="0" /&gt;&lt;/a&gt;&lt;a href="http://1.bp.blogspot.com/-o2Q-EQPd92M/TwfRU9QsoLI/AAAAAAAAnNw/CWtNu2k3x3E/s1600/repo%2Batt%2Bjar1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 156px;" src="http://1.bp.blogspot.com/-o2Q-EQPd92M/TwfRU9QsoLI/AAAAAAAAnNw/CWtNu2k3x3E/s320/repo%2Batt%2Bjar1.jpg" alt="" id="BLOGGER_PHOTO_ID_5694750411805466802" border="0" /&gt;&lt;/a&gt;ed&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-QW2u-NjxJqk/TwfRvG7QM3I/AAAAAAAAnN4/ZvFqwxTzqvY/s1600/jar%2B2%2Bvt%2Btop.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 70px;" src="http://2.bp.blogspot.com/-QW2u-NjxJqk/TwfRvG7QM3I/AAAAAAAAnN4/ZvFqwxTzqvY/s320/jar%2B2%2Bvt%2Btop.jpg" alt="" id="BLOGGER_PHOTO_ID_5694750861076476786" border="0" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/-V72z3w8BUHI/TwfRvLLmyUI/AAAAAAAAnOA/OEMNXqmB2Q4/s1600/report%2Battu%2Bjar2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 173px;" src="http://4.bp.blogspot.com/-V72z3w8BUHI/TwfRvLLmyUI/AAAAAAAAnOA/OEMNXqmB2Q4/s320/report%2Battu%2Bjar2.jpg" alt="" id="BLOGGER_PHOTO_ID_5694750862218807618" border="0" /&gt;&lt;/a&gt;sono identificati come&lt;span style="font-weight: bold;"&gt; malware anche se in maniera estremamente bassa &lt;/span&gt;come succede spesso in questi casi dove i codici  malevoli possono essere aggiornati in tempo reale per evitare o ridurre  il riconoscimento da parte dei software AV&lt;br /&gt;&lt;br /&gt;Qui invece alcuni dettagli della relazione tra&lt;span style="font-weight: bold;"&gt; IP russo e dominio osa.pl coinvolto&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-TELJh9Cwpl8/TwfVxd0AKRI/AAAAAAAAnOQ/Q8yciqqVDgk/s1600/dett%2Bip%2Brusso.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 105px;" src="http://3.bp.blogspot.com/-TELJh9Cwpl8/TwfVxd0AKRI/AAAAAAAAnOQ/Q8yciqqVDgk/s320/dett%2Bip%2Brusso.jpg" alt="" id="BLOGGER_PHOTO_ID_5694755299626330386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8489200621535886379?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8489200621535886379/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8489200621535886379' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8489200621535886379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8489200621535886379'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/siti-it-compromessi-con-inclusione-di.html' title='Siti IT compromessi con inclusione di script pericolosi (7 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-rm8srwRommI/TwfQGYiRpdI/AAAAAAAAnMU/Xho1oINOqw8/s72-c/wh%2Bit%2Bsiti%2Bcompro.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-283684996773058957</id><published>2012-01-06T19:23:00.007+07:00</published><updated>2012-01-08T17:35:11.300+07:00</updated><title type='text'>Ingannevole phishing PayPal IT(6 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ecco l'odierna mail che si dimostra abbastanza&lt;span style="font-weight: bold;"&gt; ingannevole&lt;/span&gt; considerata  &lt;span style="font-weight: bold;"&gt;la cura posta dai phishers nel creare le pagine clone &lt;span style="color: rgb(255, 0, 0);"&gt;PayPal&lt;/span&gt; ed  in particolare anche quelle che simulano la connessione al servizio e l'eventuale richiesta di dati personali di conto.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-kB3wUth7EW0/Twbo9ntd2MI/AAAAAAAAnIw/jdsBbnHNXl0/s1600/mail%2B2012-01-06_153454.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 318px;" src="http://4.bp.blogspot.com/-kB3wUth7EW0/Twbo9ntd2MI/AAAAAAAAnIw/jdsBbnHNXl0/s320/mail%2B2012-01-06_153454.jpg" alt="" id="BLOGGER_PHOTO_ID_5694494924185917634" border="0" /&gt;&lt;/a&gt;Il testo in mail informa &lt;span style="font-weight: bold;"&gt;del  blocco del nostro account,&lt;/span&gt; riportando &lt;span style="font-weight: bold;"&gt;date recenti &lt;/span&gt;(quella di ieri) e propone&lt;span style="font-weight: bold;"&gt; come soluzione diversi links che puntano, naturalmente, al falso sito PayPal&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Vediamo alcuni dettali:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il link in mail richiama &lt;span style="font-weight: bold;"&gt;un redirect ospitato su sito compromesso con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-teJiH_MC1hQ/Twbo-etWidI/AAAAAAAAnJU/pa4L73HfsdA/s1600/wh%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://4.bp.blogspot.com/-teJiH_MC1hQ/Twbo-etWidI/AAAAAAAAnJU/pa4L73HfsdA/s320/wh%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5694494938949388754" border="0" /&gt;&lt;/a&gt;Sempre sullo stesso sito &lt;span style="font-weight: bold;"&gt;troviamo codici php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-1Yc_IQ7z80o/Twbo91aG5CI/AAAAAAAAnI8/q2mjoQV9_PM/s1600/php.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 230px; height: 320px;" src="http://2.bp.blogspot.com/-1Yc_IQ7z80o/Twbo91aG5CI/AAAAAAAAnI8/q2mjoQV9_PM/s320/php.jpg" alt="" id="BLOGGER_PHOTO_ID_5694494927862817826" border="0" /&gt;&lt;/a&gt;tra cui&lt;span style="font-weight: bold;"&gt; shell (protetta da password)  e programma mailer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-oBl25o1ra_U/Twbo-Gv_tLI/AAAAAAAAnJE/PPkjOYtg_7k/s1600/mailer.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 124px;" src="http://4.bp.blogspot.com/-oBl25o1ra_U/Twbo-Gv_tLI/AAAAAAAAnJE/PPkjOYtg_7k/s320/mailer.jpg" alt="" id="BLOGGER_PHOTO_ID_5694494932518024370" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Il sito clone, a cui si viene rediretti&lt;/span&gt;, e' ospitato su sottodominio &lt;span style="font-weight: bold;"&gt;appartenente ancora a dominio .RO&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-WRTnRaD1k8Q/Twbpuvb2C5I/AAAAAAAAnJg/IYTrMfllIqE/s1600/wh%2Bdominio%2Bcon%2Bsub%2Bcanada%2Bhost%2Bph.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://1.bp.blogspot.com/-WRTnRaD1k8Q/Twbpuvb2C5I/AAAAAAAAnJg/IYTrMfllIqE/s320/wh%2Bdominio%2Bcon%2Bsub%2Bcanada%2Bhost%2Bph.jpg" alt="" id="BLOGGER_PHOTO_ID_5694495768073079698" border="0" /&gt;&lt;/a&gt;sottodominio che&lt;span style="font-weight: bold;"&gt; in realta' rivela IP relativo a server canadese&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-Q_1rsuMxeqk/TwbpuihTlGI/AAAAAAAAnJs/4iv1iSwA3mA/s1600/reale%2Bwh%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 147px;" src="http://2.bp.blogspot.com/-Q_1rsuMxeqk/TwbpuihTlGI/AAAAAAAAnJs/4iv1iSwA3mA/s320/reale%2Bwh%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5694495764606325858" border="0" /&gt;&lt;/a&gt;come si nota anche da una analisi dei records &lt;span style="font-weight: bold;"&gt;DNS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-nX6x-0V5KzA/TwbpvMm7ElI/AAAAAAAAnJ0/0oU5X75xk9w/s1600/dns.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 202px;" src="http://4.bp.blogspot.com/-nX6x-0V5KzA/TwbpvMm7ElI/AAAAAAAAnJ0/0oU5X75xk9w/s320/dns.jpg" alt="" id="BLOGGER_PHOTO_ID_5694495775904174674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;La&lt;span style="font-weight: bold;"&gt; homepage di phishing, identica all'originale login PayPal, propone sito clone in italiano che verifica sommariamente i dati inseriti&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-fraBrM4CWKE/TwbqMMg6wTI/AAAAAAAAnKE/O5jANkc87lU/s1600/clone%2B1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 246px;" src="http://3.bp.blogspot.com/-fraBrM4CWKE/TwbqMMg6wTI/AAAAAAAAnKE/O5jANkc87lU/s320/clone%2B1.jpg" alt="" id="BLOGGER_PHOTO_ID_5694496274095194418" border="0" /&gt;&lt;/a&gt;e che pone &lt;span style="font-weight: bold;"&gt;particolare cura nel simulare l'attesa per la connessione al form di login, attraverso questa pagina animata&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-lbW1EF_RQKc/TwbqMfZ86-I/AAAAAAAAnKU/6Yv5h88D-68/s1600/clone%2B2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 144px;" src="http://2.bp.blogspot.com/-lbW1EF_RQKc/TwbqMfZ86-I/AAAAAAAAnKU/6Yv5h88D-68/s320/clone%2B2.jpg" alt="" id="BLOGGER_PHOTO_ID_5694496279166249954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il lungo form di richiesta dati&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-KnQeGmyuWLU/TwbqMwDFZVI/AAAAAAAAnKk/riA8CJi58Xs/s1600/ph%2Brich%2Bdati.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 272px; height: 320px;" src="http://1.bp.blogspot.com/-KnQeGmyuWLU/TwbqMwDFZVI/AAAAAAAAnKk/riA8CJi58Xs/s320/ph%2Brich%2Bdati.jpg" alt="" id="BLOGGER_PHOTO_ID_5694496283633739090" border="0" /&gt;&lt;/a&gt; nel caso si cliccasse sulle&lt;span style="font-weight: bold;"&gt; opzioni di visualizzazione dei dettagli del conto&lt;/span&gt;, propone anche una&lt;span style="font-weight: bold;"&gt; fake segnalazione di 'dati non disponibili al momento'&lt;span style="color: rgb(204, 0, 0);"&gt; cercando di dare una parvenza di autenticita' al sito clone&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-p884DB6x12A/TwbqM8e7WvI/AAAAAAAAnKc/f6YlzXYHmu8/s1600/spiacenti.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 198px;" src="http://3.bp.blogspot.com/-p884DB6x12A/TwbqM8e7WvI/AAAAAAAAnKc/f6YlzXYHmu8/s320/spiacenti.jpg" alt="" id="BLOGGER_PHOTO_ID_5694496286971747058" border="0" /&gt;&lt;/a&gt;Anche al &lt;span style="font-weight: bold;"&gt;termine della sessione di input dei dati verra' proposta una pagina di conferma dell'avvenuta riattivazione del nostro account&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-NwIq-NKj-A8/TwbqNNbd84I/AAAAAAAAnKs/4hNvVFZWlHY/s1600/conferma%2Bph.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 168px;" src="http://2.bp.blogspot.com/-NwIq-NKj-A8/TwbqNNbd84I/AAAAAAAAnKs/4hNvVFZWlHY/s320/conferma%2Bph.jpg" alt="" id="BLOGGER_PHOTO_ID_5694496291520639874" border="0" /&gt;&lt;/a&gt; nonche' una &lt;span style="font-weight: bold;"&gt;fake pagina finale con possibilita' eventuale di riconnettersi al sito PayPal&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-b1oH7GigPkg/TwbrLJEpPfI/AAAAAAAAnLA/-j-Le9DEbOU/s1600/ph%2Bvuoi%2Bnuovam%2Bacc.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 165px;" src="http://2.bp.blogspot.com/-b1oH7GigPkg/TwbrLJEpPfI/AAAAAAAAnLA/-j-Le9DEbOU/s320/ph%2Bvuoi%2Bnuovam%2Bacc.jpg" alt="" id="BLOGGER_PHOTO_ID_5694497355503058418" border="0" /&gt;&lt;/a&gt; che naturalmente, &lt;span style="font-weight: bold;"&gt;questa volta, sara' quello reale.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ywTze8QYu2U/TwbrLeKZOVI/AAAAAAAAnLM/fONzLLCFOmw/s1600/reaale%2Bpay%2Briaccede.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://3.bp.blogspot.com/-ywTze8QYu2U/TwbrLeKZOVI/AAAAAAAAnLM/fONzLLCFOmw/s320/reaale%2Bpay%2Briaccede.jpg" alt="" id="BLOGGER_PHOTO_ID_5694497361164319058" border="0" /&gt;&lt;/a&gt;Un phishing quindi&lt;span style="font-weight: bold;"&gt; ingannevole e  ben curato nei dettagli&lt;/span&gt; che vede forse solo, come&lt;span style="font-weight: bold;"&gt; 'lato debole' dell'attacco l'uso di indirizzi WEB per niente ingannevoli&lt;/span&gt;,  che dovrebbero 'insospettire' chi seguisse i links in mail, rivelando la natura fraudolenta delle pagine proposte.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-283684996773058957?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/283684996773058957/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=283684996773058957' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/283684996773058957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/283684996773058957'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-paypal-it6-gennaio.html' title='Ingannevole phishing PayPal IT(6 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-kB3wUth7EW0/Twbo9ntd2MI/AAAAAAAAnIw/jdsBbnHNXl0/s72-c/mail%2B2012-01-06_153454.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-3494000422643774288</id><published>2012-01-06T10:19:00.006+07:00</published><updated>2012-01-06T10:39:06.127+07:00</updated><title type='text'>Siti IT compromessi. (agg.6 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ritorno brevemente sulla &lt;span style="font-weight: bold;"&gt;presenza online di siti IT compromessi&lt;/span&gt; attraverso alcune odierne segnalazioni.&lt;br /&gt;&lt;br /&gt;Questo un report &lt;span style="font-weight: bold;"&gt;Webscanner&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-18EwOW77ABA/TwZoy_1O3oI/AAAAAAAAnGE/KHfuP29W0lM/s1600/rep%2Bobf.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 205px;" src="http://2.bp.blogspot.com/-18EwOW77ABA/TwZoy_1O3oI/AAAAAAAAnGE/KHfuP29W0lM/s320/rep%2Bobf.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354004194025090" border="0" /&gt;&lt;/a&gt;che evidenzia che praticamente&lt;span style="font-weight: bold;"&gt; tutti i siti rilevati con reverse IP su&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-01Tjm_udnns/TwZozG021bI/AAAAAAAAnGc/HIS2fYWMCac/s1600/wh%2Bob%2B2012-01-06_075122.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 124px;" src="http://3.bp.blogspot.com/-01Tjm_udnns/TwZozG021bI/AAAAAAAAnGc/HIS2fYWMCac/s320/wh%2Bob%2B2012-01-06_075122.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354006071498162" border="0" /&gt;&lt;/a&gt;presentano &lt;span style="font-weight: bold;"&gt;la homepage sostituita da&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-nH0NX9X4ATc/TwZoy8Xzy9I/AAAAAAAAnGM/WYj2nksnU4g/s1600/home.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 241px;" src="http://3.bp.blogspot.com/-nH0NX9X4ATc/TwZoy8Xzy9I/AAAAAAAAnGM/WYj2nksnU4g/s320/home.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354003265309650" border="0" /&gt;&lt;/a&gt;Come si vede &lt;span style="font-weight: bold;"&gt;dalla URL dello screenshot &lt;/span&gt;abbiamo anche un sito relativo a protezione civile del Nord Italia che e' stato colpito da questa azione di 'defacement' , cosa che mostra una certa pericolosita' dell'attacco in quanto potrebbe trattarsi di sito utilizzato per avvisi ed allerta  in caso di calamita' naturali ecc....&lt;br /&gt;&lt;br /&gt;Questi invece &lt;span style="font-weight: bold;"&gt;alcuni siti Comunali toscani con inclusa pagina di hacking:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-qVpXDG13qHo/TwZpIG5FoJI/AAAAAAAAnG0/2s7Mo4mCWdk/s1600/1%2Bcom%2Bhack.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 219px;" src="http://2.bp.blogspot.com/-qVpXDG13qHo/TwZpIG5FoJI/AAAAAAAAnG0/2s7Mo4mCWdk/s320/1%2Bcom%2Bhack.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354366866497682" border="0" /&gt;&lt;/a&gt;e whois&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-fi-R_IVKKDE/TwZpH2IcOEI/AAAAAAAAnGo/JXZIv45ER1w/s1600/1%2Bwh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 131px;" src="http://4.bp.blogspot.com/-fi-R_IVKKDE/TwZpH2IcOEI/AAAAAAAAnGo/JXZIv45ER1w/s320/1%2Bwh.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354362367490114" border="0" /&gt;&lt;/a&gt;ed anche&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-xLg5eftfT0c/TwZpdgzH-cI/AAAAAAAAnHA/qhyOVRSytn8/s1600/2%2Bcom%2Bhome.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 218px;" src="http://2.bp.blogspot.com/-xLg5eftfT0c/TwZpdgzH-cI/AAAAAAAAnHA/qhyOVRSytn8/s320/2%2Bcom%2Bhome.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354734598060482" border="0" /&gt;&lt;/a&gt;con whois&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-_bPJR988otM/TwZpdvyvswI/AAAAAAAAnHM/Q5RSnbRCUd4/s1600/2%2Bwh%2Bob.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 126px;" src="http://2.bp.blogspot.com/-_bPJR988otM/TwZpdvyvswI/AAAAAAAAnHM/Q5RSnbRCUd4/s320/2%2Bwh%2Bob.jpg" alt="" id="BLOGGER_PHOTO_ID_5694354738623001346" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Decine di siti hostati su&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-8jCnpKW2dpg/TwZp231oHWI/AAAAAAAAnHY/jrkZHjsCE38/s1600/3%2Bwh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 155px;" src="http://4.bp.blogspot.com/-8jCnpKW2dpg/TwZp231oHWI/AAAAAAAAnHY/jrkZHjsCE38/s320/3%2Bwh.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355170279300450" border="0" /&gt;&lt;/a&gt;presentano invece&lt;span style="font-weight: bold;"&gt; una inclusione di semplice file immagine jpg.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Un uso del tool &lt;span style="font-weight: bold;"&gt;Webscanner&lt;/span&gt; permette&lt;span style="font-weight: bold;"&gt; il download del file immagine  relativamente ad ogni sito individuato da reverse IP, dimostrando due differenti JPG utilizzate pur con il medesimo nome di file&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ygMtA6PeNxA/TwZp3GcatmI/AAAAAAAAnHk/n0702eZMZvc/s1600/listapict.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 167px;" src="http://3.bp.blogspot.com/-ygMtA6PeNxA/TwZp3GcatmI/AAAAAAAAnHk/n0702eZMZvc/s320/listapict.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355174200096354" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;In dettaglio abbiamo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-kCQYK-24gfs/TwZp3U34WmI/AAAAAAAAnHw/wNM47XaJ5pY/s1600/3%2Bimg1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 294px;" src="http://2.bp.blogspot.com/-kCQYK-24gfs/TwZp3U34WmI/AAAAAAAAnHw/wNM47XaJ5pY/s320/3%2Bimg1.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355178073381474" border="0" /&gt;&lt;/a&gt;ed anche&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-63jgnD99A3c/TwZp30db7pI/AAAAAAAAnH8/XeiLTan0jOY/s1600/3%2Bimg2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 315px;" src="http://3.bp.blogspot.com/-63jgnD99A3c/TwZp30db7pI/AAAAAAAAnH8/XeiLTan0jOY/s320/3%2Bimg2.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355186552401554" border="0" /&gt;&lt;/a&gt;Interessante notare &lt;span style="font-weight: bold;"&gt;che si tratta ancora una volta di siti che usano un versione datata e vulnerabile di Dot Net Nuke&lt;/span&gt; attraverso  '&lt;span style="font-style: italic; color: rgb(0, 51, 51);"&gt;gallery remote file upload without authentication' &lt;/span&gt; che permette &lt;span style="font-weight: bold;"&gt;l'accesso da remoto dell'interfaccia di amministrazione dei contenuti e l'upload di differenti files (txt,jpg ..)  anche con doppia estensione es. php.jpg&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-HEskReI8zWE/TwZp4Lz-lmI/AAAAAAAAnII/bS8wqZzhAXA/s1600/nuke%2Bupload.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 202px;" src="http://3.bp.blogspot.com/-HEskReI8zWE/TwZp4Lz-lmI/AAAAAAAAnII/bS8wqZzhAXA/s320/nuke%2Bupload.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355192820962914" border="0" /&gt;&lt;/a&gt;Esaminando &lt;span style="font-weight: bold;"&gt;l'interfaccia  di upload contenuti  &lt;/span&gt;di uno di questi siti vediamo come sia presente&lt;span style="font-weight: bold;"&gt; anche altro file jpg&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-NJnkiQ9t8ZQ/TwZqjgCKNlI/AAAAAAAAnIY/KRZPRth45rc/s1600/nuke%2Bdet.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 210px;" src="http://1.bp.blogspot.com/-NJnkiQ9t8ZQ/TwZqjgCKNlI/AAAAAAAAnIY/KRZPRth45rc/s320/nuke%2Bdet.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355936983529042" border="0" /&gt;&lt;/a&gt;come&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-t-BghIqURKo/TwZqjyF1VaI/AAAAAAAAnIk/iwYSd1YMwUY/s1600/nuke%2Baltro%2Bjppg.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://1.bp.blogspot.com/-t-BghIqURKo/TwZqjyF1VaI/AAAAAAAAnIk/iwYSd1YMwUY/s320/nuke%2Baltro%2Bjppg.jpg" alt="" id="BLOGGER_PHOTO_ID_5694355941830776226" border="0" /&gt;&lt;/a&gt;cosa che denota probabili &lt;span style="font-weight: bold;"&gt;precedenti attacchi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il fatto che da tempo (ormai anni) siano online siti con problemi &lt;span style="font-weight: bold;"&gt;DotNetNuke&lt;/span&gt; e' anche spiegabile con le modalita' di attacco specifiche per questo tipo di hacking, considerato che in generale si tratta di&lt;span style="font-weight: bold;"&gt; inclusioni di files testo o immagine in folders non direttamente coinvolti nel layout on-line del sito colpito &lt;/span&gt;e quindi e' molto probabile che chi lo amministra, non sia neanche a conoscenza dell'attacco.&lt;br /&gt;&lt;br /&gt;Ricordo comunque che sono&lt;span style="font-weight: bold;"&gt; molti i siti che usano versioni vulnerabili di DotNetNuke che mostrano  la presenza non solo di innocui file testo od immagine, ma di codici php, asp &lt;/span&gt; (shells) perfettamente attivi:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_-6waw8mcpyI/TEzx39LAx3I/AAAAAAAAaI0/67Jvpb54hGw/s1600/shell.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 277px;" src="http://2.bp.blogspot.com/_-6waw8mcpyI/TEzx39LAx3I/AAAAAAAAaI0/67Jvpb54hGw/s320/shell.jpg" alt="" id="BLOGGER_PHOTO_ID_5498035188728383346" border="0" /&gt;&lt;/a&gt;e che permettono di agire sul sito interessato ma, in alcuni casi, anche di poter 'navigare' tre i vari siti hostati sul server in questione.&lt;br /&gt;&lt;br /&gt;In questi casi si tratta di attacchi che potrebbero, ad esempio, essere sfruttati come supporto ad azioni di phishing, redirects a phishing, SEO poisoning ma anche distribuzione di links a malware o malware... ecc......&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-3494000422643774288?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/3494000422643774288/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=3494000422643774288' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3494000422643774288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3494000422643774288'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/siti-it-compromessi-agg6-gennaio.html' title='Siti IT compromessi. (agg.6 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-18EwOW77ABA/TwZoy_1O3oI/AAAAAAAAnGE/KHfuP29W0lM/s72-c/rep%2Bobf.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-7916748200158954377</id><published>2012-01-03T20:36:00.004+07:00</published><updated>2012-01-03T20:45:14.144+07:00</updated><title type='text'>Nuova mail di phishing CartaSi con interessanti conferme sull'attivita' dei phishers (3 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Per terminare la giornata, che ha visto &lt;span style="font-weight: bold;"&gt;la ricezione e l'analisi di diverse mails di phishing &lt;/span&gt;legate sia ad attacchi a &lt;span style="font-weight: bold;"&gt;CartaSi che PostePay (vedi i vari post odierni) &lt;/span&gt;  abbiamo questo ulteriore messaggio di posta elettronica che propone l'ennesimo phishing &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-adFdcnTFMXo/TwMExG36CtI/AAAAAAAAnDg/m7F8UypohqY/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 216px;" src="http://4.bp.blogspot.com/-adFdcnTFMXo/TwMExG36CtI/AAAAAAAAnDg/m7F8UypohqY/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5693399595631643346" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;Il layout e' simile ad&lt;span style="font-weight: bold;"&gt; altre mails fake ricevute,&lt;/span&gt; ma e' interessante analizzare&lt;span style="font-weight: bold;"&gt; in dettaglio, come il form allegato gestisca i dati eventualmente immessi da chi cadesse nel phishing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-eb0u_3RucKM/TwMExUqVUrI/AAAAAAAAnDs/E9F42ZesfIs/s1600/form.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://4.bp.blogspot.com/-eb0u_3RucKM/TwMExUqVUrI/AAAAAAAAnDs/E9F42ZesfIs/s320/form.jpg" alt="" id="BLOGGER_PHOTO_ID_5693399599332807346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Il codice php linkato al form e' infatti&lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://edetools.blogspot.com/2012/01/nuovo-anno-vecchio-phishing-phishing.html"&gt; hostato sullo stesso sito compromesso visto in mattinata &lt;/a&gt;nel caso di phishing &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;PostePay.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-3o1pqt0m9iA/TwMFWG6MKFI/AAAAAAAAnEQ/jmXbKot7B1c/s1600/form%2Baction.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 46px;" src="http://2.bp.blogspot.com/-3o1pqt0m9iA/TwMFWG6MKFI/AAAAAAAAnEQ/jmXbKot7B1c/s320/form%2Baction.jpg" alt="" id="BLOGGER_PHOTO_ID_5693400231296378962" border="0" /&gt;&lt;/a&gt;Una analisi del folder &lt;span style="font-weight: bold;"&gt;utilizzato attualmente per CartaSi&lt;/span&gt; mostra sia &lt;span style="font-weight: bold;"&gt;il file php &lt;/span&gt;che un file di&lt;span style="font-weight: bold;"&gt; elenco credenziali sottratte dal phishing &lt;/span&gt;ed entrambi con data odierna.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-m4Ja07W68t8/TwMExzr-y0I/AAAAAAAAnEA/e0-iKFu5HmM/s1600/dettagli%2Bphp%2Be%2Blista%2Bcredenz%2B2012-01-03_194200.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 122px;" src="http://3.bp.blogspot.com/-m4Ja07W68t8/TwMExzr-y0I/AAAAAAAAnEA/e0-iKFu5HmM/s320/dettagli%2Bphp%2Be%2Blista%2Bcredenz%2B2012-01-03_194200.jpg" alt="" id="BLOGGER_PHOTO_ID_5693399607661218626" border="0" /&gt;&lt;/a&gt;Come conseguenza del fatto che &lt;span style="font-weight: bold;"&gt;siamo sempre sullo stesso sito visto in mattinata a supporto di phishing PostePay &lt;/span&gt;non c'e' da sorprendersi se&lt;span style="font-weight: bold;"&gt; l'indirizzo mail codificato nel php  sia lo stesso di questa mattina.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-AWKB0-Ukmo8/TwMExgYZUDI/AAAAAAAAnD4/H9JEAMmD3_8/s1600/php.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 265px;" src="http://1.bp.blogspot.com/-AWKB0-Ukmo8/TwMExgYZUDI/AAAAAAAAnD4/H9JEAMmD3_8/s320/php.jpg" alt="" id="BLOGGER_PHOTO_ID_5693399602478796850" border="0" /&gt;&lt;/a&gt;E' evidente che avendo a disposizione un sito compromesso che permette facilmente di uploadare tramite shell i contenuti di phishing, &lt;span style="font-weight: bold;"&gt;il phisher ne ha approfittato per creare diversi attacchi con obiettivo sia &lt;span style="color: rgb(255, 0, 0);"&gt;PostePay&lt;/span&gt; che &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Altra analogia riscontrabile e' che &lt;span style="font-weight: bold;"&gt;entrambi i phishing vedono oltre all'invio di credenziali sottratte anche la scrittura su file delle stesse.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-7916748200158954377?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/7916748200158954377/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=7916748200158954377' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7916748200158954377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7916748200158954377'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/nuova-mail-di-phishing-cartasi-con.html' title='Nuova mail di phishing CartaSi con interessanti conferme sull&apos;attivita&apos; dei phishers (3 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-adFdcnTFMXo/TwMExG36CtI/AAAAAAAAnDg/m7F8UypohqY/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8018179075954271168</id><published>2012-01-03T17:53:00.004+07:00</published><updated>2012-01-03T18:02:03.806+07:00</updated><title type='text'>Phishing CartaSi (aggiornamento 3 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Insieme a &lt;span style="font-weight: bold;"&gt;PosteIt&lt;/span&gt; si puo' sicuramente affermare che &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt; e' uno degli &lt;span style="font-weight: bold;"&gt;obiettivi preferiti  dai  phisher in questi ultimi mesi.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Ecco quindi  un altro &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;attacco a CartaS&lt;/span&gt;i che segue quello&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2012/01/phishing-cartasi-in-compagnia-di-un.html"&gt; analizzato sul blog il 1 gennaio.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Si tratta di sito compromesso sviluppato ancora una volta &lt;span style="font-weight: bold;"&gt;in WordPress &lt;/span&gt;che presenta incluso un clone di phishing &lt;span style="font-weight: bold;"&gt;CartaSi&lt;/span&gt; costituito dall'immancabile login e dal form di acquisizione dati relativi a carta di credito.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-wyiu4BU427c/TwLecIp90mI/AAAAAAAAnC8/BTr3gMftPAI/s1600/form.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://2.bp.blogspot.com/-wyiu4BU427c/TwLecIp90mI/AAAAAAAAnC8/BTr3gMftPAI/s320/form.jpg" alt="" id="BLOGGER_PHOTO_ID_5693357453890933346" border="0" /&gt;&lt;/a&gt;Come si vede visualizzando &lt;span style="font-weight: bold;"&gt;la tipica struttura dei folders di phishing CartaSi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-pH5JJ26xX7Y/TwLecPluFtI/AAAAAAAAnCw/1dmEZo9ZlTE/s1600/data%2Battuale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 34px;" src="http://3.bp.blogspot.com/-pH5JJ26xX7Y/TwLecPluFtI/AAAAAAAAnCw/1dmEZo9ZlTE/s320/data%2Battuale.jpg" alt="" id="BLOGGER_PHOTO_ID_5693357455752173266" border="0" /&gt;&lt;/a&gt; abbiamo &lt;span style="font-weight: bold;"&gt;date attuali  per  quei codici php che si occupano di trasferire via mail al phisher i dati eventualmente catturati dal fake form&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-MbR22tPWYh0/TwLecbyPvCI/AAAAAAAAnDU/2K4ECQyrtlU/s1600/stru%2B3.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 198px;" src="http://1.bp.blogspot.com/-MbR22tPWYh0/TwLecbyPvCI/AAAAAAAAnDU/2K4ECQyrtlU/s320/stru%2B3.jpg" alt="" id="BLOGGER_PHOTO_ID_5693357459025935394" border="0" /&gt;&lt;/a&gt;Gli indirizzi&lt;span style="font-weight: bold;"&gt; delle &lt;span style="color: rgb(255, 0, 0);"&gt;2 mail&lt;/span&gt;&lt;/span&gt;  di invio al phisher dei dati sottratti,  non sembrano essere gia' stati rilevati altre volte in precedenti analisi di phishing CartaSi ed e' probabile che si tratti di nuovi attacchi.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-xwOZb6BPEMU/TwLeccDYvsI/AAAAAAAAnDE/wYNgPAgeiWc/s1600/php1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 236px;" src="http://2.bp.blogspot.com/-xwOZb6BPEMU/TwLeccDYvsI/AAAAAAAAnDE/wYNgPAgeiWc/s320/php1.jpg" alt="" id="BLOGGER_PHOTO_ID_5693357459097829058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;In ogni caso una dimostrazione di intensa attivita' di phishing che tende sempre piu', come abbiamo visto negli ultimi mesi, ad &lt;span style="font-weight: bold;"&gt;acquisire credenziali di carta di credito &lt;/span&gt;piuttosto che dati di &lt;span style="font-weight: bold;"&gt;login di accesso a conti bancari online.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8018179075954271168?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8018179075954271168/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8018179075954271168' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8018179075954271168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8018179075954271168'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-cartasi-aggiornamento-3.html' title='Phishing CartaSi (aggiornamento 3 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-wyiu4BU427c/TwLecIp90mI/AAAAAAAAnC8/BTr3gMftPAI/s72-c/form.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5052001526283648385</id><published>2012-01-03T13:49:00.002+07:00</published><updated>2012-01-03T13:57:04.031+07:00</updated><title type='text'>Ulteriore phishing PosteIT (3 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Per non smentire il fatto che i servizi internet di&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt; PosteIT&lt;/span&gt; sono tra i piu' colpiti da azioni di phishing, ecco arrivare una ulteriore mail che vediamo in dettaglio&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-BO2f-tzQFtM/TwKlO1dSlVI/AAAAAAAAnCU/96j8EpWymvs/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 232px;" src="http://2.bp.blogspot.com/-BO2f-tzQFtM/TwKlO1dSlVI/AAAAAAAAnCU/96j8EpWymvs/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294553236411730" border="0" /&gt;&lt;/a&gt;Si tratta di messaggio composto&lt;span style="font-weight: bold;"&gt; da unica immagine &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-hAepwdovMWg/TwKlOnKZtTI/AAAAAAAAnCM/IZMtnhDhI28/s1600/img.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 233px;" src="http://4.bp.blogspot.com/-hAepwdovMWg/TwKlOnKZtTI/AAAAAAAAnCM/IZMtnhDhI28/s320/img.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294549399090482" border="0" /&gt;&lt;/a&gt;hostata sul medesimo dominio che&lt;span style="font-weight: bold;"&gt; ospita il redir al phishing&lt;/span&gt; (notare sottodominio su server cinese)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-3LyXdF1ROL4/TwKlOaHGQPI/AAAAAAAAnB0/v2Kenq8fc3c/s1600/det%2Bcina%2Bwh%2Be%2Bcode%2Bred.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 152px;" src="http://4.bp.blogspot.com/-3LyXdF1ROL4/TwKlOaHGQPI/AAAAAAAAnB0/v2Kenq8fc3c/s320/det%2Bcina%2Bwh%2Be%2Bcode%2Bred.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294545895571698" border="0" /&gt;&lt;/a&gt;Sia il dominio di redirect che quello che ospita il clone &lt;span style="font-weight: bold;"&gt;PosteIt  presentano data attuale di registrazione&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-ivtOWMx3RZM/TwKlPC-7WzI/AAAAAAAAnCg/CXGLRw34L-0/s1600/redirccreat%2Bdomani.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://4.bp.blogspot.com/-ivtOWMx3RZM/TwKlPC-7WzI/AAAAAAAAnCg/CXGLRw34L-0/s320/redirccreat%2Bdomani.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294556867156786" border="0" /&gt;&lt;/a&gt;In linea con le&lt;span style="font-weight: bold;"&gt; procedure di phishing utilizzate spesso per attacchi  a poste IT, &lt;/span&gt;e che si differenziano molto dal tradizionale attacco con sito compromesso come visto ad  esempio  nel post precedente&lt;span style="font-weight: bold;"&gt;, in questo caso abbiamo sia di domini creati allo scopo ma anche l'uso di differenti sottodomini ospitati su diversi servers, come vediamo da questo dettaglio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-lSGOd78fdTc/TwKlOsQwNuI/AAAAAAAAnB8/8FrmpcnqOYE/s1600/dns%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 186px;" src="http://3.bp.blogspot.com/-lSGOd78fdTc/TwKlOsQwNuI/AAAAAAAAnB8/8FrmpcnqOYE/s320/dns%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5693294550767908578" border="0" /&gt;&lt;/a&gt;Il sistema cosi utilizzato rende sicuramente &lt;span style="font-weight: bold;"&gt;piu' difficoltoso il blocco dei siti che ospitano i redirects nonche' i cloni di phishing garantendo una maggiore permanenza On-line degli stessi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5052001526283648385?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5052001526283648385/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5052001526283648385' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5052001526283648385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5052001526283648385'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/ulteriore-phishing-posteit-3-gennaio.html' title='Ulteriore phishing PosteIT (3 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-BO2f-tzQFtM/TwKlO1dSlVI/AAAAAAAAnCU/96j8EpWymvs/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6039514260355979204</id><published>2012-01-03T09:36:00.004+07:00</published><updated>2012-01-03T09:48:40.336+07:00</updated><title type='text'>Nuovo anno, vecchio phishing. Phishing PostePay - PosteIT 2012 (3 gennaio)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Cosi' come era &lt;span style="font-weight: bold;"&gt;terminato il 2011&lt;/span&gt; &lt;a style="font-weight: bold; font-style: italic; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/phishing-postepay-28-dicembre.html"&gt;(vedi questo post)&lt;/a&gt; anche &lt;span style="font-weight: bold;"&gt;l'inizio&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; 2012&lt;/span&gt; propone nuovamente un phishing &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;PostePay&lt;/span&gt; sempre attribuibile ai medesimi phishers&lt;br /&gt;&lt;br /&gt;Gia' dal layout mail&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-ALRi29D2FeA/TwJql8fk9PI/AAAAAAAAnAg/39JYrIqPFAw/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 254px;" src="http://4.bp.blogspot.com/-ALRi29D2FeA/TwJql8fk9PI/AAAAAAAAnAg/39JYrIqPFAw/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5693230079076005106" border="0" /&gt;&lt;/a&gt;si nota che si tratta delle medesime azioni di phishing viste numerose a fine anno, che utilizzano   &lt;span style="font-weight: bold;"&gt;form allegato al messaggio mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-uTq_agE6_so/TwJriyVEFzI/AAAAAAAAnBc/qdrt8oSac4g/s1600/form%2Balle.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 224px;" src="http://4.bp.blogspot.com/-uTq_agE6_so/TwJriyVEFzI/AAAAAAAAnBc/qdrt8oSac4g/s320/form%2Balle.jpg" alt="" id="BLOGGER_PHOTO_ID_5693231124319573810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;e&lt;span style="font-weight: bold;"&gt; codice php di gestione credenziali acquisite hostato su sito compromesso&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Questo un dettaglio della homepage&lt;span style="font-weight: bold;"&gt; del sito con whois usa&lt;/span&gt; che si occupa di avvenimenti sportivi&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-UdErYggOxp8/TwJqmMZcTaI/AAAAAAAAnAs/X3J1pKmjyLw/s1600/shoutsu%2Bsito.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 300px; height: 320px;" src="http://1.bp.blogspot.com/-UdErYggOxp8/TwJqmMZcTaI/AAAAAAAAnAs/X3J1pKmjyLw/s320/shoutsu%2Bsito.jpg" alt="" id="BLOGGER_PHOTO_ID_5693230083345239458" border="0" /&gt;&lt;/a&gt;e che mostra  nel folder utilizzato dalla chat&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-YVenpa9SEF8/TwJqmX6Z5MI/AAAAAAAAnBE/FlVPrrPXyo0/s1600/shotbox%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 290px;" src="http://3.bp.blogspot.com/-YVenpa9SEF8/TwJqmX6Z5MI/AAAAAAAAnBE/FlVPrrPXyo0/s320/shotbox%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5693230086436283586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;alcune shells php&lt;/span&gt; usate probabilmente per la gestione del phishing e che parrebbero essere legate a qualche vulnerabilita' sfruttata relativa a detta chat.&lt;br /&gt;&lt;br /&gt;Il file&lt;span style="font-weight: bold;"&gt; php che viene utilizzato  per acquisire i dati personali eventualmente digitati nel form &lt;/span&gt;allegato alla mail fake di PostePay&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-uTq_agE6_so/TwJriyVEFzI/AAAAAAAAnBc/qdrt8oSac4g/s1600/form%2Balle.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 224px;" src="http://4.bp.blogspot.com/-uTq_agE6_so/TwJriyVEFzI/AAAAAAAAnBc/qdrt8oSac4g/s320/form%2Balle.jpg" alt="" id="BLOGGER_PHOTO_ID_5693231124319573810" border="0" /&gt;&lt;/a&gt;mostra sempre&lt;span style="font-weight: bold;"&gt; la medesima mail di invio credenziali sottratte ed anche la scrittura di un file testo con i dati acquisiti.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-yMGscVZBZsE/TwJqmORb_FI/AAAAAAAAnA0/nDOvgsR-AaQ/s1600/php%2B2012-01-03_084033.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 200px;" src="http://4.bp.blogspot.com/-yMGscVZBZsE/TwJqmORb_FI/AAAAAAAAnA0/nDOvgsR-AaQ/s320/php%2B2012-01-03_084033.jpg" alt="" id="BLOGGER_PHOTO_ID_5693230083848535122" border="0" /&gt;&lt;/a&gt;Si tratta di&lt;span style="font-weight: bold;"&gt; date recenti per i records presenti &lt;/span&gt;e con&lt;span style="font-weight: bold;"&gt; Ip Est Europeo per il primo  &lt;/span&gt;(probabile&lt;span style="font-weight: bold;"&gt; test da parte del phisher del corretto funzionamento del codice php&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-IOvOdndkNX4/TwJqmu__1SI/AAAAAAAAnBQ/302WkLP-Eug/s1600/credenz%2Btxt.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 216px;" src="http://2.bp.blogspot.com/-IOvOdndkNX4/TwJqmu__1SI/AAAAAAAAnBQ/302WkLP-Eug/s320/credenz%2Btxt.jpg" alt="" id="BLOGGER_PHOTO_ID_5693230092633756962" border="0" /&gt;&lt;/a&gt;sino a&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-uI08lSPsg9U/TwJri4HrKcI/AAAAAAAAnBk/xfvUfmF1RUc/s1600/ultimo.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://3.bp.blogspot.com/-uI08lSPsg9U/TwJri4HrKcI/AAAAAAAAnBk/xfvUfmF1RUc/s320/ultimo.jpg" alt="" id="BLOGGER_PHOTO_ID_5693231125874026946" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con data recente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6039514260355979204?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6039514260355979204/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6039514260355979204' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6039514260355979204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6039514260355979204'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/nuovo-anno-vecchio-phishing-phishing.html' title='Nuovo anno, vecchio phishing. Phishing PostePay - PosteIT 2012 (3 gennaio)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ALRi29D2FeA/TwJql8fk9PI/AAAAAAAAnAg/39JYrIqPFAw/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-320012821551931817</id><published>2012-01-01T20:01:00.005+07:00</published><updated>2012-01-01T20:15:42.524+07:00</updated><title type='text'>Phishing CartaSi in compagnia di un interessante KIT di phishing multiplo ai danni di banche inglesi (1 gennaio )</title><content type='html'>&lt;div style="text-align: justify;"&gt;Si tratta di questa segnalazione in rete di mail di&lt;span style="font-weight: bold;"&gt; phishing &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi &lt;/span&gt;con allegato form&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-DaR9N5ZEiqs/TwBZwQfyEiI/AAAAAAAAm_Q/fS-U6YxFUQ0/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 176px;" src="http://2.bp.blogspot.com/-DaR9N5ZEiqs/TwBZwQfyEiI/AAAAAAAAm_Q/fS-U6YxFUQ0/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5692648614593172002" border="0" /&gt;&lt;/a&gt;In realta' su &lt;span style="font-weight: bold;"&gt;Phishtank appare la stessa URL con link al codice PHP&lt;/span&gt; di gestione dei dati inseriti nel form fake gia' in&lt;span style="font-weight: bold;"&gt; data 15 dicembre.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Si tratta quindi di un phishing attivo da tempo e che &lt;span style="font-weight: bold;"&gt;utilizza un sito koreano &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-60k81Z8xdTA/TwBaKf-inwI/AAAAAAAAm_Y/iQSAs7vs_24/s1600/wh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 133px;" src="http://2.bp.blogspot.com/-60k81Z8xdTA/TwBaKf-inwI/AAAAAAAAm_Y/iQSAs7vs_24/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5692649065425313538" border="0" /&gt;&lt;/a&gt;per ospitare il php, &lt;span style="font-weight: bold;"&gt;che gestisce appunto l'invio via mail dei dati eventualmente acquisiti.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-vK4RSR-LuAo/TwBZwTsajgI/AAAAAAAAm_A/Ncd0yqbuHQU/s1600/form%2Baction.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 68px;" src="http://2.bp.blogspot.com/-vK4RSR-LuAo/TwBZwTsajgI/AAAAAAAAm_A/Ncd0yqbuHQU/s320/form%2Baction.jpg" alt="" id="BLOGGER_PHOTO_ID_5692648615451463170" border="0" /&gt;&lt;/a&gt;Un ricerca sul sito compromesso&lt;span style="font-weight: bold;"&gt; mostra  una semplice shell&lt;/span&gt; che permette di visualizzare anche&lt;span style="font-weight: bold;"&gt; il contenuto del file php collegato al form di phishing&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-tbEoQVMZLJA/TwBaftmT-II/AAAAAAAAm_k/F0ZL_PTfOrs/s1600/shell.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 301px; height: 320px;" src="http://4.bp.blogspot.com/-tbEoQVMZLJA/TwBaftmT-II/AAAAAAAAm_k/F0ZL_PTfOrs/s320/shell.jpg" alt="" id="BLOGGER_PHOTO_ID_5692649429859039362" border="0" /&gt;&lt;/a&gt;Piu' interessante e'&lt;span style="font-weight: bold;"&gt; la presenza di un kit di phishing (formato ZIP)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-hw0BzKPt_QE/TwBaf0Z_-_I/AAAAAAAAm_s/vk13FyH7WGA/s1600/kit%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 268px;" src="http://1.bp.blogspot.com/-hw0BzKPt_QE/TwBaf0Z_-_I/AAAAAAAAm_s/vk13FyH7WGA/s320/kit%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5692649431686446066" border="0" /&gt;&lt;/a&gt; abbastanza particolare&lt;span style="font-weight: bold;"&gt; in quanto e' costituito in realta ' da  una lunga serie di pagine che simulano diverse banche inglesi ed anche una pagina dedicata a generiche carte di credito.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-cjzYUOQuVSI/TwBbCmZIHRI/AAAAAAAAnAU/a3yzQsunQaA/s1600/all%2Bpage.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 301px;" src="http://1.bp.blogspot.com/-cjzYUOQuVSI/TwBbCmZIHRI/AAAAAAAAnAU/a3yzQsunQaA/s320/all%2Bpage.jpg" alt="" id="BLOGGER_PHOTO_ID_5692650029220109586" border="0" /&gt;&lt;/a&gt;Si tratta di attacco phishing &lt;span style="font-weight: bold;"&gt;gia' osservato altre volte in rete &lt;/span&gt;(&lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://edetools.blogspot.com/2011/05/phishing-multiplo-ai-danni-di-banche.html"&gt;dettagli in questo post&lt;/a&gt;)  che, attraverso un clone del servizio inglese di pagamento&lt;span style="font-weight: bold;"&gt; imposte HMRC&lt;/span&gt; propone &lt;span style="font-weight: bold;"&gt;una serie di cloni relativi a numerosi istituti bancari UK (ma c'e' anche una banca spagnola)  e form per acquisire dati relativi a diverse carte di credito.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ecco un dettaglio del &lt;span style="font-weight: bold;"&gt;KIT in formato zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Pgtnfi_3-Yc/TwBagCae-lI/AAAAAAAAm_8/rIrCQdbp5AU/s1600/kits%2B1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 184px;" src="http://1.bp.blogspot.com/-Pgtnfi_3-Yc/TwBagCae-lI/AAAAAAAAm_8/rIrCQdbp5AU/s320/kits%2B1.jpg" alt="" id="BLOGGER_PHOTO_ID_5692649435446573650" border="0" /&gt;&lt;/a&gt;ed un particolare del&lt;span style="font-weight: bold;"&gt; codice relativo ad una delle banche prese di mira.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-2nTrse4tJ-Q/TwBagdBGrbI/AAAAAAAAnAI/OlX1jlGaWEE/s1600/kit%2Babbey.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 121px;" src="http://2.bp.blogspot.com/-2nTrse4tJ-Q/TwBagdBGrbI/AAAAAAAAnAI/OlX1jlGaWEE/s320/kit%2Babbey.jpg" alt="" id="BLOGGER_PHOTO_ID_5692649442587880882" border="0" /&gt;&lt;/a&gt;Le&lt;span style="font-weight: bold;"&gt; date dei codici php  dimostrano che molto probabilmente il kit e' stato attivato a fine 2011.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-320012821551931817?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/320012821551931817/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=320012821551931817' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/320012821551931817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/320012821551931817'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-cartasi-in-compagnia-di-un.html' title='Phishing CartaSi in compagnia di un interessante KIT di phishing multiplo ai danni di banche inglesi (1 gennaio )'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-DaR9N5ZEiqs/TwBZwQfyEiI/AAAAAAAAm_Q/fS-U6YxFUQ0/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-8414466712199871089</id><published>2012-01-01T14:27:00.003+07:00</published><updated>2012-01-01T14:34:29.444+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione prevalentemente regionale. Aggiornamento phishing Banca Reale (1 gennaio )</title><content type='html'>&lt;div style="text-align: justify;"&gt;Poche righe per aggiornare&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/phishing-ai-danni-di-banche-it_31.html"&gt; il post di ieri sul phishing Banca Reale&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In linea con i&lt;span style="font-weight: bold;"&gt; 'consueti' metodi applicati dai phishers &lt;/span&gt;il link gestito dal redirect e' cambiato e punta ora a differente folder, rimanendo &lt;span style="font-weight: bold;"&gt;sempre sul medesimo sito che ospita l'Asset Manager Innova Studio gia' visto ieri.&lt;/span&gt;&lt;br /&gt;Si tratta di una consueta procedura atta ad evitare eventuali&lt;span style="font-weight: bold;"&gt; blacklist dell'indirizzo del clone di phishing.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questa l'attuale struttura  dove vediamo&lt;span style="font-weight: bold;"&gt; il nuovo nome della pagina home (login) del clone &lt;span style="color: rgb(255, 0, 0);"&gt;Banca Reale&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-8wf4L5WAfbI/TwAL2whl-KI/AAAAAAAAm-g/zQdXgEa25NI/s1600/stru%2Bph%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 116px;" src="http://3.bp.blogspot.com/-8wf4L5WAfbI/TwAL2whl-KI/AAAAAAAAm-g/zQdXgEa25NI/s320/stru%2Bph%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5692562964362950818" border="0" /&gt;&lt;/a&gt;mentre per quanto si riferisce ai codici php di invio credenziali sottratte, risultano sempre i medesimi indirizzi mail utilizzati ieri. (notare sempre&lt;span style="font-weight: bold;"&gt; la doppia estensione&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-5j972WaMm2w/TwAL2sV-zQI/AAAAAAAAm-Y/11kdJqy_iZs/s1600/ob1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 236px;" src="http://3.bp.blogspot.com/-5j972WaMm2w/TwAL2sV-zQI/AAAAAAAAm-Y/11kdJqy_iZs/s320/ob1.jpg" alt="" id="BLOGGER_PHOTO_ID_5692562963240504578" border="0" /&gt;&lt;/a&gt;L'estensione presente come &lt;span style="font-weight: bold;"&gt;php.&lt;span style="color: rgb(255, 0, 0);"&gt;pgif&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;serve ad evitare il blocco dell'upload con Asset Manager che riconosce l'estensione&lt;span style="font-weight: bold;"&gt; php come  'pericolosa', ma non files con doppia estensione php.&lt;span style="color: rgb(255, 0, 0);"&gt;pgif&lt;/span&gt; che vengono caricati senza problemi&lt;/span&gt;&lt;br /&gt;Chiaramente i files cosi ' ridenominati ', una volta fatto l'upload possono venire eseguiti quanto un normale file php permettendo sia l'uso di shells remote che di codici php a supporto dei forms di phishing.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-8414466712199871089?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/8414466712199871089/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=8414466712199871089' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8414466712199871089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/8414466712199871089'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2012/01/phishing-ai-danni-di-banche-it.html' title='Phishing ai danni di banche IT a diffusione prevalentemente regionale. Aggiornamento phishing Banca Reale (1 gennaio )'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-8wf4L5WAfbI/TwAL2whl-KI/AAAAAAAAm-g/zQdXgEa25NI/s72-c/stru%2Bph%2Bfolder.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5628636433120432046</id><published>2011-12-31T09:16:00.006+07:00</published><updated>2011-12-31T09:35:22.133+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione prevalentemente regionale (31 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Anche per fine anno troviamo&lt;span style="font-weight: bold;"&gt; on-line un clone di phishing ai danni di banca IT &lt;/span&gt;e sempre, molto probabilmente, gestito dagli stessi personaggi che da tempo attaccano banche IT a diffusione prevalentemente regionale.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Si tratta di phisihng &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;Banca Reale&lt;/span&gt; di cui vediamo lo screenshot del clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-yOoOOAIVJTI/Tv5xUE_eoYI/AAAAAAAAm90/F_Ho4Y1279w/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 234px;" src="http://3.bp.blogspot.com/-yOoOOAIVJTI/Tv5xUE_eoYI/AAAAAAAAm90/F_Ho4Y1279w/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111568794198402" border="0" /&gt;&lt;/a&gt;Questo il testo della mail&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-CWB1JYNGbdg/Tv50OjPkYgI/AAAAAAAAm-M/7bvslyS7wus/s1600/testo%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 140px;" src="http://3.bp.blogspot.com/-CWB1JYNGbdg/Tv50OjPkYgI/AAAAAAAAm-M/7bvslyS7wus/s320/testo%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5692114772370416130" border="0" /&gt;&lt;/a&gt;con link che punta al consueto redirect gestito dall'immancabile (nel caso di questi attacchi di phishing a banche IT)&lt;span style="font-weight: bold;"&gt; Innova Studio Asset Manager&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-wu7oFCTPR3g/Tv5wy9e2ToI/AAAAAAAAm84/9xoPwtAVhzY/s1600/asset%2Bredir%2Bvn.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 177px;" src="http://2.bp.blogspot.com/-wu7oFCTPR3g/Tv5wy9e2ToI/AAAAAAAAm84/9xoPwtAVhzY/s320/asset%2Bredir%2Bvn.jpg" alt="" id="BLOGGER_PHOTO_ID_5692110999842606722" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;su sito vietnamita&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-8sXZscqPpJ8/Tv5wzIIBrMI/AAAAAAAAm9A/b77dRHnDnK8/s1600/vh%2Bred.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://2.bp.blogspot.com/-8sXZscqPpJ8/Tv5wzIIBrMI/AAAAAAAAm9A/b77dRHnDnK8/s320/vh%2Bred.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111002699672770" border="0" /&gt;&lt;/a&gt;Il redirect punta a &lt;span style="font-weight: bold;"&gt;clone Banca Reale&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-yOoOOAIVJTI/Tv5xUE_eoYI/AAAAAAAAm90/F_Ho4Y1279w/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 234px;" src="http://3.bp.blogspot.com/-yOoOOAIVJTI/Tv5xUE_eoYI/AAAAAAAAm90/F_Ho4Y1279w/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111568794198402" border="0" /&gt;&lt;/a&gt;su sito&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Z7sAssT3wOs/Tv5wzWmRPaI/AAAAAAAAm9c/GEBwysvga0E/s1600/wh%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 149px;" src="http://3.bp.blogspot.com/-Z7sAssT3wOs/Tv5wzWmRPaI/AAAAAAAAm9c/GEBwysvga0E/s320/wh%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111006584618402" border="0" /&gt;&lt;/a&gt;Anche in questo caso&lt;span style="font-weight: bold;"&gt;  Innova Studio Asset Manager &lt;/span&gt;che ha permesso l'upload sia dei codici del clone che alcune shells&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-OchacmZFj0Y/Tv5wzJz8nDI/AAAAAAAAm9M/e_9R0SowhwQ/s1600/clone%2Bphhp%2Bin%2Basset.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://1.bp.blogspot.com/-OchacmZFj0Y/Tv5wzJz8nDI/AAAAAAAAm9M/e_9R0SowhwQ/s320/clone%2Bphhp%2Bin%2Basset.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111003152325682" border="0" /&gt;&lt;/a&gt;Da notare come anche i codici php legati al form di phishing siano stati offuscati nel nome ridenominandoli in maniera leggermente diversa dal solito &lt;span style="color: rgb(153, 0, 0); font-style: italic;"&gt;xxxx.php.pgif&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ecco la struttura del folder&lt;span style="font-weight: bold;"&gt; che ospita il clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Hetxs-BlRcw/Tv5wz7hc34I/AAAAAAAAm9o/l6HOIIGvWNI/s1600/struct.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://4.bp.blogspot.com/-Hetxs-BlRcw/Tv5wz7hc34I/AAAAAAAAm9o/l6HOIIGvWNI/s320/struct.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111016496521090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;i cui codici php presentano indirizzo &lt;span style="font-weight: bold;"&gt;mail di invio credenziali eventualmente sottratte, leggermente variato rispetto al noto indirizzo mail di R-team&lt;/span&gt; (vedi precedenti posts)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-7qjNC6inHc8/Tv5xUaag8BI/AAAAAAAAm98/QZiWq4QJTZk/s1600/phppin.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 208px;" src="http://2.bp.blogspot.com/-7qjNC6inHc8/Tv5xUaag8BI/AAAAAAAAm98/QZiWq4QJTZk/s320/phppin.jpg" alt="" id="BLOGGER_PHOTO_ID_5692111574544740370" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5628636433120432046?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5628636433120432046/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5628636433120432046' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5628636433120432046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5628636433120432046'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-ai-danni-di-banche-it_31.html' title='Phishing ai danni di banche IT a diffusione prevalentemente regionale (31 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-yOoOOAIVJTI/Tv5xUE_eoYI/AAAAAAAAm90/F_Ho4Y1279w/s72-c/clone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5834179667439195036</id><published>2011-12-30T12:05:00.006+07:00</published><updated>2011-12-30T13:12:53.687+07:00</updated><title type='text'>La capitale degli hacker? E' in Romania. Notizia ANSA (30 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.ansa.it/web/notizie/rubriche/mondo/2011/12/29/visualizza_new.html_19268508.html"&gt;Ansa.it &lt;/a&gt;pubblica un articolo che fa' riferimento a quello comparso sul noto quotidiano francese   &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.lemonde.fr/europe/article/2011/12/28/les-pirates-roumains-d-hackerville-tiennent-tete-aux-polices-du-monde-entier_1623331_3214.html"&gt;Le Monde&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; il 29/12&lt;/span&gt;. &lt;span style="font-weight: bold;"&gt; “Les pirates roumains d'"Hackerville" tiennent tete aux polices du monde entier "   &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A parte alcune note '&lt;span style="font-style: italic;"&gt;folcloristiche&lt;/span&gt;' su&lt;span style="font-weight: bold;"&gt; "Hackerville"&lt;/span&gt; l'articolo evidenzia una realta' ben nota.&lt;br /&gt;&lt;br /&gt;Che&lt;span style="font-weight: bold;"&gt; il phishing &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;sia, in moltissimi casi, di provenienza est europea ed in particolare romena &lt;/span&gt;e' indubbiamente vero, se &lt;span style="font-weight: bold;"&gt;guardiamo i numerosi casi, anche rilevati su questo blog, di indirizzi internet e siti clone con IP romeni coinvolti in azioni ai danni di banche IT.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Qui il&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.ansa.it/web/notizie/rubriche/mondo/2011/12/29/visualizza_new.html_19268508.html"&gt; link alla notizia Ansa&lt;/a&gt; mentre qui&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.lemonde.fr/europe/article/2011/12/28/les-pirates-roumains-d-hackerville-tiennent-tete-aux-polices-du-monde-entier_1623331_3214.html"&gt; il link all'articolo sul sito di Le Monde.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5834179667439195036?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5834179667439195036/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5834179667439195036' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5834179667439195036'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5834179667439195036'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/la-capitale-degli-hacker-e-in-romania.html' title='La capitale degli hacker? E&apos; in Romania. Notizia ANSA (30 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6987917509646247133</id><published>2011-12-30T11:09:00.005+07:00</published><updated>2011-12-30T11:30:15.106+07:00</updated><title type='text'>Linkedin e fake mails con link a pharmacy. Interessante uso di Wayback Machine (30 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ricevo una segnalazione da&lt;span style="font-weight: bold;"&gt; parte di un lettore del blog&lt;/span&gt; (attraverso il &lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="https://spreadsheets.google.com/viewform?formkey=dDF4WGYzeXdFNUc0Q29KbEZ2OEFibFE6MQ"&gt;db segnalazioni&lt;/a&gt;) di numerose mails di spam ricevute, che simulano una mail di  notifica messaggio personale,  da parte di&lt;span style="font-weight: bold;"&gt; Linkedin&lt;/span&gt; (&lt;span style="font-style: italic; color: rgb(0, 51, 51);"&gt;LinkedIn e' un servizio di social networking in rete impiegato principalmente per la rete professionale.(da Wikipedia) &lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-cJox3oKxeM8/Tv06ohPk24I/AAAAAAAAm7A/E0mUdr0j8Wk/s1600/dbsegn.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 102px;" src="http://2.bp.blogspot.com/-cJox3oKxeM8/Tv06ohPk24I/AAAAAAAAm7A/E0mUdr0j8Wk/s320/dbsegn.jpg" alt="" id="BLOGGER_PHOTO_ID_5691769971859053442" border="0" /&gt;&lt;/a&gt;Anche da parte del sottoscritto sono state&lt;span style="font-weight: bold;"&gt; ricevute alcune mails di cui vediamo un dettaglio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-4eUkmTuzV18/Tv06oieTaFI/AAAAAAAAm7I/AdpIsLt7SnU/s1600/mail%2B2011-12-30_090703.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 182px;" src="http://1.bp.blogspot.com/-4eUkmTuzV18/Tv06oieTaFI/AAAAAAAAm7I/AdpIsLt7SnU/s320/mail%2B2011-12-30_090703.jpg" alt="" id="BLOGGER_PHOTO_ID_5691769972189259858" border="0" /&gt;&lt;/a&gt;e che presentano &lt;span style="font-weight: bold;"&gt;layout che vuole simulare una reale comunicazione Linkedin.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo un dettaglio dell'IP dell'header in mail&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-VY2se_xPCRY/Tv08O-JncCI/AAAAAAAAm78/lXeCXU_AGUc/s1600/headers.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 54px;" src="http://2.bp.blogspot.com/-VY2se_xPCRY/Tv08O-JncCI/AAAAAAAAm78/lXeCXU_AGUc/s320/headers.jpg" alt="" id="BLOGGER_PHOTO_ID_5691771731965341730" border="0" /&gt;&lt;/a&gt;I link puntano a redirects &lt;span style="font-weight: bold;"&gt;ospitati su siti compromessi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-IHMWeCXLkRg/Tv06o-VMEdI/AAAAAAAAm7k/qIvzRQrrdNo/s1600/redir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 66px;" src="http://3.bp.blogspot.com/-IHMWeCXLkRg/Tv06o-VMEdI/AAAAAAAAm7k/qIvzRQrrdNo/s320/redir.jpg" alt="" id="BLOGGER_PHOTO_ID_5691769979667222994" border="0" /&gt;&lt;/a&gt;che a loro volta&lt;span style="font-weight: bold;"&gt; redirigono a sito attualmente Off-line ma che parrebbe essere comunque legato a prodotti di pharmacy&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-d0LeBPEpKSc/Tv06pXhWHSI/AAAAAAAAm7w/tOx1-LQP2BA/s1600/pharma%2Bcanadian%2Bsite.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 100px;" src="http://3.bp.blogspot.com/-d0LeBPEpKSc/Tv06pXhWHSI/AAAAAAAAm7w/tOx1-LQP2BA/s320/pharma%2Bcanadian%2Bsite.jpg" alt="" id="BLOGGER_PHOTO_ID_5691769986429099298" border="0" /&gt;&lt;/a&gt;Da notare come&lt;span style="font-weight: bold;"&gt; i siti che hostano il redirect siano numerosi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Tra questi ne troviamo uno che merita una analisi piu' approfondita:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Attualmente la homepage&lt;span style="font-weight: bold;"&gt; risulta assente&lt;/span&gt;, ma ad una analisi piu' accurata si scopre che e' comunque&lt;span style="font-weight: bold;"&gt; attivo un programma di statistiche che mostrano come il sito sia stato ampiamente utilizzato per hostare link a pharmacy od altri siti di dubbi affidabilita' anche ad inizio anno&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-ThW6_y5Hxto/Tv08Pkw4NQI/AAAAAAAAm8g/xMWVxn9JejQ/s1600/webstatallyear.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 146px;" src="http://2.bp.blogspot.com/-ThW6_y5Hxto/Tv08Pkw4NQI/AAAAAAAAm8g/xMWVxn9JejQ/s320/webstatallyear.jpg" alt="" id="BLOGGER_PHOTO_ID_5691771742330565890" border="0" /&gt;&lt;/a&gt;Il log degli accessi dimostra, dopo un periodo di non utilizzo di qualche mese, una ripresa del traffico a fine 2011, dovuta quas&lt;span style="font-weight: bold;"&gt;i certamente anche al redirect a pharmacy tramite link in mail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Visto che cercando in Google si trovano solo info al riguardo delle pagine incluse di pharmacy ed anche di noto allerta Google sulla possibile pericolosita' del sito &lt;span style="font-weight: bold;"&gt;“This site may harm your computer"&lt;/span&gt;  vediamo l'uso di un interessante servizio on-line di  “........ ritorno al passato ….....”  riguardo alla storia internet di vecchi siti tra i quali molti ormai non piu' presenti in rete.&lt;br /&gt;&lt;br /&gt;Si tratta della &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.archive.org/web/web.php"&gt;Wayback Machine&lt;/a&gt;   che mette a disposizione&lt;span style="font-weight: bold;"&gt; un enorme archivio pagine web e siti (oltre &lt;span style="color: rgb(255, 0, 0);"&gt;150 miliardi di pagine web &lt;/span&gt;archiviate dal 1996 a pochi mesi fa ) che erano online negli anni scorsi e molti dei quali ormai 'scomparsi'.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Troviamo cosi che il sito &lt;span style="font-weight: bold;"&gt;attualmente senza homepage&lt;/span&gt;,&lt;span style="color: rgb(255, 102, 102); font-weight: bold;"&gt; nel 2004 (marzo)&lt;/span&gt; veniva visitato per al prima volta da &lt;span style="font-weight: bold;"&gt;Wayback Machine&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-69oiLvVp_OM/Tv06o2RB94I/AAAAAAAAm7Q/atUox-kaPhw/s1600/2004%2Ball.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 248px;" src="http://4.bp.blogspot.com/-69oiLvVp_OM/Tv06o2RB94I/AAAAAAAAm7Q/atUox-kaPhw/s320/2004%2Ball.jpg" alt="" id="BLOGGER_PHOTO_ID_5691769977502300034" border="0" /&gt;&lt;/a&gt; e presentava&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-2ACIIxc-faY/Tv08O8gaqbI/AAAAAAAAm8E/EpBKm4N5Ars/s1600/2004.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 221px;" src="http://1.bp.blogspot.com/-2ACIIxc-faY/Tv08O8gaqbI/AAAAAAAAm8E/EpBKm4N5Ars/s320/2004.jpg" alt="" id="BLOGGER_PHOTO_ID_5691771731524102578" border="0" /&gt;&lt;/a&gt;e sempre &lt;span style="font-weight: bold;"&gt;a fine 2004&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-IlGLtBgugAE/Tv08PLTdizI/AAAAAAAAm8Y/zlv98OvTs-I/s1600/nov%2B2004.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 204px;" src="http://1.bp.blogspot.com/-IlGLtBgugAE/Tv08PLTdizI/AAAAAAAAm8Y/zlv98OvTs-I/s320/nov%2B2004.jpg" alt="" id="BLOGGER_PHOTO_ID_5691771735496297266" border="0" /&gt;&lt;/a&gt;mente&lt;span style="font-weight: bold;"&gt; l'ultima homepage legittima pare risalire a fine 2009&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Da quel momento &lt;span style="font-weight: bold;"&gt;le successive visite al sito da parte di 'Wayback Machine'  mostrano la homepage inesistente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Si tratta in pratica di una azienda che probabilmente a cessato l'attivita' o comunque di gestire il dominio lasciandolo pero on-line ed attivo, cosa che ne ha permesso l'utilizzo per hosting di codici di redirect , pagine di pharmacy ecc...&lt;br /&gt;&lt;br /&gt;E' una pratica molto diffusa in rete che vede siti, forum.... ecc... che dal momento che sono 'abbandonati” dai creatori o da chi dovrebbe gestirli diventano facile host di malware di vario tipo...permettendo a phishers, spammer, ecc di avere un servizio di hosting free e senza problemi di 'bonifica' dei contenuti.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6987917509646247133?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6987917509646247133/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6987917509646247133' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6987917509646247133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6987917509646247133'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/linkedin-e-fake-mails-con-link-pharmacy.html' title='Linkedin e fake mails con link a pharmacy. Interessante uso di Wayback Machine (30 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-cJox3oKxeM8/Tv06ohPk24I/AAAAAAAAm7A/E0mUdr0j8Wk/s72-c/dbsegn.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2821850729929751450</id><published>2011-12-28T11:03:00.003+07:00</published><updated>2011-12-28T11:13:53.538+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione prevalentemente regionale. Banca Farnese (28 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Dopo la pausa natalizia pare riprendere &lt;span style="font-weight: bold;"&gt;attivamente il phishing ai danni di banche IT a diffusione prevalentemente regionale.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questo il&lt;span style="font-weight: bold;"&gt; clone &lt;span style="color: rgb(255, 0, 0);"&gt;Banca Farnese&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-VEY2BpBrHxk/TvqVX_W0ujI/AAAAAAAAm5g/_QOZjzUGS5A/s1600/clone%2Blogin.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 285px;" src="http://4.bp.blogspot.com/-VEY2BpBrHxk/TvqVX_W0ujI/AAAAAAAAm5g/_QOZjzUGS5A/s320/clone%2Blogin.jpg" alt="" id="BLOGGER_PHOTO_ID_5691025318512736818" border="0" /&gt;&lt;/a&gt;da cui&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-bVix0amyPsg/TvqVYGUzhQI/AAAAAAAAm5o/juJmQjC6lJ0/s1600/pin.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 189px;" src="http://4.bp.blogspot.com/-bVix0amyPsg/TvqVYGUzhQI/AAAAAAAAm5o/juJmQjC6lJ0/s320/pin.jpg" alt="" id="BLOGGER_PHOTO_ID_5691025320383317250" border="0" /&gt;&lt;/a&gt;banca che non risulta colpita in precedenti azioni di phishing rilevabili dal DB del blog&lt;br /&gt;&lt;br /&gt;Si tratta sempre di &lt;span style="font-weight: bold;"&gt;redirect a clone tramite noto Assetmanager Innova Studio&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-I0ritfT8dG4/TvqVYkxLYzI/AAAAAAAAm6E/cUpxqLw0lDM/s1600/asset%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://2.bp.blogspot.com/-I0ritfT8dG4/TvqVYkxLYzI/AAAAAAAAm6E/cUpxqLw0lDM/s320/asset%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5691025328555385650" border="0" /&gt;&lt;/a&gt;su sito greco&lt;span style="font-weight: bold;"&gt; compromesso,&lt;/span&gt; o &lt;span style="font-weight: bold;"&gt;meglio, che mette online interfaccia di gestione contenuti liberamente accessibile da remoto.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-kelHz6tpr8g/TvqVYOcO0nI/AAAAAAAAm54/D5o6glAJCsE/s1600/wh%2Bredir%2B2011-12-28_102239.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 157px;" src="http://3.bp.blogspot.com/-kelHz6tpr8g/TvqVYOcO0nI/AAAAAAAAm54/D5o6glAJCsE/s320/wh%2Bredir%2B2011-12-28_102239.jpg" alt="" id="BLOGGER_PHOTO_ID_5691025322561950322" border="0" /&gt;&lt;/a&gt;Il clone e' invece &lt;span style="font-weight: bold;"&gt;ospitato su sito azero&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-5M_ZFxkRW84/TvqWr88LDgI/AAAAAAAAm6s/jnf8CKrCq0o/s1600/azero%2Bclone%2Bwh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://3.bp.blogspot.com/-5M_ZFxkRW84/TvqWr88LDgI/AAAAAAAAm6s/jnf8CKrCq0o/s320/azero%2Bclone%2Bwh.jpg" alt="" id="BLOGGER_PHOTO_ID_5691026760973094402" border="0" /&gt;&lt;/a&gt;con asset manager che ha permesso di uploadare&lt;span style="font-weight: bold;"&gt; tutto quello che serve per il phishing&lt;/span&gt; attuale&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-f1CYG6jgMfE/TvqWrvXyg-I/AAAAAAAAm6Q/wpb-YaZrTzY/s1600/asset%2Bclone%2B1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 145px;" src="http://1.bp.blogspot.com/-f1CYG6jgMfE/TvqWrvXyg-I/AAAAAAAAm6Q/wpb-YaZrTzY/s320/asset%2Bclone%2B1.jpg" alt="" id="BLOGGER_PHOTO_ID_5691026757330830306" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-4_F9kwlMJVs/TvqWr7xF1NI/AAAAAAAAm6Y/CcESRYTGn0A/s1600/asset%2Bclone%2B2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 243px;" src="http://1.bp.blogspot.com/-4_F9kwlMJVs/TvqWr7xF1NI/AAAAAAAAm6Y/CcESRYTGn0A/s320/asset%2Bclone%2B2.jpg" alt="" id="BLOGGER_PHOTO_ID_5691026760658179282" border="0" /&gt;&lt;/a&gt;I codici php mostrano &lt;span style="font-weight: bold;"&gt;la solita mail  di invio credenziali al phisher attribuibile sempre ad R-team&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-cgzGCE6zTmU/TvqWssFjVHI/AAAAAAAAm60/TjbKAsSUeUA/s1600/run%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 188px;" src="http://2.bp.blogspot.com/-cgzGCE6zTmU/TvqWssFjVHI/AAAAAAAAm60/TjbKAsSUeUA/s320/run%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5691026773628900466" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2821850729929751450?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2821850729929751450/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2821850729929751450' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2821850729929751450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2821850729929751450'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-ai-danni-di-banche-it_28.html' title='Phishing ai danni di banche IT a diffusione prevalentemente regionale. Banca Farnese (28 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-VEY2BpBrHxk/TvqVX_W0ujI/AAAAAAAAm5g/_QOZjzUGS5A/s72-c/clone%2Blogin.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-923938564175132852</id><published>2011-12-28T09:40:00.004+07:00</published><updated>2011-12-28T09:49:32.444+07:00</updated><title type='text'>Phishing PostePay (28 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Numerose&lt;span style="font-weight: bold;"&gt; mails di phishing ai danni di &lt;span style="color: rgb(255, 0, 0);"&gt;PostePay&lt;/span&gt;&lt;/span&gt; ricevute negli ultimi giorni&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-wcICbANxx4o/TvqCOButBmI/AAAAAAAAm4Y/Q14va8BAuRg/s1600/mails%2Blist.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 58px;" src="http://2.bp.blogspot.com/-wcICbANxx4o/TvqCOButBmI/AAAAAAAAm4Y/Q14va8BAuRg/s320/mails%2Blist.jpg" alt="" id="BLOGGER_PHOTO_ID_5691004256630146658" border="0" /&gt;&lt;/a&gt;con layout sempre uguale&lt;span style="font-weight: bold;"&gt; (bonus natalizio)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-CJ66kk3oQyg/TvqB4YjbQ9I/AAAAAAAAm30/G2-yf36V6k8/s1600/mail%2Bsera.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 295px;" src="http://1.bp.blogspot.com/-CJ66kk3oQyg/TvqB4YjbQ9I/AAAAAAAAm30/G2-yf36V6k8/s320/mail%2Bsera.jpg" alt="" id="BLOGGER_PHOTO_ID_5691003884799738834" border="0" /&gt;&lt;/a&gt;ma con quelle ricevute in data meno recente che hanno il&lt;span style="font-weight: bold; font-style: italic;"&gt; 'logo natalizio' &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;non piu' visualizzabile&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-CON8H_POAag/TvqB4uOXGnI/AAAAAAAAm38/lpjz1lKMODE/s1600/ieri%2Berrorr%2Bpict.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 222px;" src="http://2.bp.blogspot.com/-CON8H_POAag/TvqB4uOXGnI/AAAAAAAAm38/lpjz1lKMODE/s320/ieri%2Berrorr%2Bpict.jpg" alt="" id="BLOGGER_PHOTO_ID_5691003890616965746" border="0" /&gt;&lt;/a&gt;come da source&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-YjAhMF30WJs/TvqB4g6XAXI/AAAAAAAAm4I/Mboz4s9emgo/s1600/ieri%2Berror%2Bimg.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 109px;" src="http://2.bp.blogspot.com/-YjAhMF30WJs/TvqB4g6XAXI/AAAAAAAAm4I/Mboz4s9emgo/s320/ieri%2Berror%2Bimg.jpg" alt="" id="BLOGGER_PHOTO_ID_5691003887043412338" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Le piu' recenti (data di ieri) hanno invece  il source che e' stato  modificato,&lt;/span&gt; per ovviare all'inconveniente,  e &lt;span style="font-weight: bold;"&gt;linkano l'immagine gif direttamente dal sito PostePay&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-KD-VlUg21ZE/TvqClgKMq3I/AAAAAAAAm4k/8-Gpktj_c8o/s1600/oggi%2Bimg%2Bf%2Bposte.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 107px;" src="http://3.bp.blogspot.com/-KD-VlUg21ZE/TvqClgKMq3I/AAAAAAAAm4k/8-Gpktj_c8o/s320/oggi%2Bimg%2Bf%2Bposte.jpg" alt="" id="BLOGGER_PHOTO_ID_5691004659935521650" border="0" /&gt;&lt;/a&gt;Il form presente come allegato in tutte le mail ricevute, presenta layout noto&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-bbeOLxG4IM8/TvqClg0ckNI/AAAAAAAAm40/5fUWFRWkGhw/s1600/form%2Ballegato.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 205px;" src="http://3.bp.blogspot.com/-bbeOLxG4IM8/TvqClg0ckNI/AAAAAAAAm40/5fUWFRWkGhw/s320/form%2Ballegato.jpg" alt="" id="BLOGGER_PHOTO_ID_5691004660112724178" border="0" /&gt;&lt;/a&gt;e link a codice &lt;span style="font-weight: bold;"&gt;php hostato su&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-kHYXZZWU084/TvqCmSf5wSI/AAAAAAAAm48/tQBoQMi18c4/s1600/php%2Baction.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 66px;" src="http://3.bp.blogspot.com/-kHYXZZWU084/TvqCmSf5wSI/AAAAAAAAm48/tQBoQMi18c4/s320/php%2Baction.jpg" alt="" id="BLOGGER_PHOTO_ID_5691004673448329506" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Si tratta di sito USA compromesso quasi sicuramente &lt;span style="font-weight: bold;"&gt;attraverso vulnerabilita' della chat Shoutbox presente&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-h86Ae1JbL8c/TvqCmpL7zdI/AAAAAAAAm5U/8l14feOi7TA/s1600/struct%2Bshout.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 254px;" src="http://2.bp.blogspot.com/-h86Ae1JbL8c/TvqCmpL7zdI/AAAAAAAAm5U/8l14feOi7TA/s320/struct%2Bshout.jpg" alt="" id="BLOGGER_PHOTO_ID_5691004679538593234" border="0" /&gt;&lt;/a&gt;Attraverso detta vulnerabilita'&lt;span style="font-weight: bold;"&gt; e' stato possibile uploadare shell remota e codice di phishing PHP&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il Codice php &lt;/span&gt;effettua  &lt;span style="font-weight: bold;"&gt;oltre che all'invio al phisher via mail delle credenziali sottratte&lt;/span&gt; anche&lt;span style="font-weight: bold;"&gt; la scrittura su file delle stesse, come si nota dal source&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-J2Ml5KcAT68/TvqCmQ4LPRI/AAAAAAAAm5E/U2ZdwQLK9Pw/s1600/scrive%2Be%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 152px;" src="http://1.bp.blogspot.com/-J2Ml5KcAT68/TvqCmQ4LPRI/AAAAAAAAm5E/U2ZdwQLK9Pw/s320/scrive%2Be%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5691004673013267730" border="0" /&gt;&lt;/a&gt;Ancora quindi di un caso di phishing&lt;span style="font-weight: bold;"&gt; PosteIt&lt;/span&gt; che vede, come gia' ampiamente descritto , il tentativo&lt;span style="font-weight: bold;"&gt; di sottrarre credenziali di carta di credito&lt;/span&gt;, tendenza che probabilmente, andra' &lt;span style="font-weight: bold;"&gt;sempre di piu' affermandosi in futuro negli attacchi di phishing ai danni di banche IT e non.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-923938564175132852?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/923938564175132852/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=923938564175132852' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/923938564175132852'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/923938564175132852'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-postepay-28-dicembre.html' title='Phishing PostePay (28 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-wcICbANxx4o/TvqCOButBmI/AAAAAAAAm4Y/Q14va8BAuRg/s72-c/mails%2Blist.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-552617813288053623</id><published>2011-12-28T08:53:00.004+07:00</published><updated>2011-12-28T09:29:24.794+07:00</updated><title type='text'>Phishing UniCredit (28 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ancora attivi in rete&lt;span style="font-weight: bold;"&gt; diversi phishing &lt;span style="color: rgb(255, 0, 0);"&gt;UniCredit&lt;/span&gt; &lt;/span&gt;come ad esempio questo&lt;span style="font-weight: bold;"&gt; su dominio BR&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-RILOuT6hIhw/Tvp28eTLEJI/AAAAAAAAm2U/DqZaCHRZT10/s1600/wh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 134px;" src="http://1.bp.blogspot.com/-RILOuT6hIhw/Tvp28eTLEJI/AAAAAAAAm2U/DqZaCHRZT10/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5690991860433752210" border="0" /&gt;&lt;/a&gt;che mostra i &lt;span style="font-weight: bold;"&gt;soliti accurati layout&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-h39Rmujs0es/Tvp28qDB0-I/AAAAAAAAm2c/NFdVWfr4lhM/s1600/2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 174px;" src="http://4.bp.blogspot.com/-h39Rmujs0es/Tvp28qDB0-I/AAAAAAAAm2c/NFdVWfr4lhM/s320/2.jpg" alt="" id="BLOGGER_PHOTO_ID_5690991863587263458" border="0" /&gt;&lt;/a&gt;anche se, questa volta,&lt;span style="font-weight: bold;"&gt; con qualche errore&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-OKbdt-fCzGQ/Tvp288k6xPI/AAAAAAAAm2w/WlpqmoJh6_s/s1600/3.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 155px;" src="http://2.bp.blogspot.com/-OKbdt-fCzGQ/Tvp288k6xPI/AAAAAAAAm2w/WlpqmoJh6_s/s320/3.jpg" alt="" id="BLOGGER_PHOTO_ID_5690991868561245426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Interessante anche questo phishing HSBC / &lt;span style="color: rgb(255, 0, 0);"&gt;UniCredit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-DSX8PhZhoUU/Tvp3avgS_rI/AAAAAAAAm3c/IMurMRO1by8/s1600/u1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 209px;" src="http://1.bp.blogspot.com/-DSX8PhZhoUU/Tvp3avgS_rI/AAAAAAAAm3c/IMurMRO1by8/s320/u1.jpg" alt="" id="BLOGGER_PHOTO_ID_5690992380448276146" border="0" /&gt;&lt;/a&gt; ospitato su dominio creato di recente&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-V8JWtL-YVjg/Tvp3Z42lu5I/AAAAAAAAm24/078kaqT5nFo/s1600/data%2Breg%2Bsbc.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 72px;" src="http://1.bp.blogspot.com/-V8JWtL-YVjg/Tvp3Z42lu5I/AAAAAAAAm24/078kaqT5nFo/s320/data%2Breg%2Bsbc.jpg" alt="" id="BLOGGER_PHOTO_ID_5690992365777828754" border="0" /&gt;&lt;/a&gt;ed hostato su server USA.&lt;br /&gt;&lt;br /&gt;Da  notare che &lt;span style="font-weight: bold;"&gt;il nome di dominio creato fa esplicito riferimento alla nota banca inglese HSBC &lt;/span&gt;(&lt;span style="font-style: italic; color: rgb(0, 102, 0);"&gt;e' il primo istituto di credito europeo per capitalizzazione  con sede a Londra.&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(fonte Wikipedia)&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;Si e' addirittura&lt;span style="font-weight: bold;"&gt; scelto un  dominio di primo livello come &lt;span style="color: rgb(255, 0, 0);"&gt;.CO &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;(Colombia)&lt;/span&gt; per creare un indirizzo web ingannevole del tipo &lt;span style="color: rgb(255, 0, 0);"&gt;xxxHSBC.CO&lt;/span&gt;  (il reale dominio della banca e'&lt;span style="color: rgb(255, 0, 0);"&gt; www.hsbc.co.uk&lt;/span&gt; )&lt;br /&gt;&lt;br /&gt;Con queste premesse non e' stato difficile trovare su questo dominio di phishing&lt;span style="font-weight: bold;"&gt; alcune pagine fake ai danni di HSBC come:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-CJ3yJg_brLQ/Tvp3aDq1gwI/AAAAAAAAm3E/3JZdeIqZLks/s1600/hsbclog.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 234px;" src="http://2.bp.blogspot.com/-CJ3yJg_brLQ/Tvp3aDq1gwI/AAAAAAAAm3E/3JZdeIqZLks/s320/hsbclog.jpg" alt="" id="BLOGGER_PHOTO_ID_5690992368681321218" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-fJiGxfxH7R0/Tvp3aVxdCOI/AAAAAAAAm3Q/YqH_PdfuNVQ/s1600/hsbc%2Bstesso%2Burl2011-12-28_080349.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 229px;" src="http://3.bp.blogspot.com/-fJiGxfxH7R0/Tvp3aVxdCOI/AAAAAAAAm3Q/YqH_PdfuNVQ/s320/hsbc%2Bstesso%2Burl2011-12-28_080349.jpg" alt="" id="BLOGGER_PHOTO_ID_5690992373540915426" border="0" /&gt;&lt;/a&gt;che mostrano un layout&lt;span style="font-weight: bold;"&gt; accurato e con i link presenti che redirigono sempre alla stessa pagina fake.&lt;/span&gt;&lt;br /&gt;Si tratta di phishing attualmente attivo anche se non indicato nella segnalazione di quello UniCredit.&lt;br /&gt;&lt;br /&gt;Sullo stesso dominio esiste, come detto,  &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;anche un phishing UniCredit&lt;/span&gt; che mostra questa pagina di fake login&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-DSX8PhZhoUU/Tvp3avgS_rI/AAAAAAAAm3c/IMurMRO1by8/s1600/u1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 209px;" src="http://1.bp.blogspot.com/-DSX8PhZhoUU/Tvp3avgS_rI/AAAAAAAAm3c/IMurMRO1by8/s320/u1.jpg" alt="" id="BLOGGER_PHOTO_ID_5690992380448276146" border="0" /&gt;&lt;/a&gt;seguita da   form di acquisizione &lt;span style="font-weight: bold;"&gt;credenziali relative a carta di credito&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-p7OulaqZreA/Tvp3a6CbjLI/AAAAAAAAm3s/EBLCw8YgGhc/s1600/u2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 228px;" src="http://3.bp.blogspot.com/-p7OulaqZreA/Tvp3a6CbjLI/AAAAAAAAm3s/EBLCw8YgGhc/s320/u2.jpg" alt="" id="BLOGGER_PHOTO_ID_5690992383275797682" border="0" /&gt;&lt;/a&gt;Da notare, anche in questo caso, &lt;span style="font-weight: bold;"&gt;la cura posta nei layouts fake anche se  pare che non vengano effettuati controlli di forma sui dati immessi,&lt;/span&gt; come succedeva nei precedenti phishing &lt;span style="font-weight: bold;"&gt;UniCredit.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Si tratta ancora una volta di tentativi la cui tendenza, sempre in aumento, e' quella di&lt;span style="font-weight: bold;"&gt; cercare di sottrarre credenziali di carta di credito piuttosto o non solo di password di login di accesso a conti bancari online.&lt;/span&gt;&lt;br /&gt;L'uso di dispositivi hardware di verifica delle password (OTP) per l' accesso a servizi di internet banking, rende infatti&lt;span style="font-weight: bold;"&gt; sempre meno praticabile per i phishers,&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;attacchi diretti ai conti on-line.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-552617813288053623?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/552617813288053623/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=552617813288053623' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/552617813288053623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/552617813288053623'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-unicredit-28-dicembre.html' title='Phishing UniCredit (28 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-RILOuT6hIhw/Tvp28eTLEJI/AAAAAAAAm2U/DqZaCHRZT10/s72-c/wh.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4788865407832059840</id><published>2011-12-26T10:45:00.008+07:00</published><updated>2011-12-26T11:28:24.026+07:00</updated><title type='text'>“Click here to see the attached photos”  Spam da probabile account mail compromesso.(26 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ricevuta una lunga sequenza&lt;span style="font-weight: bold;"&gt; di mails da parte di un indirizzo mail presente tra quelli della mia lista  di contatti&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-5sJ8zU_DI_4/TvfuIbbRoNI/AAAAAAAAmzs/5ndJmABL5BY/s1600/msils.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 40px;" src="http://4.bp.blogspot.com/-5sJ8zU_DI_4/TvfuIbbRoNI/AAAAAAAAmzs/5ndJmABL5BY/s320/msils.jpg" alt="" id="BLOGGER_PHOTO_ID_5690278482774434002" border="0" /&gt;&lt;/a&gt;Si tratta di  alcune mails che con&lt;span style="font-weight: bold;"&gt; differente 'oggetto'&lt;/span&gt;  e che sono inviate su diversi miei account ma &lt;span style="font-weight: bold;"&gt;tutte dalla medesima persona.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il testo presente nell'oggetto &lt;span style="font-weight: bold;"&gt;sembra essere creato apposta per incuriosire chi riceve la mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;'VERY GOOD'&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;'SEE THIS'&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;'INCREDIBLE'&lt;/span&gt;&lt;/span&gt; &lt;div style="text-align: justify;"&gt;&lt;br /&gt;e per di piu', &lt;span style="font-weight: bold;"&gt;essendo il mittente persona nota, le premesse per cadere nel tranello della fake mail ci sono tutte.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ecco invece alcuni dettagli&lt;span style="font-weight: bold;"&gt; del contenuto, molto semplice, delle diverse e-mails ricevute&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-F6eALw-ZtMA/TvfuIfvoLWI/AAAAAAAAmz8/owxq2lOAzUs/s1600/m1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 70px;" src="http://3.bp.blogspot.com/-F6eALw-ZtMA/TvfuIfvoLWI/AAAAAAAAmz8/owxq2lOAzUs/s320/m1.jpg" alt="" id="BLOGGER_PHOTO_ID_5690278483933539682" border="0" /&gt;&lt;/a&gt;ed anche&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-XzLzMonkEVA/TvfuI8JJW0I/AAAAAAAAm0E/qKr8vCsJnhs/s1600/m2hot.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 74px;" src="http://2.bp.blogspot.com/-XzLzMonkEVA/TvfuI8JJW0I/AAAAAAAAm0E/qKr8vCsJnhs/s320/m2hot.jpg" alt="" id="BLOGGER_PHOTO_ID_5690278491556764482" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-AYsxIKEm61c/TvfuI-uH5CI/AAAAAAAAm0U/wE9dkGCahy0/s1600/m3hot.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 75px;" src="http://4.bp.blogspot.com/-AYsxIKEm61c/TvfuI-uH5CI/AAAAAAAAm0U/wE9dkGCahy0/s320/m3hot.jpg" alt="" id="BLOGGER_PHOTO_ID_5690278492248728610" border="0" /&gt;&lt;/a&gt;Si tratta di un semplice link &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;“Click here to see the attached photos “&lt;/span&gt; che se cliccato punta a differenti sub-domini (a seconda della mail)&lt;span style="font-weight: bold;"&gt; creati qualche giorno fa.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-3RvlAsUHOl0/TvfvS8hRh4I/AAAAAAAAm00/3jQacDPVXWs/s1600/xm2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 193px;" src="http://2.bp.blogspot.com/-3RvlAsUHOl0/TvfvS8hRh4I/AAAAAAAAm00/3jQacDPVXWs/s320/xm2.jpg" alt="" id="BLOGGER_PHOTO_ID_5690279762968283010" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-9eeMz-riFlQ/TvfvS6b65fI/AAAAAAAAm0o/E7B9JgpZf8Y/s1600/xm1immail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 247px;" src="http://3.bp.blogspot.com/-9eeMz-riFlQ/TvfvS6b65fI/AAAAAAAAm0o/E7B9JgpZf8Y/s320/xm1immail.jpg" alt="" id="BLOGGER_PHOTO_ID_5690279762408957426" border="0" /&gt;&lt;/a&gt;Notate come sia presente&lt;span style="font-weight: bold;"&gt; nel link il nostro indirizzo mail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-m4dfG18KlZc/TvfuJXHTvCI/AAAAAAAAm0c/vXtPcwt0-7U/s1600/mail%2Bdettaglio.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 123px;" src="http://2.bp.blogspot.com/-m4dfG18KlZc/TvfuJXHTvCI/AAAAAAAAm0c/vXtPcwt0-7U/s320/mail%2Bdettaglio.jpg" alt="" id="BLOGGER_PHOTO_ID_5690278498796813346" border="0" /&gt;&lt;/a&gt;che parrebbe essere utilizzato anche per &lt;span style="font-weight: bold;"&gt;personalizzare la pagina cui si viene linkati&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il redirect presente punta a questa pagina dal &lt;span style="font-weight: bold;"&gt;background sfocato&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-3ovPr37pwKI/TvfvprKQLJI/AAAAAAAAm1A/dh78IgGEsIA/s1600/sfondo%2Bsfumato.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://4.bp.blogspot.com/-3ovPr37pwKI/TvfvprKQLJI/AAAAAAAAm1A/dh78IgGEsIA/s320/sfondo%2Bsfumato.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280153445313682" border="0" /&gt;&lt;/a&gt;utile a creare lo sfondo per &lt;span style="font-weight: bold;"&gt;questo form di fake login a Windows Live&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-qbE8kwW3ooI/TvfvpqU-mbI/AAAAAAAAm1I/IYq7EpECUB8/s1600/fake%2Blogin%2B2011-12-26_100722.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 191px;" src="http://2.bp.blogspot.com/-qbE8kwW3ooI/TvfvpqU-mbI/AAAAAAAAm1I/IYq7EpECUB8/s320/fake%2Blogin%2B2011-12-26_100722.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280153221863858" border="0" /&gt;&lt;/a&gt;In pratica si chiede, a fronte del nostro indirizzo mail mail visualizzato in automatico, &lt;span style="font-weight: bold;"&gt;di loggarsi con la propria password, attuando cosi l'acquisizione dei nostri dati di accesso.&lt;/span&gt;&lt;br /&gt;Il fatto che come pagina iniziale venga proprio richiesta la password di login sarebbe un sistema per&lt;span style="font-weight: bold;"&gt; incrementare da parte degli spammers la lista di ulteriori  accounts compromessi da usare in futuro per l'invio delle fake mail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il dominio che ospita il fake login e'&lt;span style="font-weight: bold;"&gt; stato creato il 24 dicembre.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-DfKq9KTcxWE/Tvfvp7OZpYI/AAAAAAAAm1Y/uxkwjPRSKJo/s1600/wh%2Bmerry.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 222px;" src="http://2.bp.blogspot.com/-DfKq9KTcxWE/Tvfvp7OZpYI/AAAAAAAAm1Y/uxkwjPRSKJo/s320/wh%2Bmerry.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280157757678978" border="0" /&gt;&lt;/a&gt;Una volta effettuato il login vengono presentate diverse&lt;span style="font-weight: bold;"&gt; pagine di concorsi a premi, personalizzate nella lingua del destinatario della mail (vedi screenshot)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-E3A1D5xEm6U/TvfwLOYNPZI/AAAAAAAAm1k/8fe7o3E0ZTM/s1600/thai.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 198px;" src="http://3.bp.blogspot.com/-E3A1D5xEm6U/TvfwLOYNPZI/AAAAAAAAm1k/8fe7o3E0ZTM/s320/thai.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280729834765714" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-X8huKHAtGg8/TvfwLalNbeI/AAAAAAAAm1s/QSGRwt-aGo0/s1600/vincita%2Bita.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 265px;" src="http://4.bp.blogspot.com/-X8huKHAtGg8/TvfwLalNbeI/AAAAAAAAm1s/QSGRwt-aGo0/s320/vincita%2Bita.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280733110529506" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-KMEEseosP4I/TvfwLQq5uCI/AAAAAAAAm18/lUSq3J6q2xw/s1600/german.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 193px;" src="http://4.bp.blogspot.com/-KMEEseosP4I/TvfwLQq5uCI/AAAAAAAAm18/lUSq3J6q2xw/s320/german.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280730450049058" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-h4FlDAwfUUU/TvfwLy0Vf-I/AAAAAAAAm2I/U6RdV8TAAvU/s1600/pub%2Busa.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 192px;" src="http://2.bp.blogspot.com/-h4FlDAwfUUU/TvfwLy0Vf-I/AAAAAAAAm2I/U6RdV8TAAvU/s320/pub%2Busa.jpg" alt="" id="BLOGGER_PHOTO_ID_5690280739616423906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Potrebbe quindi trattarsi di &lt;span style="font-weight: bold;"&gt;uno spam orientato a proporre  pagine di dubbia affidabilita', concorsi , ecc...  attraverso mail inviate da account compromessi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Tra l'altro la pagina di login&lt;span style="font-weight: bold;"&gt; fasullo si riferisce proprio ad account Microsoft Live &lt;/span&gt;che e' poi lo stesso usato realmente dalla persona a cui e' stata probabilmente carpita la password di login.&lt;br /&gt;&lt;br /&gt;Chiaramente&lt;span style="font-weight: bold;"&gt; chi venisse a conoscenza di questo problema, relativamente all'invio di mail in automatico da parte del proprio account mail,&lt;/span&gt; dovra'&lt;span style="font-weight: bold;"&gt; tempestivamente cambiare password di accesso al proprio account mail  &lt;/span&gt;(sperando che nel frattempo non ci abbiano gia' 'pensato gli spammers, cosa che vedrebbe l'account mail non piu' amministrabile) ed anche, per sicurezza,&lt;span style="font-weight: bold;"&gt; altre password di accesso a servizi online usati, &lt;/span&gt;che potrebbero comunque essere state&lt;span style="font-weight: bold;"&gt; esposte a seguito dell'account colpito.&lt;/span&gt;&lt;br /&gt;Inoltre sara' opportuno, effettuare&lt;span style="font-weight: bold;"&gt; una completa scansione antivirus del PC, &lt;/span&gt;al fine di evidenziare&lt;span style="font-weight: bold;"&gt; eventuali softwares coinvolti  nella compromissione dell'account, &lt;/span&gt;anche se, come ben sappiamo, non e' detto che il software AV possa rilevare completamente tutte le possibili varianti di malware a cui si e' esposti ogni giorno navigando in rete, proprio per il fatto che la connessione Internet permette attacchi che,  in tempo reale, propongono varianti sempre nuove e mutevoli di malware.&lt;br /&gt;&lt;br /&gt;&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://www.nerdsonsite.com/blog/2011/11/29/windows-live-email-password-theft/"&gt;Qui trovate un post di fine novembre  &lt;/a&gt;pubblicato da blog che si e' occupato di un caso simile.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4788865407832059840?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4788865407832059840/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4788865407832059840' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4788865407832059840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4788865407832059840'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/click-here-to-see-attached-photos-spam.html' title='“Click here to see the attached photos”  Spam da probabile account mail compromesso.(26 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-5sJ8zU_DI_4/TvfuIbbRoNI/AAAAAAAAmzs/5ndJmABL5BY/s72-c/msils.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-423871732778894437</id><published>2011-12-25T13:04:00.005+07:00</published><updated>2011-12-25T13:44:24.385+07:00</updated><title type='text'>E-Cards natalizie pericolose. Alcun ulteriori dettagli (24 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Una ricerca in rete porta a trovare alcuni siti compromessi IT che attualmente ospitano una pagina  E-Card come quella &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/e-cards-pericolose-una-cartolina.html"&gt;vista nel precedente post.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-aBLCuB5TkIU/TvXK3_TYhTI/AAAAAAAAmws/dL3iDES7vl0/s1600/card%2Bonline.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://3.bp.blogspot.com/-aBLCuB5TkIU/TvXK3_TYhTI/AAAAAAAAmws/dL3iDES7vl0/s320/card%2Bonline.jpg" alt="" id="BLOGGER_PHOTO_ID_5689676767486838066" border="0" /&gt;&lt;/a&gt;Andando ad esaminare &lt;span style="font-weight: bold;"&gt;gli headers della connessione web &lt;/span&gt;relativi alle pagine di fake &lt;span style="font-weight: bold;"&gt;E-Card&lt;/span&gt; su siti &lt;span style="font-weight: bold;"&gt;con whois IT&lt;/span&gt; troviamo&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-29ke0yhj9NM/Tva9ej6IopI/AAAAAAAAmyk/VNyVsNUtrYs/s1600/source%2B2%2B2011-12-25_102922.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://3.bp.blogspot.com/-29ke0yhj9NM/Tva9ej6IopI/AAAAAAAAmyk/VNyVsNUtrYs/s320/source%2B2%2B2011-12-25_102922.jpg" alt="" id="BLOGGER_PHOTO_ID_5689943511962002066" border="0" /&gt;&lt;/a&gt;ed in un altro caso&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-68C_05P2BQ0/Tva9erNKAMI/AAAAAAAAmyY/I6BUqrrhWoo/s1600/source%2B1%2Bdata%2B222011-12-25_102411.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 94px;" src="http://1.bp.blogspot.com/-68C_05P2BQ0/Tva9erNKAMI/AAAAAAAAmyY/I6BUqrrhWoo/s320/source%2B1%2Bdata%2B222011-12-25_102411.jpg" alt="" id="BLOGGER_PHOTO_ID_5689943513920831682" border="0" /&gt;&lt;/a&gt;Prendendo per  attendibile l'header indicante l'ultima modifica effettuata possiamo notare data recente che vedrebbe il probabile upload della pagina.&lt;br /&gt;Si tratta in entrambi i casi del&lt;span style="font-weight: bold;"&gt; 22 dicembre cosa che confermerebbe un attacco attuale.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;La cosa piu' interessante e' che&lt;span style="font-weight: bold;"&gt; una ricerca Google porta a trovare un sito USA con struttura di folder simile alle precedenti viste nei casi IT e che mostra identica pagina&lt;/span&gt;.(stessa immagine, testo....)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-TnUPL5ZB9Dg/Tva9fKonjvI/AAAAAAAAmy8/GcgZD908OzM/s1600/old%2Bpage%2Bold%2Bheders.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 203px;" src="http://4.bp.blogspot.com/-TnUPL5ZB9Dg/Tva9fKonjvI/AAAAAAAAmy8/GcgZD908OzM/s320/old%2Bpage%2Bold%2Bheders.jpg" alt="" id="BLOGGER_PHOTO_ID_5689943522357513970" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;La particolarita' sta nella&lt;span style="font-weight: bold;"&gt; data proposta dagli headers che parrebbe far risalire detta pagina al  23 aprile 2011&lt;/span&gt;, datando un simile layout come presente da molto in rete.&lt;br /&gt;In effetti una analisi Wepawet&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-DsCgIXDG79Q/Tva9ezaZ_XI/AAAAAAAAmys/GOtjdNuBx2Q/s1600/wwet1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 184px;" src="http://1.bp.blogspot.com/-DsCgIXDG79Q/Tva9ezaZ_XI/AAAAAAAAmys/GOtjdNuBx2Q/s320/wwet1.jpg" alt="" id="BLOGGER_PHOTO_ID_5689943516123889010" border="0" /&gt;&lt;/a&gt; conferma la data del 23 aprile come quella di una analisi della pagina stessa ed e quindi altamente probabile che gia' in tale data avevamo &lt;span style="font-weight: bold;"&gt;on-line un layout che e' stato 'riciclato' per le odierne fake E-Cards.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ma c'e'  di piu'; analizzando in data odierna la pagina attualmente online (probabilmente a partire da Aprile 2011) otteniamo&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-oWdgJ7T4O-M/Tva9fXuHZkI/AAAAAAAAmzM/J7XvxWsCKlI/s1600/reportobf%2B.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 193px;" src="http://1.bp.blogspot.com/-oWdgJ7T4O-M/Tva9fXuHZkI/AAAAAAAAmzM/J7XvxWsCKlI/s320/reportobf%2B.jpg" alt="" id="BLOGGER_PHOTO_ID_5689943525870233154" border="0" /&gt;&lt;/a&gt;Appare evidente che i codici presenti rivelino&lt;span style="font-weight: bold;"&gt; un BlackHole exploit&lt;/span&gt; ed come un certo numero di indirizzi web attuali, indicati nel report,  linki sempre a script offuscato:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-pOrzNiUfE4w/Tva-WtsiqUI/AAAAAAAAmzc/TkdxYLnNNJs/s1600/sito%2B2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 154px;" src="http://1.bp.blogspot.com/-pOrzNiUfE4w/Tva-WtsiqUI/AAAAAAAAmzc/TkdxYLnNNJs/s320/sito%2B2.jpg" alt="" id="BLOGGER_PHOTO_ID_5689944476662016322" border="0" /&gt;&lt;/a&gt;ed anche&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-1ZbJ80GsNvA/Tva-WRLnVcI/AAAAAAAAmzU/JzUNxtQ6Q1I/s1600/sito%2Bcon%2Bscript.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 151px;" src="http://1.bp.blogspot.com/-1ZbJ80GsNvA/Tva-WRLnVcI/AAAAAAAAmzU/JzUNxtQ6Q1I/s320/sito%2Bcon%2Bscript.jpg" alt="" id="BLOGGER_PHOTO_ID_5689944469007717826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-423871732778894437?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/423871732778894437/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=423871732778894437' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/423871732778894437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/423871732778894437'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/e-cards-natalizie-pericolose-alcun.html' title='E-Cards natalizie pericolose. Alcun ulteriori dettagli (24 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-aBLCuB5TkIU/TvXK3_TYhTI/AAAAAAAAmws/dL3iDES7vl0/s72-c/card%2Bonline.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-5160633870055946685</id><published>2011-12-24T19:47:00.009+07:00</published><updated>2011-12-24T20:46:54.157+07:00</updated><title type='text'>E-Cards pericolose. Una cartolina elettronica natalizia particolare (24 dicembre)</title><content type='html'>Ecco una mail ricevuta questa mattina, che dal testo (nome di persona sconosciuta che invia l'E-Card) sembra &lt;span style="font-weight: bold;"&gt;essere il solito tentativo di compromettere il PC di chi al riceve.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/--r66faZpNk4/TvXKGb_gA3I/AAAAAAAAmv8/rtuNBOObKEs/s1600/mail%2B2011-12-24_184835.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 286px;" src="http://1.bp.blogspot.com/--r66faZpNk4/TvXKGb_gA3I/AAAAAAAAmv8/rtuNBOObKEs/s320/mail%2B2011-12-24_184835.jpg" alt="" id="BLOGGER_PHOTO_ID_5689675916194612082" border="0" /&gt;&lt;/a&gt;Un click su uno dei links presenti, rivela pero' &lt;span style="font-weight: bold;"&gt;che il sito IT a cui puntava&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-LMU8p-nUB8E/TvXK4l0hmAI/AAAAAAAAmxQ/KwF9pJbIiws/s1600/wh%2Bsito%2Bsuspended.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 125px;" src="http://3.bp.blogspot.com/-LMU8p-nUB8E/TvXK4l0hmAI/AAAAAAAAmxQ/KwF9pJbIiws/s320/wh%2Bsito%2Bsuspended.jpg" alt="" id="BLOGGER_PHOTO_ID_5689676777826392066" border="0" /&gt;&lt;/a&gt; e' stato messo &lt;span style="font-weight: bold;"&gt;offline dall' hoster, &lt;/span&gt;molto probabilmente proprio a causa di problemi di sicurezza.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-jfcOfCf2BSI/TvXKHclEdnI/AAAAAAAAmwk/mUBCR9a49zg/s1600/susp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 107px;" src="http://1.bp.blogspot.com/-jfcOfCf2BSI/TvXKHclEdnI/AAAAAAAAmwk/mUBCR9a49zg/s320/susp.jpg" alt="" id="BLOGGER_PHOTO_ID_5689675933532059250" border="0" /&gt;&lt;/a&gt;Una veloce ricerca in rete &lt;span style="font-weight: bold;"&gt;permette comunque di trovare un altro sito IT compromesso,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-blbdG8U_I90/TvXKGlkR6gI/AAAAAAAAmwE/_Oa-SQrWjak/s1600/whois%2Bit%2Bsto%2Battivo.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 128px;" src="http://3.bp.blogspot.com/-blbdG8U_I90/TvXKGlkR6gI/AAAAAAAAmwE/_Oa-SQrWjak/s320/whois%2Bit%2Bsto%2Battivo.jpg" alt="" id="BLOGGER_PHOTO_ID_5689675918764796418" border="0" /&gt;&lt;/a&gt; questa volta ON-line, e &lt;span style="font-weight: bold;"&gt;che propone una pagina come questa&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-aBLCuB5TkIU/TvXK3_TYhTI/AAAAAAAAmws/dL3iDES7vl0/s1600/card%2Bonline.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://3.bp.blogspot.com/-aBLCuB5TkIU/TvXK3_TYhTI/AAAAAAAAmws/dL3iDES7vl0/s320/card%2Bonline.jpg" alt="" id="BLOGGER_PHOTO_ID_5689676767486838066" border="0" /&gt;&lt;/a&gt;Notate che il link corrisponde comunque nella sua struttura ---- &lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;/E-Cards/?id&lt;/span&gt;----   a quello rilevabile &lt;span style="font-weight: bold;"&gt;nel source della mail ricevuta&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-VoThWxSvw3Q/TvXKG50FQ1I/AAAAAAAAmwQ/dynZHjsFXZA/s1600/source%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 297px;" src="http://4.bp.blogspot.com/-VoThWxSvw3Q/TvXKG50FQ1I/AAAAAAAAmwQ/dynZHjsFXZA/s320/source%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5689675924199785298" border="0" /&gt;&lt;/a&gt;cosa che dimostra che ci troviamo, molto probabilmente&lt;span style="font-weight: bold;"&gt;, sempre di fronte ad un sito coinvolto, suo malgrado, nella distribuzione del malware linkato dalle fake E-Card.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il sorgente della pagina contiene &lt;span style="font-weight: bold;"&gt;questo codice offuscato&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-jv17mWLbpks/TvXK4H8ybjI/AAAAAAAAmw0/GSMcpffoPlw/s1600/card%2Bcode.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 133px;" src="http://2.bp.blogspot.com/-jv17mWLbpks/TvXK4H8ybjI/AAAAAAAAmw0/GSMcpffoPlw/s320/card%2Bcode.jpg" alt="" id="BLOGGER_PHOTO_ID_5689676769807986226" border="0" /&gt;&lt;/a&gt;che parrebbe&lt;span style="font-weight: bold;"&gt; puntare a sito ucraino&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-RWGxLhc6C2I/TvXK4R-eJuI/AAAAAAAAmxA/HbTpsUUvLrQ/s1600/deoffuscato.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 106px;" src="http://3.bp.blogspot.com/-RWGxLhc6C2I/TvXK4R-eJuI/AAAAAAAAmxA/HbTpsUUvLrQ/s320/deoffuscato.jpg" alt="" id="BLOGGER_PHOTO_ID_5689676772499400418" border="0" /&gt;&lt;/a&gt;con whois&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-pwbVavRYvv4/TvXLX0VdfWI/AAAAAAAAmxc/GvfBLXtSKec/s1600/whoi%2Bpuntato%2Bda%2Bdeoffsc.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 226px;" src="http://4.bp.blogspot.com/-pwbVavRYvv4/TvXLX0VdfWI/AAAAAAAAmxc/GvfBLXtSKec/s320/whoi%2Bpuntato%2Bda%2Bdeoffsc.jpg" alt="" id="BLOGGER_PHOTO_ID_5689677314298576226" border="0" /&gt;&lt;/a&gt;Seguendo il link &lt;span style="font-weight: bold;"&gt;del codice de-offuscato ci troviamo di fronte a questo nuovo codice nuovamente offuscato&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-agw_Gdcq-zY/TvXLYMU9l8I/AAAAAAAAmxo/FumPNwbosvw/s1600/cod%2Bof%2Bsu%2Bsito%2Bukr.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;" src="http://1.bp.blogspot.com/-agw_Gdcq-zY/TvXLYMU9l8I/AAAAAAAAmxo/FumPNwbosvw/s320/cod%2Bof%2Bsu%2Bsito%2Bukr.jpg" alt="" id="BLOGGER_PHOTO_ID_5689677320738936770" border="0" /&gt;&lt;/a&gt;che deoffuscato mostra&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-13FQDDPopsc/TvXLYS6HqiI/AAAAAAAAmx0/eqfoptBsMgw/s1600/malware.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 114px;" src="http://4.bp.blogspot.com/-13FQDDPopsc/TvXLYS6HqiI/AAAAAAAAmx0/eqfoptBsMgw/s320/malware.jpg" alt="" id="BLOGGER_PHOTO_ID_5689677322505398818" border="0" /&gt;&lt;/a&gt;Il codice&lt;span style="font-weight: bold;"&gt; e' simile a quello gia' analizzato&lt;a style="color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/distribuzione-malware-attraverso-mail.html"&gt; qualche giorno fa sul blog&lt;/a&gt;&lt;span style="color: rgb(51, 102, 255);"&gt;,&lt;/span&gt;&lt;/span&gt; in un caso di spam malware, e ricorda il noto &lt;span style="font-weight: bold;"&gt;BlackHole Exploit.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In effetti se salviamo il codice della pagina &lt;span style="font-weight: bold;"&gt; di fake E-Card e passiamo il file a Virus Total troviamo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-4O4TaD_quV8/TvXSWY13VZI/AAAAAAAAmyA/Jbht0mxNP_o/s1600/vt%2Bcard.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 256px;" src="http://4.bp.blogspot.com/-4O4TaD_quV8/TvXSWY13VZI/AAAAAAAAmyA/Jbht0mxNP_o/s320/vt%2Bcard.jpg" alt="" id="BLOGGER_PHOTO_ID_5689684986319820178" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;con 8 softwares Av &lt;/span&gt;che individuano una minaccia ed alcuni nello specifico un software malevolo Blacole&lt;br /&gt;&lt;br /&gt;Se passiamo invece &lt;span style="font-weight: bold;"&gt;a VT il codice finale, offuscato linkato sul sito ucraino &lt;/span&gt;abbiamo &lt;span style="font-weight: bold;"&gt;l'antivirus Microsoft che individua il file come Blacole Exploit.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ICpJur6txj8/TvXSWvGtaNI/AAAAAAAAmyM/wRV_IbDhsAs/s1600/codice%2B%2Bsu%2Bukra.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 131px;" src="http://3.bp.blogspot.com/-ICpJur6txj8/TvXSWvGtaNI/AAAAAAAAmyM/wRV_IbDhsAs/s320/codice%2B%2Bsu%2Bukra.jpg" alt="" id="BLOGGER_PHOTO_ID_5689684992296052946" border="0" /&gt;&lt;/a&gt;Come si vede, si tratta di un tentativo di diffondere malware da parte di personaggi  che approfittano del periodo natalizio per rendere&lt;span style="font-weight: bold;"&gt; piu' credibili le mails con links a fakes  E-Card &lt;/span&gt;hostate, anche, su &lt;span style="font-weight: bold;"&gt;alcuni siti IT compromessi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(204, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-5160633870055946685?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/5160633870055946685/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=5160633870055946685' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5160633870055946685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/5160633870055946685'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/e-cards-pericolose-una-cartolina.html' title='E-Cards pericolose. Una cartolina elettronica natalizia particolare (24 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/--r66faZpNk4/TvXKGb_gA3I/AAAAAAAAmv8/rtuNBOObKEs/s72-c/mail%2B2011-12-24_184835.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2908353501149509522</id><published>2011-12-24T14:42:00.002+07:00</published><updated>2011-12-24T15:12:13.432+07:00</updated><title type='text'></title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-TOrV0ixOkvY/TvWJKyHAm5I/AAAAAAAAmvw/8vLussQy3wU/s1600/buon%2Bnatale%2Bbig.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 302px;" src="http://3.bp.blogspot.com/-TOrV0ixOkvY/TvWJKyHAm5I/AAAAAAAAmvw/8vLussQy3wU/s400/buon%2Bnatale%2Bbig.jpg" alt="" id="BLOGGER_PHOTO_ID_5689604522595359634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-MYyxiBiXonI/TvWIhG1BXQI/AAAAAAAAmvk/PgdzZ2d3Blk/s1600/buon%2Bnatale%2Bbig.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-MYyxiBiXonI/TvWIhG1BXQI/AAAAAAAAmvk/PgdzZ2d3Blk/s1600/buon%2Bnatale%2Bbig.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2908353501149509522?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2908353501149509522/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2908353501149509522' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2908353501149509522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2908353501149509522'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/blog-post.html' title=''/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-TOrV0ixOkvY/TvWJKyHAm5I/AAAAAAAAmvw/8vLussQy3wU/s72-c/buon%2Bnatale%2Bbig.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6410508298208910685</id><published>2011-12-24T11:51:00.003+07:00</published><updated>2011-12-24T12:05:17.396+07:00</updated><title type='text'>Ancora phishing CartaSi (24 dicembre)</title><content type='html'>Poche righe per descrivere  ancora&lt;span style="font-weight: bold;"&gt; una  mail di phishing &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt; che vede l'utilizzo sempre del layout gia' visto parecchio in passato&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-EteVWUfEOY4/TvVcfFR-G3I/AAAAAAAAmvA/s8YIU8h-FRc/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 313px; height: 320px;" src="http://2.bp.blogspot.com/-EteVWUfEOY4/TvVcfFR-G3I/AAAAAAAAmvA/s8YIU8h-FRc/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5689555393315740530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;con header che presenta IP IT gia' trovato altre volte&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-NMGxUp7Wy14/TvVceuxBiLI/AAAAAAAAmu4/7Wn-QvcZD-Q/s1600/headers%2Bit.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 53px;" src="http://3.bp.blogspot.com/-NMGxUp7Wy14/TvVceuxBiLI/AAAAAAAAmu4/7Wn-QvcZD-Q/s320/headers%2Bit.jpg" alt="" id="BLOGGER_PHOTO_ID_5689555387271973042" border="0" /&gt;&lt;/a&gt;e  medesimi domini c&lt;span style="font-weight: bold;"&gt;ompromessi usati in passato  dal phisher per il redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-3n5_cqCI_LY/TvVcff9rNrI/AAAAAAAAmvY/YlFzekEIsfw/s1600/redir%2Bfile%2B2011-12-24_111126.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 66px;" src="http://4.bp.blogspot.com/-3n5_cqCI_LY/TvVcff9rNrI/AAAAAAAAmvY/YlFzekEIsfw/s320/redir%2Bfile%2B2011-12-24_111126.jpg" alt="" id="BLOGGER_PHOTO_ID_5689555400478373554" border="0" /&gt;&lt;/a&gt;La differenza e' che&lt;span style="font-weight: bold;"&gt; il sito compromesso IT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-D6jqV4tN9jk/TuiG9iWC5iI/AAAAAAAAmUM/dXOw-wKb0Pk/s1600/wh%2Bit.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 190px;" src="http://3.bp.blogspot.com/-D6jqV4tN9jk/TuiG9iWC5iI/AAAAAAAAmUM/dXOw-wKb0Pk/s320/wh%2Bit.jpg" alt="" id="BLOGGER_PHOTO_ID_5685942921304663586" border="0" /&gt;&lt;/a&gt;che &lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/on-line-lennesimo-phishing-cartasi-14.html"&gt;era utilizzato qui come host del redirect&lt;/a&gt; ospita ora un clone &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;CartaSi &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-MtXnPssAb-I/TvVceg70orI/AAAAAAAAmuo/6MK4WvTX7HE/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 143px;" src="http://2.bp.blogspot.com/-MtXnPssAb-I/TvVceg70orI/AAAAAAAAmuo/6MK4WvTX7HE/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5689555383559168690" border="0" /&gt;&lt;/a&gt;(notare date recenti dei files)&lt;br /&gt;&lt;br /&gt;Analizzando il codice php di invio credenziali eventualmente sottratte dal phishing si nota come si tratta sempre del medesimo indirizzo mail gia' visto &lt;span style="font-weight: bold;"&gt;nel precedente caso CartaSi che vedeva coinvolto il sito IT.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-vELOU6JWYpM/TvVcfCXbb5I/AAAAAAAAmvI/CbGxT7i48ls/s1600/php.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 207px;" src="http://3.bp.blogspot.com/-vELOU6JWYpM/TvVcfCXbb5I/AAAAAAAAmvI/CbGxT7i48ls/s320/php.jpg" alt="" id="BLOGGER_PHOTO_ID_5689555392533327762" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6410508298208910685?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6410508298208910685/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6410508298208910685' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6410508298208910685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6410508298208910685'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/ancora-phishing-cartasi-24-dicembre.html' title='Ancora phishing CartaSi (24 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-EteVWUfEOY4/TvVcfFR-G3I/AAAAAAAAmvA/s8YIU8h-FRc/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4253050224440798388</id><published>2011-12-24T10:36:00.006+07:00</published><updated>2011-12-24T10:55:44.156+07:00</updated><title type='text'>Dal Db segnalazioni del blog. Un nuovo caso di phishing UniCredit estremamente curato nel layout   ed ingannevole. (24 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Gli ultimi attacchi di phishing del mese di novembre,  ai &lt;span style="font-weight: bold;"&gt;danni di UniCredit&lt;/span&gt; hanno presentato un&lt;a style="color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/11/lintrepido-viaggio-di-topolino-phishing.html"&gt;&lt;span style="font-weight: bold;"&gt; livello di dettaglio raramente visto in rete&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;Si trattava di phishing che sfruttando info tratte da un reale concorso promosso dalla banca, tentava di ingannare  chi avesse ricevuto la fake mail, informando di una vincita, naturalmente fasulla  (&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/11/continua-lintrepido-viaggio-di-topolino.html"&gt;maggiori dettagli al riguardo anche su questo precedente post&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;L'odierna segnalazione di un lettore del blog, che ringrazio,&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-UJCivYQjAl4/TvVJM0QVeJI/AAAAAAAAmsY/tGwCmXS9kTc/s1600/segnal.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 91px;" src="http://4.bp.blogspot.com/-UJCivYQjAl4/TvVJM0QVeJI/AAAAAAAAmsY/tGwCmXS9kTc/s320/segnal.jpg" alt="" id="BLOGGER_PHOTO_ID_5689534188786907282" border="0" /&gt;&lt;/a&gt;ci presenta un nuovo &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;phishing UniCredit&lt;/span&gt; che raggiunge &lt;span style="font-weight: bold;"&gt;un livello di dettaglio fuori dal comune per phishing ai danni di banche IT.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Per di piu' anche&lt;span style="font-weight: bold;"&gt; gli indirizzi web sia del redirect che del clone sfruttano ampiamente la tecnica di uso di sottodomini creati a partire da legittimi domini come gia'  visto anche nel caso di diversi phishing PosteIT.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Da evidenziare inoltre, che, anche in questo phishing&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; UniCredit&lt;/span&gt;, ritornano  domini turchi compromessi come accadeva  per il precedente phishing UniCredit di novembre.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-TkWEEjJKt-0/TvVJM49VA6I/AAAAAAAAmsg/neoLzVG_9Qc/s1600/cooncorso%2Btopolino%2Bturco.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 71px;" src="http://4.bp.blogspot.com/-TkWEEjJKt-0/TvVJM49VA6I/AAAAAAAAmsg/neoLzVG_9Qc/s320/cooncorso%2Btopolino%2Bturco.jpg" alt="" id="BLOGGER_PHOTO_ID_5689534190049362850" border="0" /&gt;&lt;/a&gt;Dato che&lt;span style="font-weight: bold;"&gt; non e' disponibile la reale mail, ma il codice presente nella segnalazione,&lt;/span&gt; ricostruiamo il layout della mail copiando la parte html  del codice in un  file testo ed aprendolo in browser.&lt;br /&gt;Ecco come si presenta la mail (&lt;span style="font-style: italic;"&gt;ricostruita&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-5vM55MYiQG4/TvVJNIlAmpI/AAAAAAAAmsw/bALYijlAFXY/s1600/mail%2Bin%2Bhtml.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 217px;" src="http://4.bp.blogspot.com/-5vM55MYiQG4/TvVJNIlAmpI/AAAAAAAAmsw/bALYijlAFXY/s320/mail%2Bin%2Bhtml.jpg" alt="" id="BLOGGER_PHOTO_ID_5689534194242329234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;che  gia' dal layout &lt;span style="font-weight: bold;"&gt;evidenzia la cura posta sia nel testo che nella presenza di links al phishing anche  attraverso un apposito pulsante di scelta.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il dominio di redirect &lt;span style="font-weight: bold;"&gt;appare ad una sommaria analisi come&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Ms68q5bkBNU/TvVJvEAUUPI/AAAAAAAAms8/glZ-hcg7DHo/s1600/dns%2Bredirect.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 166px;" src="http://4.bp.blogspot.com/-Ms68q5bkBNU/TvVJvEAUUPI/AAAAAAAAms8/glZ-hcg7DHo/s320/dns%2Bredirect.jpg" alt="" id="BLOGGER_PHOTO_ID_5689534777130242290" border="0" /&gt;&lt;/a&gt;dove si nota che il reale IP a cui si viene&lt;span style="font-weight: bold;"&gt; rediretti e' su server polacco.&lt;/span&gt;&lt;br /&gt;Ii pratica i phishers hanno creato un sottodominio fake accedendo probabilmente al controllo dei DNS sul sito turco, facendo puntare a sito con whois PL  che ospita il redirect al clone UniCredit  come:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-4zACaHp37Ag/TvVKAJes6-I/AAAAAAAAmtI/RG_vztyuwtI/s1600/domain%2Bph%2Bdns.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 150px;" src="http://4.bp.blogspot.com/-4zACaHp37Ag/TvVKAJes6-I/AAAAAAAAmtI/RG_vztyuwtI/s320/domain%2Bph%2Bdns.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535070657637346" border="0" /&gt;&lt;/a&gt;Anche in questo caso un utilizzo di dominio legittimo con whois turco con attivo un sottodominio che  punta al sito clone&lt;span style="font-weight: bold;"&gt; ospitato su ip sloveno&lt;/span&gt;.&lt;br /&gt;Una riprova e' che&lt;span style="font-weight: bold;"&gt; sostituendo nella URL  direttamente l'IP sloveno 'il risultato non cambia'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-IJawvvckBR0/TvVKApJjI1I/AAAAAAAAmtg/WUgWiIw8YyA/s1600/url%2Bip%2Bsloveno.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 118px;" src="http://1.bp.blogspot.com/-IJawvvckBR0/TvVKApJjI1I/AAAAAAAAmtg/WUgWiIw8YyA/s320/url%2Bip%2Bsloveno.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535079158850386" border="0" /&gt;&lt;/a&gt;Altra nota particolare accedendo con IP thai, il sito clone parrebbe essere comunque&lt;span style="font-weight: bold;"&gt; 'forbidden'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-uCa2I4z3uhE/TvVKADZCJ6I/AAAAAAAAmtY/GmOw91BLm2g/s1600/forbidden.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 108px;" src="http://2.bp.blogspot.com/-uCa2I4z3uhE/TvVKADZCJ6I/AAAAAAAAmtY/GmOw91BLm2g/s320/forbidden.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535069023250338" border="0" /&gt;&lt;/a&gt;Tornando al phishing, &lt;span style="font-weight: bold;"&gt;la prima pagina proposta presenta questa finestra sovrapposta alla fake home e che invita a digitare codici di accesso&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-pWmUxE-8XNs/TvVKlgFLHII/AAAAAAAAmts/MVdZMOCiqAA/s1600/main%2Bph.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 187px;" src="http://1.bp.blogspot.com/-pWmUxE-8XNs/TvVKlgFLHII/AAAAAAAAmts/MVdZMOCiqAA/s320/main%2Bph.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535712379739266" border="0" /&gt;&lt;/a&gt;a seguito dei quali, ed&lt;span style="font-weight: bold;"&gt; dopo una attesa ,simulata, di connessione al s&lt;/span&gt;erver,&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Nzr4YSaQNrI/TvVKl1Bwk-I/AAAAAAAAmt0/5xVprWmVboA/s1600/2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 166px;" src="http://3.bp.blogspot.com/-Nzr4YSaQNrI/TvVKl1Bwk-I/AAAAAAAAmt0/5xVprWmVboA/s320/2.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535718002562018" border="0" /&gt;&lt;/a&gt;si passa ad &lt;span style="font-weight: bold;"&gt;una serie finestre tutte curate nei minimi particolari&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-EaF4sMwPESM/TvVKl8YQCsI/AAAAAAAAmuE/0MQWX8deKdQ/s1600/3.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 172px;" src="http://3.bp.blogspot.com/-EaF4sMwPESM/TvVKl8YQCsI/AAAAAAAAmuE/0MQWX8deKdQ/s320/3.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535719975946946" border="0" /&gt;&lt;/a&gt;da cui&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-XNacNZtm_ns/TvVKmSWaF_I/AAAAAAAAmuQ/MV8510oim7M/s1600/4.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 192px;" src="http://3.bp.blogspot.com/-XNacNZtm_ns/TvVKmSWaF_I/AAAAAAAAmuQ/MV8510oim7M/s320/4.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535725873797106" border="0" /&gt;&lt;/a&gt;ed ancora&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-UE4cIQAIFpU/TvVKmuA4Y4I/AAAAAAAAmuc/4VFEySfroaI/s1600/5.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 183px;" src="http://2.bp.blogspot.com/-UE4cIQAIFpU/TvVKmuA4Y4I/AAAAAAAAmuc/4VFEySfroaI/s320/5.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535733299700610" border="0" /&gt;&lt;/a&gt;sempre con&lt;span style="font-weight: bold;"&gt; verifica della forma dei dati immessi &lt;/span&gt;(codice fiscale, n.carta di credito ecc....)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-pWmUxE-8XNs/TvVKlgFLHII/AAAAAAAAmts/MVdZMOCiqAA/s1600/main%2Bph.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 187px;" src="http://1.bp.blogspot.com/-pWmUxE-8XNs/TvVKlgFLHII/AAAAAAAAmts/MVdZMOCiqAA/s320/main%2Bph.jpg" alt="" id="BLOGGER_PHOTO_ID_5689535712379739266" border="0" /&gt;&lt;/a&gt;Cura viene anche posta nella rappresentazione&lt;span style="font-weight: bold;"&gt; dell'URL nel browser dove ad esempio appare una reale icona   UniCredit e ,notate, il nome ingannevole della URL in uso.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Un phishing quindi&lt;span style="font-weight: bold;"&gt; molto curato e che per questo potrebbe risultare estremamente ingannevole a chi ricevesse la fake mail &lt;span style="color: rgb(255, 0, 0);"&gt;UniCredit.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4253050224440798388?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4253050224440798388/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4253050224440798388' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4253050224440798388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4253050224440798388'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/dal-db-segnalazioni-del-blog-un-nuovo.html' title='Dal Db segnalazioni del blog. Un nuovo caso di phishing UniCredit estremamente curato nel layout   ed ingannevole. (24 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-UJCivYQjAl4/TvVJM0QVeJI/AAAAAAAAmsY/tGwCmXS9kTc/s72-c/segnal.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-2100737694215669682</id><published>2011-12-23T22:03:00.006+07:00</published><updated>2011-12-23T22:17:58.929+07:00</updated><title type='text'>Phishing CartaSi. Ancora vulnerabilita' note a supporto di azioni di phishing (23 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Come ormai ben documentato in rete ed anche sul blog,  l'azione dei phishers vede in moltissimi casi l'utilizzo a supporto dell'hosting dei cloni di phishing, sia&lt;span style="font-weight: bold;"&gt; siti che propongono on-line vie di accesso senza restrizioni ai contenuti degli stessi (Innova Studio File&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; Manager e' uno dei piu' utilizzati) sia vulnerabilita' diffuse.&lt;/span&gt;&lt;br /&gt;Tra quelle piu' utilizzate ultimamente  in attacchi a &lt;span style="font-weight: bold;"&gt;CartaSi &lt;/span&gt;c'e'  quella &lt;span style="font-weight: bold;"&gt;WordPress&lt;/span&gt; definita come  '&lt;span style="font-weight: bold;"&gt;WordPress Timthumb Vulnerability'&lt;/span&gt; (&lt;a style="font-weight: bold; color: rgb(51, 102, 255);" href="http://blog.spiderlabs.com/2011/11/wordpress-timthumb-attacks-rising.html"&gt;qui alcuni dettagli&lt;/a&gt;) e che e' usata anche nel caso odierno.&lt;br /&gt;Si tratta di vulnerabilita' diffusa e che e' ben documentata in rete da tempo come vediamo in questo articolo &lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://www.darkreading.com/database-security/167901020/security/news/231902162/hackers-timthumb-their-noses-at-vulnerability-to-compromise-1-2-million-sites.html"&gt;apparso online nel novembre 2011&lt;/a&gt; &lt;span style="font-style: italic; font-weight: bold;"&gt;“Hackers 'Timthumb' Their Noses At Vulnerability To Compromise 1.2 Million Sites...........”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Tornando al caso odierno, &lt;span style="font-weight: bold;"&gt;questa la mail ricevuta&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-8CLVoCxtozY/TvSZLGWk7jI/AAAAAAAAmrw/qVI5ju2-brY/s1600/mail%2B2011-12-23_204635.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 250px;" src="http://3.bp.blogspot.com/-8CLVoCxtozY/TvSZLGWk7jI/AAAAAAAAmrw/qVI5ju2-brY/s320/mail%2B2011-12-23_204635.jpg" alt="" id="BLOGGER_PHOTO_ID_5689340645238697522" border="0" /&gt;&lt;/a&gt;con primo &lt;span style="font-weight: bold;"&gt;IP negli headers italiano:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-vPsrmJI2bLM/TvSZKBeAGbI/AAAAAAAAmrQ/vhJ-YwvcfZM/s1600/header.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 63px;" src="http://3.bp.blogspot.com/-vPsrmJI2bLM/TvSZKBeAGbI/AAAAAAAAmrQ/vhJ-YwvcfZM/s320/header.jpg" alt="" id="BLOGGER_PHOTO_ID_5689340626747791794" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Il form di phishing CartaSi allegato&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-jbkdPHD05_U/TvSZKnrvwDI/AAAAAAAAmro/jUfsylrUHpY/s1600/il%2Bform.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 208px; height: 320px;" src="http://4.bp.blogspot.com/-jbkdPHD05_U/TvSZKnrvwDI/AAAAAAAAmro/jUfsylrUHpY/s320/il%2Bform.jpg" alt="" id="BLOGGER_PHOTO_ID_5689340637005987890" border="0" /&gt;&lt;/a&gt;utilizza come codice di acquisizione dei dati introdotti,&lt;span style="font-weight: bold;"&gt; un php ospitato su sito  sviluppato in WordPress e compromesso.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-iuq2EFrODUk/TvSZLRKfHxI/AAAAAAAAmsA/o-cYPM8Cee4/s1600/php%2Bform%2Baction.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 37px;" src="http://3.bp.blogspot.com/-iuq2EFrODUk/TvSZLRKfHxI/AAAAAAAAmsA/o-cYPM8Cee4/s320/php%2Bform%2Baction.jpg" alt="" id="BLOGGER_PHOTO_ID_5689340648140775186" border="0" /&gt;&lt;/a&gt;Questo un dettaglio del&lt;span style="font-weight: bold;"&gt; folder collegato appunto al plugin Timthumb &lt;/span&gt;sul sito colpito,  che vede&lt;span style="font-weight: bold;"&gt; oltre che al codice php  anche numerosi codici di shells legati alla vulnerabilita',&lt;/span&gt; alcune shells ed anche un file di testo su cui vengono salvate le credenziali sottratte.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-9YQwldZUPnk/TvSZKan8BRI/AAAAAAAAmrY/nkQOLOOv-No/s1600/cache.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 159px;" src="http://4.bp.blogspot.com/-9YQwldZUPnk/TvSZKan8BRI/AAAAAAAAmrY/nkQOLOOv-No/s320/cache.jpg" alt="" id="BLOGGER_PHOTO_ID_5689340633500353810" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Il php linkato dal form,infatti&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/--vZ6wN2pbgE/TvSaAYvVOCI/AAAAAAAAmsM/GcELDb7lEo8/s1600/php.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 318px;" src="http://1.bp.blogspot.com/--vZ6wN2pbgE/TvSaAYvVOCI/AAAAAAAAmsM/GcELDb7lEo8/s320/php.jpg" alt="" id="BLOGGER_PHOTO_ID_5689341560707430434" border="0" /&gt;&lt;/a&gt;oltre che ad&lt;span style="font-weight: bold;"&gt; inviare,come succede quasi sempre, le credenziali sottratte al phisher tramite e-mail  &lt;/span&gt;(indirizzo gia' visto  in altri recenti casi di phishing CartaSi) &lt;span style="font-weight: bold;"&gt;scrive sul  file evidenziato nello screenshot, i dati personali acquisiti&lt;/span&gt; a chi fosse caduto nel tranello della &lt;span style="font-weight: bold;"&gt;fake comunicazione CartaSi&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-2100737694215669682?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/2100737694215669682/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=2100737694215669682' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2100737694215669682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/2100737694215669682'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-cartasi-ancora-vulnerabilita.html' title='Phishing CartaSi. Ancora vulnerabilita&apos; note a supporto di azioni di phishing (23 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-8CLVoCxtozY/TvSZLGWk7jI/AAAAAAAAmrw/qVI5ju2-brY/s72-c/mail%2B2011-12-23_204635.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-7890329851553757566</id><published>2011-12-21T09:58:00.010+07:00</published><updated>2011-12-21T10:44:29.724+07:00</updated><title type='text'>Sito italiano compromesso per distribuire malware mirato ad utenti internet di lingua tedesca. Il 'solito' file dal nome ingannevole.(21 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;AVVISO     IMPORTANTE!     Ricordo che anche se alcuni links sono lasciati in     chiaro  negli    screenshot, evitate di visitare i siti elencati se non     avete preso     tutte le precauzioni del caso ! Si tratta di  pagine e    siti  che distribuiscono eseguibili MALWARE a volte anche poco   riconosciuti dai    software AV.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Si tratta di una&lt;span style="font-weight: bold;"&gt; mail in lingua tedesca&lt;/span&gt; ricevuta oggi&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-PRlPj-D2n4M/TvFLw77PYRI/AAAAAAAAmpA/LyERek_g_WI/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 220px;" src="http://2.bp.blogspot.com/-PRlPj-D2n4M/TvFLw77PYRI/AAAAAAAAmpA/LyERek_g_WI/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411108437614866" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;che tradotta&lt;/span&gt; mostra&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-2hpVpkABAz4/TvFMLiiuezI/AAAAAAAAmpk/35EZRnfwInE/s1600/translate%2Bgerm%2Bita.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 58px;" src="http://4.bp.blogspot.com/-2hpVpkABAz4/TvFMLiiuezI/AAAAAAAAmpk/35EZRnfwInE/s320/translate%2Bgerm%2Bita.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411565480377138" border="0" /&gt;&lt;/a&gt;e che vede ancora una volta&lt;span style="font-weight: bold;"&gt; l'utilizzo dell'ormai ben nota pratica del file allegato in formato zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-GLfk6B4KOpw/TvFMg2Q6DoI/AAAAAAAAmqI/FHJcBGBDHvY/s1600/zip.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 65px;" src="http://1.bp.blogspot.com/-GLfk6B4KOpw/TvFMg2Q6DoI/AAAAAAAAmqI/FHJcBGBDHvY/s320/zip.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411931551600258" border="0" /&gt;&lt;/a&gt;che propone un&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; nome di file eseguibile particolare&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-cheOtY_oJ2w/TvFMLyvty_I/AAAAAAAAmqA/FREApOs7d1s/s1600/detfile.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 63px;" src="http://4.bp.blogspot.com/-cheOtY_oJ2w/TvFMLyvty_I/AAAAAAAAmqA/FREApOs7d1s/s320/detfile.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411569829825522" border="0" /&gt;&lt;/a&gt;L'utilizzo di una lunga serie di caratteri&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt; 'underscore'&lt;/span&gt; consente, &lt;span style="font-weight: bold;"&gt;se la finestra del programma  unzip e' di dimensioni ridotte&lt;/span&gt;, di vedere&lt;span style="font-weight: bold;"&gt; solo la parte iniziale del nome del file&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-GLfk6B4KOpw/TvFMg2Q6DoI/AAAAAAAAmqI/FHJcBGBDHvY/s1600/zip.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 65px;" src="http://1.bp.blogspot.com/-GLfk6B4KOpw/TvFMg2Q6DoI/AAAAAAAAmqI/FHJcBGBDHvY/s320/zip.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411931551600258" border="0" /&gt;&lt;/a&gt;che risultera' cosi &lt;span style="font-weight: bold;"&gt;essere un PDF e non un eseguibile come e' in realta'.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il sito compromesso che ospita il malware&lt;/span&gt; come zip file&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-oprLZ6mvjWI/TvFLxM9uYkI/AAAAAAAAmpM/EmwZclUyrfg/s1600/home%2Bcompro%2Bita.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 183px;" src="http://2.bp.blogspot.com/-oprLZ6mvjWI/TvFLxM9uYkI/AAAAAAAAmpM/EmwZclUyrfg/s320/home%2Bcompro%2Bita.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411113011438146" border="0" /&gt;&lt;/a&gt; &lt;span style="font-weight: bold;"&gt;e' questa volta  IT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-0VK5bvXJvtM/TvFLxRdvYGI/AAAAAAAAmpY/JGHgsws9Kjs/s1600/wh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 122px;" src="http://4.bp.blogspot.com/-0VK5bvXJvtM/TvFLxRdvYGI/AAAAAAAAmpY/JGHgsws9Kjs/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411114219462754" border="0" /&gt;&lt;/a&gt;Una analisi&lt;span style="font-weight: bold;"&gt; VT mostra come, al momento, il riconoscimento del malware sia ancora estremamente basso&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-ltS_ko_7TiQ/TvFML7nqumI/AAAAAAAAmps/I66RQPPIvas/s1600/vt%2Bzip%2Brep%2B2011-12-21_081108.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 184px;" src="http://1.bp.blogspot.com/-ltS_ko_7TiQ/TvFML7nqumI/AAAAAAAAmps/I66RQPPIvas/s320/vt%2Bzip%2Brep%2B2011-12-21_081108.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411572211989090" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Anubis rivela invece come ci sia una serie di possibili download in cascata&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-yPM2TTY0zQY/TvFMg0rUN-I/AAAAAAAAmqU/MxouhSJubCw/s1600/schemam%2Bdown%2Bmalwa.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 217px;" src="http://3.bp.blogspot.com/-yPM2TTY0zQY/TvFMg0rUN-I/AAAAAAAAmqU/MxouhSJubCw/s320/schemam%2Bdown%2Bmalwa.jpg" alt="" id="BLOGGER_PHOTO_ID_5688411931125495778" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;di eseguibili malware&lt;span style="font-weight: bold;"&gt; che partendo dal primo exe presente nel link&lt;/span&gt; portano al download sul pc colpito&lt;span style="font-weight: bold;"&gt; di successivi files eseguibili spesso quasi per niente riconosciuti&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-AA_rSfgEbGY/TvFNVwzt7aI/AAAAAAAAmrE/w0hPISgs_zI/s1600/vt%2Bdownloaded%2Bfrom%2Bmalware.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 219px; height: 320px;" src="http://4.bp.blogspot.com/-AA_rSfgEbGY/TvFNVwzt7aI/AAAAAAAAmrE/w0hPISgs_zI/s320/vt%2Bdownloaded%2Bfrom%2Bmalware.jpg" alt="" id="BLOGGER_PHOTO_ID_5688412840620060066" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Ecco alcuni dettagli&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;Il file eseguibile&lt;span style="font-weight: bold;"&gt; iniziale presenta codice che scarica quando in 'run'  alcuni ulteriori eseguibili&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-gcq03eTebf4/TvFM1UYb2bI/AAAAAAAAmqg/i9P8BHe15bA/s1600/files%2Bexe%2Bdownl.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 200px;" src="http://4.bp.blogspot.com/-gcq03eTebf4/TvFM1UYb2bI/AAAAAAAAmqg/i9P8BHe15bA/s320/files%2Bexe%2Bdownl.jpg" alt="" id="BLOGGER_PHOTO_ID_5688412283233622450" border="0" /&gt;&lt;/a&gt;Tra l'altro &lt;span style="font-weight: bold;"&gt;il sito di host dei nuovi files e' ancora con whois IT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-UdRqUigPDEI/TvFM1l2SDvI/AAAAAAAAmqo/NZz7X0SEb-w/s1600/wh%2Bothers%2Bdoownloads.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://4.bp.blogspot.com/-UdRqUigPDEI/TvFM1l2SDvI/AAAAAAAAmqo/NZz7X0SEb-w/s320/wh%2Bothers%2Bdoownloads.jpg" alt="" id="BLOGGER_PHOTO_ID_5688412287922212594" border="0" /&gt;&lt;/a&gt;A loro volta gli &lt;span style="font-weight: bold;"&gt;eseguibili scaricati presentano un codice che mostra attivare una connessione a &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-y9sGz2Z5eqo/TvFNM-cX4xI/AAAAAAAAmq4/7J4i3gD8atQ/s1600/licenza%2Bexe%2Bdownload%2Bmalware.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 159px;" src="http://2.bp.blogspot.com/-y9sGz2Z5eqo/TvFNM-cX4xI/AAAAAAAAmq4/7J4i3gD8atQ/s320/licenza%2Bexe%2Bdownload%2Bmalware.jpg" alt="" id="BLOGGER_PHOTO_ID_5688412689661420306" border="0" /&gt;&lt;/a&gt;scaricando &lt;span style="font-weight: bold;"&gt;altro malware.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Si tratta di una pratica molto nota in caso di attacchi malware che evidenza come  in tempo reale possano venire variati i codici malevoli che vengono uploadati sui pc colpiti per differenti scopi che vanno dall'acquisizione di dati personali, alla creazione di reti botnet, alla proposta di falsi softwares AV.....  ecc..........&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-7890329851553757566?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/7890329851553757566/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=7890329851553757566' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7890329851553757566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7890329851553757566'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/sito-italiano-compromesso-per.html' title='Sito italiano compromesso per distribuire malware mirato ad utenti internet di lingua tedesca. Il &apos;solito&apos; file dal nome ingannevole.(21 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-PRlPj-D2n4M/TvFLw77PYRI/AAAAAAAAmpA/LyERek_g_WI/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4694764730977533093</id><published>2011-12-19T22:58:00.005+07:00</published><updated>2011-12-19T23:10:11.985+07:00</updated><title type='text'>Phishing ai danni di banche IT a diffusione prevalentemente regionale (19 dicembre)</title><content type='html'>Continuano le azioni di phishing &lt;span style="font-weight: bold;"&gt;ai danni di banche IT a diffusione regionale.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Questo un clone banca &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Monteparma&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-i-2xsc5mLJA/Tu9f7z9HoAI/AAAAAAAAmok/vHU526ywbOo/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 228px;" src="http://4.bp.blogspot.com/-i-2xsc5mLJA/Tu9f7z9HoAI/AAAAAAAAmok/vHU526ywbOo/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5687870335555706882" border="0" /&gt;&lt;/a&gt;attualmente &lt;span style="font-weight: bold;"&gt;attivo su sito thai&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-_B0Qm3Inp5I/Tu9f7sn66YI/AAAAAAAAmoY/lBg2gu7ebe4/s1600/wh%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 132px;" src="http://2.bp.blogspot.com/-_B0Qm3Inp5I/Tu9f7sn66YI/AAAAAAAAmoY/lBg2gu7ebe4/s320/wh%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5687870333587745154" border="0" /&gt;&lt;/a&gt;che presenta il solito &lt;span style="font-weight: bold;"&gt;Asset Manager Innova Studio&lt;/span&gt; raggiungibile on-line senza restrizioni ed utilizzato per uploadare i contenuti di phishing&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-1KXbOyop1c4/Tu9fneOiiFI/AAAAAAAAmoA/AtHcqEG3ru4/s1600/2011-12-asset%2Bclone%2B%2Bthai%2B19_220344.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://1.bp.blogspot.com/-1KXbOyop1c4/Tu9fneOiiFI/AAAAAAAAmoA/AtHcqEG3ru4/s320/2011-12-asset%2Bclone%2B%2Bthai%2B19_220344.jpg" alt="" id="BLOGGER_PHOTO_ID_5687869986125809746" border="0" /&gt;&lt;/a&gt;Il redirect al sito thai &lt;span style="font-weight: bold;"&gt;avviene tramite sito vietnamita gia' usato &lt;a style="color: rgb(51, 102, 255);" href="http://edetools.blogspot.com/2011/12/ritorna-il-phishing-ai-danni-di-banca.html"&gt;ed analizzato in questi giorni&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-nZKNTrxkNBc/Tut-P2D7v7I/AAAAAAAAma4/mKBLLO6LNMM/s1600/wh%2Bredir%2B2011-12-16_233505.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://4.bp.blogspot.com/-nZKNTrxkNBc/Tut-P2D7v7I/AAAAAAAAma4/mKBLLO6LNMM/s320/wh%2Bredir%2B2011-12-16_233505.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777765160533938" border="0" /&gt;&lt;/a&gt;e che vede questa volta&lt;span style="font-weight: bold;"&gt; due codici di redirect che linkano al medesimo clone&lt;/span&gt; e sempre gestiti con &lt;span style="font-weight: bold;"&gt;Asset Mananger&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-UA857gW4Yv8/Tu9gK2H4vYI/AAAAAAAAmow/WP1mdKDagsA/s1600/asset%2Bredir.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 178px;" src="http://1.bp.blogspot.com/-UA857gW4Yv8/Tu9gK2H4vYI/AAAAAAAAmow/WP1mdKDagsA/s320/asset%2Bredir.jpg" alt="" id="BLOGGER_PHOTO_ID_5687870593835777410" border="0" /&gt;&lt;/a&gt;Come si vede si  tratta di siti che sono utilizzati anche piu' volte e per   differenti attacchi considerato che, molto di rado, si provvede ad  una bonifica dei contenuti ed a un blocco della possibilita' di connettersi da remoto all'Asset Manager Innova Studio&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 102, 102);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4694764730977533093?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4694764730977533093/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4694764730977533093' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4694764730977533093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4694764730977533093'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-ai-danni-di-banche-it.html' title='Phishing ai danni di banche IT a diffusione prevalentemente regionale (19 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-i-2xsc5mLJA/Tu9f7z9HoAI/AAAAAAAAmok/vHU526ywbOo/s72-c/clone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-1480847451855075746</id><published>2011-12-19T10:19:00.008+07:00</published><updated>2011-12-19T10:43:17.209+07:00</updated><title type='text'>Phishing CartaSi con evoluto layout del clone (19 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;A parte&lt;span style="font-weight: bold;"&gt; i classici phishing PosteIT&lt;/span&gt; si puo' affermare che, attualmente, &lt;span style="font-weight: bold;"&gt; il top degli attacchi coinvolga pesantemente &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi &lt;/span&gt;&lt;/span&gt;considerato anche che passano poche ore di intervallo tra la ricezione di nuove mails fake ai danni della nota  azienda, ed anche le segnalazioni in rete sono parecchie.&lt;br /&gt;&lt;br /&gt;Si tratta di&lt;span style="font-weight: bold;"&gt; azioni di phishing che variano tra la presenza di allegati form in mail sino  a link a pagine clone&lt;/span&gt; che sfruttano le piu' diverse vulnerabilita'  per venir proposte online.&lt;br /&gt;&lt;br /&gt;Un'altra  distinzione  la possiamo fare &lt;span style="font-weight: bold;"&gt;relativamente al layout dei cloni, &lt;/span&gt;specialmente la copia fake  della&lt;span style="font-weight: bold;"&gt; homepage CartaSi&lt;/span&gt;, che propone&lt;span style="font-weight: bold;"&gt; a volte pagine 'datate' come questa di recente attacco&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-6ruZsPBdglY/TuHXiIO1CGI/AAAAAAAAmLM/aOgKXG2ceNU/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 235px;" src="http://1.bp.blogspot.com/-6ruZsPBdglY/TuHXiIO1CGI/AAAAAAAAmLM/aOgKXG2ceNU/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5684061186043480162" border="0" /&gt;&lt;/a&gt;(&lt;span style="color: rgb(204, 0, 0);"&gt;si notano date e riferimenti anche al 2010 !!&lt;/span&gt;),  sino a layout &lt;span style="font-weight: bold;"&gt;attuali con pagine che riproducono fedelmente il sito &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-r4VBdraZkdA/TtMQU7VLkQI/AAAAAAAAl9s/sDfPKqgxL_4/s1600/clone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 215px;" src="http://4.bp.blogspot.com/-r4VBdraZkdA/TtMQU7VLkQI/AAAAAAAAl9s/sDfPKqgxL_4/s320/clone.jpg" alt="" id="BLOGGER_PHOTO_ID_5679901506754285826" border="0" /&gt;&lt;/a&gt;Quello che vedremo ora e'&lt;span style="font-weight: bold;"&gt; un nuovo  clone attualmente online che raggiunge uno dei massimi gradi di corrispondenza tra sito fake e sito reale CartaSi &lt;/span&gt;attraverso l'utilizzo di &lt;span style="font-weight: bold;"&gt;frame di login incluso i&lt;/span&gt;n un  &lt;span style="font-weight: bold;"&gt;reale layout CartaSi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ecco un confronto &lt;span style="font-weight: bold;"&gt;tra il clone on-line&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-SFtpuDsxFmU/Tu6uUVCw3UI/AAAAAAAAmlk/S1X4oloCkJ8/s1600/clone%2Bregali.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 217px;" src="http://2.bp.blogspot.com/-SFtpuDsxFmU/Tu6uUVCw3UI/AAAAAAAAmlk/S1X4oloCkJ8/s320/clone%2Bregali.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675043684867394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;e &lt;span style="font-weight: bold;"&gt;il reale sito&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Z2E0Wh538Uk/Tu6uUhAWyxI/AAAAAAAAmls/GH1jVSOcEMo/s1600/reale%2Bregali.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://1.bp.blogspot.com/-Z2E0Wh538Uk/Tu6uUhAWyxI/AAAAAAAAmls/GH1jVSOcEMo/s320/reale%2Bregali.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675046895995666" border="0" /&gt;&lt;/a&gt;ed ancora questo&lt;span style="font-weight: bold;"&gt; ulteriore screenshot del clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-R7hhK3FpsSY/Tu6uUieR5CI/AAAAAAAAmmA/pJIVu6sLChg/s1600/clone%2Bface.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 214px;" src="http://4.bp.blogspot.com/-R7hhK3FpsSY/Tu6uUieR5CI/AAAAAAAAmmA/pJIVu6sLChg/s320/clone%2Bface.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675047289938978" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;ed il corrispondente reale&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-DeBc9ksULfg/Tu6uVdPMAeI/AAAAAAAAmmI/9zM0I3--0T4/s1600/reale%2Bface.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 212px;" src="http://2.bp.blogspot.com/-DeBc9ksULfg/Tu6uVdPMAeI/AAAAAAAAmmI/9zM0I3--0T4/s320/reale%2Bface.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675063064330722" border="0" /&gt;&lt;/a&gt;Come si vede&lt;span style="font-weight: bold;"&gt; una corrispondenza dei contenuti quasi perfetta.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il sistema utilizzato per  riprodurre con il massimo dettaglio la homepage &lt;span style="font-weight: bold;"&gt;CartaSi &lt;/span&gt;e' molto semplice e viene attuato attraverso&lt;span style="font-weight: bold;"&gt; questo piccolo codice&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-7wWXv0qAbRQ/Tu6vBQA1-7I/AAAAAAAAmmU/lJ-l5UXd5e0/s1600/frame%2Blogin.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 94px;" src="http://3.bp.blogspot.com/-7wWXv0qAbRQ/Tu6vBQA1-7I/AAAAAAAAmmU/lJ-l5UXd5e0/s320/frame%2Blogin.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675815428750258" border="0" /&gt;&lt;/a&gt;La parte &lt;span style="font-weight: bold; color: rgb(0, 102, 0);"&gt;evidenziata in verde&lt;/span&gt;  richiama il&lt;span style="font-weight: bold;"&gt; reale sito CartasSi&lt;/span&gt; mentre&lt;span style="font-weight: bold;"&gt; in giallo vediamo un codice di &lt;span style="color: rgb(255, 0, 0);"&gt;fake&lt;/span&gt; form di login&lt;/span&gt; (dettaglio nello screenshot)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-N9gG2xG3xZs/Tu6vBRvLl2I/AAAAAAAAmmc/5z8Er1UbAYA/s1600/codice%2Baggiunto.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 196px;" src="http://1.bp.blogspot.com/-N9gG2xG3xZs/Tu6vBRvLl2I/AAAAAAAAmmc/5z8Er1UbAYA/s320/codice%2Baggiunto.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675815891539810" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;form &lt;/span&gt;che&lt;span style="color: rgb(204, 0, 0);"&gt;, semplificando la spiegazione&lt;/span&gt;, e' per cosi'&lt;span style="font-weight: bold;"&gt; dire sovrapposto a quello reale CartaSi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Notate anche &lt;span style="font-weight: bold;"&gt;come il piccolo form di login di phishing &lt;/span&gt;necessiti del pulsante &lt;span style="color: rgb(255, 0, 0);"&gt;ENTRA&lt;/span&gt; che viene &lt;span style="font-weight: bold;"&gt;'recuperato' da un noto sito di host di immagini (Tinypic)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-mfpQ3aAF9kU/Tu6vBmoYc_I/AAAAAAAAmmo/v5Bhm0V8K10/s1600/image%2Bfro%2Btinypict.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 158px;" src="http://3.bp.blogspot.com/-mfpQ3aAF9kU/Tu6vBmoYc_I/AAAAAAAAmmo/v5Bhm0V8K10/s320/image%2Bfro%2Btinypict.jpg" alt="" id="BLOGGER_PHOTO_ID_5687675821500167154" border="0" /&gt;&lt;/a&gt;In questo modo chi &lt;span style="font-weight: bold;"&gt;aprisse il link al clone CartaS&lt;/span&gt;i si trovera' di fronte ad un pagina quasi indistinguibile dall'originale se non fosse che per &lt;span style="font-weight: bold;"&gt;l'indirizzo url che naturalmente non e' quello di CartaSi ma di un sito compromesso tedesco.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In dettaglio si tratta di sito di&lt;span style="font-weight: bold;"&gt; eCommerce  con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-cmJXnx0PyC8/Tu6vmmu35nI/AAAAAAAAmm4/hE7H2p6S-tQ/s1600/wh%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://2.bp.blogspot.com/-cmJXnx0PyC8/Tu6vmmu35nI/AAAAAAAAmm4/hE7H2p6S-tQ/s320/wh%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5687676457182553714" border="0" /&gt;&lt;/a&gt;e &lt;span style="font-weight: bold;"&gt;pesantemente compromesso&lt;/span&gt; presentando numerosi codici relativi&lt;span style="font-weight: bold;"&gt; a shells remote ed a mailer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-IVXMnPWDZcU/Tu6wDTP3mEI/AAAAAAAAmno/HH-4NRDy2Vo/s1600/mailer.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 159px;" src="http://1.bp.blogspot.com/-IVXMnPWDZcU/Tu6wDTP3mEI/AAAAAAAAmno/HH-4NRDy2Vo/s320/mailer.jpg" alt="" id="BLOGGER_PHOTO_ID_5687676950168442946" border="0" /&gt;&lt;/a&gt;e dove possiamo trovare&lt;span style="font-weight: bold;"&gt; tracce di precedenti utilizzi al riguardo di cloni&lt;span style="color: rgb(255, 0, 0);"&gt; CartaSi &lt;/span&gt;come questi kits tuttora presenti&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-6Hw9Qp1chlY/Tu6wDnBC4OI/AAAAAAAAmnw/wbkDlHcVWgc/s1600/kits.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 211px;" src="http://1.bp.blogspot.com/-6Hw9Qp1chlY/Tu6wDnBC4OI/AAAAAAAAmnw/wbkDlHcVWgc/s320/kits.jpg" alt="" id="BLOGGER_PHOTO_ID_5687676955474976994" border="0" /&gt;&lt;/a&gt;Questa &lt;span style="font-weight: bold;"&gt;la struttura del clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-G93ZYcswric/Tu6vnXf1HYI/AAAAAAAAmnY/OarzXwXISz8/s1600/stru%2Bfolder%2Bclone.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 141px;" src="http://3.bp.blogspot.com/-G93ZYcswric/Tu6vnXf1HYI/AAAAAAAAmnY/OarzXwXISz8/s320/stru%2Bfolder%2Bclone.jpg" alt="" id="BLOGGER_PHOTO_ID_5687676470272793986" border="0" /&gt;&lt;/a&gt; con i &lt;span style="font-weight: bold;"&gt;relativi codici  php di invio al phisher delle credenziali eventualmente sottratte&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-nRVGiwjH8fc/Tu6vm7eqySI/AAAAAAAAmnA/rOXXYkAQCKs/s1600/user%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://2.bp.blogspot.com/-nRVGiwjH8fc/Tu6vm7eqySI/AAAAAAAAmnA/rOXXYkAQCKs/s320/user%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5687676462751729954" border="0" /&gt;&lt;/a&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-88USlR0q9Rs/Tu6vm6iIsxI/AAAAAAAAmnQ/8Ka8QbO9OZE/s1600/pt%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 293px;" src="http://4.bp.blogspot.com/-88USlR0q9Rs/Tu6vm6iIsxI/AAAAAAAAmnQ/8Ka8QbO9OZE/s320/pt%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5687676462497837842" border="0" /&gt;&lt;/a&gt;a chi fosse caduto nel tranello del &lt;span style="font-weight: bold;"&gt;falso sito CartaSi.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-1480847451855075746?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/1480847451855075746/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=1480847451855075746' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1480847451855075746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1480847451855075746'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-cartasi-con-evoluto-layout-del.html' title='Phishing CartaSi con evoluto layout del clone (19 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-6ruZsPBdglY/TuHXiIO1CGI/AAAAAAAAmLM/aOgKXG2ceNU/s72-c/clone.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-7823460760827117274</id><published>2011-12-18T21:42:00.005+07:00</published><updated>2011-12-18T22:01:06.014+07:00</updated><title type='text'>Phishing PostePay (18 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ricevuta&lt;span style="font-weight: bold;"&gt; mail di phishing ai danni di &lt;span style="color: rgb(255, 0, 0);"&gt;PosteIT&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-D-aLiGOFNP4/Tu38MbF4AqI/AAAAAAAAmjs/k4SUEFbdQgA/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 283px;" src="http://1.bp.blogspot.com/-D-aLiGOFNP4/Tu38MbF4AqI/AAAAAAAAmjs/k4SUEFbdQgA/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5687479194799833762" border="0" /&gt;&lt;/a&gt;che vede la struttura del&lt;span style="font-weight: bold;"&gt; folder di phishing&lt;/span&gt; presentare altre al solito codice  php anche due html di cui uno solo parrebbe comunque essere utilizzato&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-YcaPolLKf1Y/Tu38MsXbV2I/AAAAAAAAmj4/4Cjn8cjjsN4/s1600/struct%2Bphishing%2Bfolder2011-12-18_200140.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 196px;" src="http://1.bp.blogspot.com/-YcaPolLKf1Y/Tu38MsXbV2I/AAAAAAAAmj4/4Cjn8cjjsN4/s320/struct%2Bphishing%2Bfolder2011-12-18_200140.jpg" alt="" id="BLOGGER_PHOTO_ID_5687479199436855138" border="0" /&gt;&lt;/a&gt;Il file con data meno recente mostra essere  debolmente offuscato ed  il codice presente non pare aver configurato un corretto indirizzo per il 'form action'&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-NDCj2ZsWK-c/Tu396Zb14jI/AAAAAAAAmkw/peqp8NhYzKE/s1600/xxxxxx.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 70px;" src="http://2.bp.blogspot.com/-NDCj2ZsWK-c/Tu396Zb14jI/AAAAAAAAmkw/peqp8NhYzKE/s320/xxxxxx.jpg" alt="" id="BLOGGER_PHOTO_ID_5687481084140708402" border="0" /&gt;&lt;/a&gt;In effetti esaminado&lt;span style="font-weight: bold;"&gt; il KIT di phishing present&lt;/span&gt;e&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Jyqnt1sVk-w/Tu38Mxl1jII/AAAAAAAAmkE/JxP6n7lKYuQ/s1600/stru%2Bw%2Bkit%2Bup%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 146px;" src="http://4.bp.blogspot.com/-Jyqnt1sVk-w/Tu38Mxl1jII/AAAAAAAAmkE/JxP6n7lKYuQ/s320/stru%2Bw%2Bkit%2Bup%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5687479200839470210" border="0" /&gt;&lt;/a&gt; &lt;span style="font-weight: bold;"&gt;troviamo identica struttura tranne che per il nome diverso del file html attivo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-QCYNJV6xijk/Tu39NgoXP_I/AAAAAAAAmkg/rii2Lv1mTx8/s1600/kit.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 63px;" src="http://1.bp.blogspot.com/-QCYNJV6xijk/Tu39NgoXP_I/AAAAAAAAmkg/rii2Lv1mTx8/s320/kit.jpg" alt="" id="BLOGGER_PHOTO_ID_5687480312978161650" border="0" /&gt;&lt;/a&gt;ed  anche in questo caso abbiamo  i due html di cui uno offuscato e non correttamente configurato&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-T94ToJ8xPpI/Tu39NXVw9gI/AAAAAAAAmkQ/dH2ri405XGM/s1600/deoff%2Bsu%2Bmalz.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 223px;" src="http://1.bp.blogspot.com/-T94ToJ8xPpI/Tu39NXVw9gI/AAAAAAAAmkQ/dH2ri405XGM/s320/deoff%2Bsu%2Bmalz.jpg" alt="" id="BLOGGER_PHOTO_ID_5687480310484235778" border="0" /&gt;&lt;/a&gt;Il link in mail punta comunque al file 'funzionante'  (html con data recente)  che sfrutta il php presente come si nota da questo screenshot&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Yh0x7XDBquM/Tu396BOUcYI/AAAAAAAAmko/ARq2E9AxY0o/s1600/php%2Bkit%2Bsource.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 183px;" src="http://4.bp.blogspot.com/-Yh0x7XDBquM/Tu396BOUcYI/AAAAAAAAmko/ARq2E9AxY0o/s320/php%2Bkit%2Bsource.jpg" alt="" id="BLOGGER_PHOTO_ID_5687481077641539970" border="0" /&gt;&lt;/a&gt;Interessante vedere una parte del source (una riga di commento in romeno piu' 4 di codice)  &lt;span style="font-weight: bold;"&gt;contrassegnata da // (commenti)  &lt;/span&gt;e quindi non eseguita e che corrisponde ad una eventuale scrittura su disco delle credenziali sottratte dal phishing.&lt;br /&gt;Si tratta un differente metodo di acquisizione dei dati di phishing  molto comune in questi casi in alternativa   od in  unione all'invio al phisher via mail delle credenziali digitate nel fake form.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Un whois&lt;/span&gt; vede il clone ospitato su server&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-IO3rdl4yqB8/Tu3-Zr3A4eI/AAAAAAAAmlA/WWY_HTqcU8U/s1600/wh%2Bserver.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://2.bp.blogspot.com/-IO3rdl4yqB8/Tu3-Zr3A4eI/AAAAAAAAmlA/WWY_HTqcU8U/s320/wh%2Bserver.jpg" alt="" id="BLOGGER_PHOTO_ID_5687481621662458338" border="0" /&gt;&lt;/a&gt;che gia' in data&lt;span style="font-weight: bold;"&gt; 16 dicembre era coinvolto in altro phishing PostePay attraverso questa mail &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-XLP5ry-foD8/Tu3-Zs189vI/AAAAAAAAmlM/bqRguMxk-L8/s1600/old%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 271px;" src="http://2.bp.blogspot.com/-XLP5ry-foD8/Tu3-Zs189vI/AAAAAAAAmlM/bqRguMxk-L8/s320/old%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5687481621926442738" border="0" /&gt;&lt;/a&gt;(testo con riferimenti a &lt;span style="font-weight: bold;"&gt;dispositivo OTP &lt;/span&gt;(one time password) ma comunque con date  al febbraio 2011) e l'utilizzo della stessa struttura di clone (compreso&lt;span style="font-weight: bold;"&gt; il file html non attivo&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-k8PXXxinrP0/Tu3-aDbrROI/AAAAAAAAmlU/qELX4eqf3b8/s1600/strumail%2Bprece.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 197px;" src="http://3.bp.blogspot.com/-k8PXXxinrP0/Tu3-aDbrROI/AAAAAAAAmlU/qELX4eqf3b8/s320/strumail%2Bprece.jpg" alt="" id="BLOGGER_PHOTO_ID_5687481627990246626" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;anche se in differente percorso&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-7823460760827117274?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/7823460760827117274/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=7823460760827117274' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7823460760827117274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/7823460760827117274'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-postepay-18-dicembre.html' title='Phishing PostePay (18 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-D-aLiGOFNP4/Tu38MbF4AqI/AAAAAAAAmjs/k4SUEFbdQgA/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-1095240277237078231</id><published>2011-12-18T16:11:00.015+07:00</published><updated>2011-12-18T17:05:54.548+07:00</updated><title type='text'>Phishing CartaSi (18 dicembre)</title><content type='html'>Continua sempre molto sostenuta &lt;span style="font-weight: bold;"&gt;la campagna di phishing ai danni di &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt;, attraverso numerose&lt;span style="font-weight: bold;"&gt; mails ricevute anche in data attuale.&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Interessante questa mai di &lt;span style="font-weight: bold;"&gt;phishing dal layout noto&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-t9252Dol9s0/Tu2vf1nyxeI/AAAAAAAAmfs/_MH6j-jUM7s/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 275px;" src="http://1.bp.blogspot.com/-t9252Dol9s0/Tu2vf1nyxeI/AAAAAAAAmfs/_MH6j-jUM7s/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5687394865943594466" border="0" /&gt;&lt;/a&gt;con headers&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-QViQKI5IC_U/Tu2vgBsinWI/AAAAAAAAmf8/nrH39_iLZDA/s1600/headers%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 57px;" src="http://2.bp.blogspot.com/-QViQKI5IC_U/Tu2vgBsinWI/AAAAAAAAmf8/nrH39_iLZDA/s320/headers%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5687394869184732514" border="0" /&gt;&lt;/a&gt;e che vede  come redirect un &lt;span style="font-weight: bold;"&gt;hosting su sito USA gia' ampiamente utilizzato in passato sia per phishing&lt;span style="color: rgb(255, 0, 0);"&gt; CartaSi&lt;/span&gt; ma anche ai danni di altre aziende IT (es &lt;span style="color: rgb(255, 0, 0);"&gt;Lottomatica&lt;/span&gt;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Esaminando il folder che contiene i &lt;span style="font-weight: bold;"&gt; files necessari al redirect&lt;/span&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-xxECt4t3-T4/Tu2vgVBjfVI/AAAAAAAAmgE/ZxM7Mi-cLnc/s1600/redirs%2Battivi.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 199px;" src="http://4.bp.blogspot.com/-xxECt4t3-T4/Tu2vgVBjfVI/AAAAAAAAmgE/ZxM7Mi-cLnc/s320/redirs%2Battivi.jpg" alt="" id="BLOGGER_PHOTO_ID_5687394874373143890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;notiamo oltre al &lt;span style="font-weight: bold;"&gt;redirect attuale (in uso)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-2uAn4v7FayE/Tu2vgjtfsPI/AAAAAAAAmgM/t9aZ5S2frYo/s1600/zxz%2Bphp%2Battuale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 64px;" src="http://1.bp.blogspot.com/-2uAn4v7FayE/Tu2vgjtfsPI/AAAAAAAAmgM/t9aZ5S2frYo/s320/zxz%2Bphp%2Battuale.jpg" alt="" id="BLOGGER_PHOTO_ID_5687394878315540722" border="0" /&gt;&lt;/a&gt;anche un  codice di redirect&lt;span style="font-weight: bold;"&gt; a precedente phishing &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-GZ4KqeVfWA0/Tu2wFwN74YI/AAAAAAAAmgc/C0CbOT7mxuw/s1600/redir%2Bro2%2Bphp%2B2011-12-18_082705.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 69px;" src="http://2.bp.blogspot.com/-GZ4KqeVfWA0/Tu2wFwN74YI/AAAAAAAAmgc/C0CbOT7mxuw/s320/redir%2Bro2%2Bphp%2B2011-12-18_082705.jpg" alt="" id="BLOGGER_PHOTO_ID_5687395517327991170" border="0" /&gt;&lt;/a&gt;e che e' attualmente &lt;span style="font-weight: bold;"&gt;ON-line e perfettamente funzionante&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-4w-RuTZSSh8/Tu2wlh5JJFI/AAAAAAAAmg0/ARk89Y-h4XQ/s1600/clone%2Brod%2B2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 206px;" src="http://3.bp.blogspot.com/-4w-RuTZSSh8/Tu2wlh5JJFI/AAAAAAAAmg0/ARk89Y-h4XQ/s320/clone%2Brod%2B2.jpg" alt="" id="BLOGGER_PHOTO_ID_5687396063238497362" border="0" /&gt;&lt;/a&gt;Interessante anche&lt;span style="font-weight: bold;"&gt; un file PHP con codice (che esamineremo in seguito nel post) &lt;/span&gt;che scrive credenziali su file testo denominato &lt;span style="font-weight: bold;"&gt;error_log&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Una analisi del contenuto denota&lt;span style="font-weight: bold;"&gt; credenziali acquisite nel mese di novembre 2011&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-WZOL-PvumAo/Tu2wXi1oIVI/AAAAAAAAmgo/H_fp9BRB2Lw/s1600/log%2Bsu%2Bold.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 298px; height: 320px;" src="http://2.bp.blogspot.com/-WZOL-PvumAo/Tu2wXi1oIVI/AAAAAAAAmgo/H_fp9BRB2Lw/s320/log%2Bsu%2Bold.jpg" alt="" id="BLOGGER_PHOTO_ID_5687395822974017874" border="0" /&gt;&lt;/a&gt;Seguendo il redirect  attuale &lt;span style="font-weight: bold;"&gt;veniamo trasferiti sul clone&lt;span style="color: rgb(255, 0, 0);"&gt; CartaSi&lt;/span&gt; (layout identico al precedente old&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-QqCYJ5p-3wk/Tu2yMGe1c7I/AAAAAAAAmhM/eZkg0E4dtHI/s1600/attuale%2Bfrommail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 208px;" src="http://1.bp.blogspot.com/-QqCYJ5p-3wk/Tu2yMGe1c7I/AAAAAAAAmhM/eZkg0E4dtHI/s320/attuale%2Bfrommail.jpg" alt="" id="BLOGGER_PHOTO_ID_5687397825406923698" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;ma con whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-w5NlBw3tQW8/Tu2wl5ono5I/AAAAAAAAmhA/XzQQ9DQH2Io/s1600/attuale%2Bro%2Bwh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://2.bp.blogspot.com/-w5NlBw3tQW8/Tu2wl5ono5I/AAAAAAAAmhA/XzQQ9DQH2Io/s320/attuale%2Bro%2Bwh.jpg" alt="" id="BLOGGER_PHOTO_ID_5687396069611643794" border="0" /&gt;&lt;/a&gt;Da notare come anche questo sito sia &lt;span style="font-weight: bold;"&gt;sviluppato in  WordPress&lt;/span&gt;, che si dimostra la piattaforma da attaccare&lt;span style="font-weight: bold;"&gt; preferita per questi phishers CartaSi.&lt;/span&gt;&lt;br /&gt;E' molto probabile che anche in questo specifico caso si sia utilizzata una nota vulnerabilita' di plugin &lt;span style="font-weight: bold;"&gt;WordPress considerato che il folder&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-6rkkhD4-YLg/Tu2yrcPOAsI/AAAAAAAAmhY/UdLv4fqXLYk/s1600/thumfolder%2Bvuln.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 219px;" src="http://3.bp.blogspot.com/-6rkkhD4-YLg/Tu2yrcPOAsI/AAAAAAAAmhY/UdLv4fqXLYk/s320/thumfolder%2Bvuln.jpg" alt="" id="BLOGGER_PHOTO_ID_5687398363822949058" border="0" /&gt;&lt;/a&gt;presenta un &lt;span style="font-weight: bold;"&gt;folder cache con un completo 'repository' di shells remote&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-jjF4EJKkPqY/Tu2yrT29CGI/AAAAAAAAmhg/fCBS-DieRQg/s1600/vslider%2Bcache%2Bbrowsabile.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 166px;" src="http://2.bp.blogspot.com/-jjF4EJKkPqY/Tu2yrT29CGI/AAAAAAAAmhg/fCBS-DieRQg/s320/vslider%2Bcache%2Bbrowsabile.jpg" alt="" id="BLOGGER_PHOTO_ID_5687398361573689442" border="0" /&gt;&lt;/a&gt;tra cui&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-ChIIRgYkw7I/Tu2ztWGZgSI/AAAAAAAAmiI/GNcSmIWZMMg/s1600/cache%2Bth%2Bnewfile%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 185px;" src="http://2.bp.blogspot.com/-ChIIRgYkw7I/Tu2ztWGZgSI/AAAAAAAAmiI/GNcSmIWZMMg/s320/cache%2Bth%2Bnewfile%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5687399496046706978" border="0" /&gt;&lt;/a&gt;ed&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-sy2XyxwstsI/Tu2ztK1HQcI/AAAAAAAAmh8/yzyhwIbT2so/s1600/cache%2Bth%2B2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 167px;" src="http://3.bp.blogspot.com/-sy2XyxwstsI/Tu2ztK1HQcI/AAAAAAAAmh8/yzyhwIbT2so/s320/cache%2Bth%2B2.jpg" alt="" id="BLOGGER_PHOTO_ID_5687399493021417922" border="0" /&gt;&lt;/a&gt;ed&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-o2z6gqYmbxY/Tu2ztFbPwZI/AAAAAAAAmhw/Y4uqCsQZKPU/s1600/cache%2Bth%2Ba%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 167px;" src="http://3.bp.blogspot.com/-o2z6gqYmbxY/Tu2ztFbPwZI/AAAAAAAAmhw/Y4uqCsQZKPU/s320/cache%2Bth%2Ba%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5687399491570745746" border="0" /&gt;&lt;/a&gt;Inoltre sono&lt;span style="font-weight: bold;"&gt; presenti alcuni codici php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-U8Y9q68ngX4/Tu23759aZEI/AAAAAAAAmic/oCZc3eDomP8/s1600/php%2Bcode%2Bcache.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 58px;" src="http://1.bp.blogspot.com/-U8Y9q68ngX4/Tu23759aZEI/AAAAAAAAmic/oCZc3eDomP8/s320/php%2Bcode%2Bcache.jpg" alt="" id="BLOGGER_PHOTO_ID_5687404144237372482" border="0" /&gt;&lt;/a&gt;che sono simili a quelli&lt;span style="font-weight: bold;"&gt; documentati in rete ed utilizzati normalmente per sfruttare vulnerabilita' &lt;/span&gt;plugin WordPress del tipo &lt;span style="font-weight: bold;"&gt;Timthumb Vulnerability&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-khavXH93p9Y/Tu2371b30WI/AAAAAAAAmiU/o1rwBfkFMOQ/s1600/timth%2Bcode%2Bexpl.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://2.bp.blogspot.com/-khavXH93p9Y/Tu2371b30WI/AAAAAAAAmiU/o1rwBfkFMOQ/s320/timth%2Bcode%2Bexpl.jpg" alt="" id="BLOGGER_PHOTO_ID_5687404143022952802" border="0" /&gt;&lt;/a&gt;Ritornando al clone da notare come&lt;span style="font-weight: bold;"&gt;  sia ospitato in un folder in compagnia di un php e di un file credenziali visti gia' in precedenza.&lt;/span&gt;&lt;span style="color: rgb(204, 0, 0);"&gt; (&lt;/span&gt;&lt;span style="font-style: italic; color: rgb(204, 0, 0);"&gt;manga.php) (.error_log&lt;/span&gt;&lt;span style="color: rgb(204, 0, 0);"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-65CVlMgFauY/Tu24aWO8gLI/AAAAAAAAmis/HywSkfYvLaw/s1600/struttura%2Bin%2Buso.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 121px;" src="http://1.bp.blogspot.com/-65CVlMgFauY/Tu24aWO8gLI/AAAAAAAAmis/HywSkfYvLaw/s320/struttura%2Bin%2Buso.jpg" alt="" id="BLOGGER_PHOTO_ID_5687404667223179442" border="0" /&gt;&lt;/a&gt;In dettaglio&lt;span style="font-weight: bold;"&gt; il php presenta&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-mhj5eXRAZic/Tu248FFuz1I/AAAAAAAAmjE/8vv0cRisBSM/s1600/manga%2Bphp%2Bnon%2Busato.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 133px;" src="http://2.bp.blogspot.com/-mhj5eXRAZic/Tu248FFuz1I/AAAAAAAAmjE/8vv0cRisBSM/s320/manga%2Bphp%2Bnon%2Busato.jpg" alt="" id="BLOGGER_PHOTO_ID_5687405246736682834" border="0" /&gt;&lt;/a&gt;e scrive un file come&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-NrYfpShHTK4/Tu24aRNEWcI/AAAAAAAAmi4/7CORtQ_sTEc/s1600/test%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 256px;" src="http://1.bp.blogspot.com/-NrYfpShHTK4/Tu24aRNEWcI/AAAAAAAAmi4/7CORtQ_sTEc/s320/test%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5687404665873127874" border="0" /&gt;&lt;/a&gt;dove troviamo &lt;span style="font-weight: bold;"&gt;attualmente un unico record con whois tedesco (test del phisher ?)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Se esaminiamo &lt;span style="font-weight: bold;"&gt;il clone in uso linkato in mail abbiamo invece questo php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-ySKbkrWv6a0/Tu25SfLdudI/AAAAAAAAmjc/_D6uAMRvEZY/s1600/go1%2Bphp%2Bfor%2Bin%2Buso.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 94px;" src="http://2.bp.blogspot.com/-ySKbkrWv6a0/Tu25SfLdudI/AAAAAAAAmjc/_D6uAMRvEZY/s320/go1%2Bphp%2Bfor%2Bin%2Buso.jpg" alt="" id="BLOGGER_PHOTO_ID_5687405631697172946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;che in dettaglio vede&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-LotdT6D-ick/Tu248UoOZnI/AAAAAAAAmjM/4vUYX8rJxjI/s1600/sen%2Bmail%2Battuale.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 210px;" src="http://3.bp.blogspot.com/-LotdT6D-ick/Tu248UoOZnI/AAAAAAAAmjM/4vUYX8rJxjI/s320/sen%2Bmail%2Battuale.jpg" alt="" id="BLOGGER_PHOTO_ID_5687405250907891314" border="0" /&gt;&lt;/a&gt;cosa che fa pensare&lt;span style="font-weight: bold;"&gt; che il php con scrittura anche su file delle credenziali al momento non venga utilizzato, almeno da questo phishing.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-1095240277237078231?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/1095240277237078231/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=1095240277237078231' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1095240277237078231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/1095240277237078231'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/phishing-cartasi-18-dicembre.html' title='Phishing CartaSi (18 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-t9252Dol9s0/Tu2vf1nyxeI/AAAAAAAAmfs/_MH6j-jUM7s/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4787592753569098331</id><published>2011-12-17T16:22:00.004+07:00</published><updated>2011-12-17T16:48:01.154+07:00</updated><title type='text'>Anche Tiscali WEB MAIL nel mirino dei phishers (17 dicembre)</title><content type='html'>Dando una occhiata ad un &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;phishing CartaSi attuale&lt;/span&gt;, segnalato da &lt;span style="font-weight: bold;"&gt;Denis Frati&lt;/span&gt;, e sempre sul medesimo sito compromesso &lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://edetools.blogspot.com/2011/12/ancora-phishing-cartasi-seconda-parte-9.html"&gt;analizzato in un precedente post&lt;/a&gt;, con sorpresa appare un folder denominato &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;Tiscali&lt;/span&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-nprj7x45JWs/Tuxfsg_fNWI/AAAAAAAAmfg/3YIUEy_M26U/s1600/tiscali.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 134px;" src="http://4.bp.blogspot.com/-nprj7x45JWs/Tuxfsg_fNWI/AAAAAAAAmfg/3YIUEy_M26U/s320/tiscali.jpg" alt="" id="BLOGGER_PHOTO_ID_5687025647837197666" border="0" /&gt;&lt;/a&gt;Si tratta di &lt;span style="font-weight: bold;"&gt;folder creato in data odierna&lt;/span&gt; che se analizzato mostra&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-wLoVxqPji5g/TuxfsY7ZstI/AAAAAAAAmfY/UbhXUDuvQfw/s1600/struct.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 119px;" src="http://1.bp.blogspot.com/-wLoVxqPji5g/TuxfsY7ZstI/AAAAAAAAmfY/UbhXUDuvQfw/s320/struct.jpg" alt="" id="BLOGGER_PHOTO_ID_5687025645672575698" border="0" /&gt;&lt;/a&gt;con online questo fake form&lt;span style="font-weight: bold;"&gt; di login &lt;span style="color: rgb(255, 0, 0);"&gt;Tiscali Mail&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-r0ds9ABgryg/Tuxfr0qZzUI/AAAAAAAAme8/lXpk6YId3pM/s1600/fake%2Blogin%2Btiscali%2B2011-12-17_160558.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 204px;" src="http://3.bp.blogspot.com/-r0ds9ABgryg/Tuxfr0qZzUI/AAAAAAAAme8/lXpk6YId3pM/s320/fake%2Blogin%2Btiscali%2B2011-12-17_160558.jpg" alt="" id="BLOGGER_PHOTO_ID_5687025635937602882" border="0" /&gt;&lt;/a&gt;con codice php come&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-zXbXHhjY4_k/TuxfsGm_ZaI/AAAAAAAAmfI/YiA3rH2YxWs/s1600/php.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 71px;" src="http://2.bp.blogspot.com/-zXbXHhjY4_k/TuxfsGm_ZaI/AAAAAAAAmfI/YiA3rH2YxWs/s320/php.jpg" alt="" id="BLOGGER_PHOTO_ID_5687025640755127714" border="0" /&gt;&lt;/a&gt;Accettando il login parrebbe&lt;span style="font-weight: bold;"&gt; generarsi questo messaggio di errore &lt;/span&gt;dovuto alla mancanza del codice linkato.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-EAyT1Yf6pBU/TuxfrgfJc3I/AAAAAAAAmew/0imCiTBV49M/s1600/error.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 136px;" src="http://2.bp.blogspot.com/-EAyT1Yf6pBU/TuxfrgfJc3I/AAAAAAAAmew/0imCiTBV49M/s320/error.jpg" alt="" id="BLOGGER_PHOTO_ID_5687025630521684850" border="0" /&gt;&lt;/a&gt;In ogni caso si tratta di un&lt;span style="font-weight: bold;"&gt; clone che potrebbe portare i phishers ad acquisire le credenziali di accesso al servizio di Tiscali Mail &lt;/span&gt;per per azioni fraudolente, invio di spam ma anche furto di dati personali eventualmente presenti nelle nostre comunicazioni e-mail.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4787592753569098331?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4787592753569098331/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4787592753569098331' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4787592753569098331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4787592753569098331'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/anche-tiscali-web-mail-nel-mirino-dei.html' title='Anche Tiscali WEB MAIL nel mirino dei phishers (17 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-nprj7x45JWs/Tuxfsg_fNWI/AAAAAAAAmfg/3YIUEy_M26U/s72-c/tiscali.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-9114977325210575056</id><published>2011-12-17T00:20:00.005+07:00</published><updated>2011-12-17T00:32:12.526+07:00</updated><title type='text'>Ritorna il phishing ai danni di Banca Monteparma (16 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Presente in rete&lt;span style="font-weight: bold;"&gt; una segnalazione di mail di phishing ai danni di&lt;span style="color: rgb(255, 0, 0);"&gt; Banca Monteparma&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Si tratta ancora una volta di phishing gestito tramite redirect che sfrutta&lt;span style="font-weight: bold;"&gt; sito compromesso vietnamita&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-nZKNTrxkNBc/Tut-P2D7v7I/AAAAAAAAma4/mKBLLO6LNMM/s1600/wh%2Bredir%2B2011-12-16_233505.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 130px;" src="http://4.bp.blogspot.com/-nZKNTrxkNBc/Tut-P2D7v7I/AAAAAAAAma4/mKBLLO6LNMM/s320/wh%2Bredir%2B2011-12-16_233505.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777765160533938" border="0" /&gt;&lt;/a&gt;con diversi &lt;span style="font-weight: bold;"&gt;Asset Manager Innova Studio disponibili on-line&lt;/span&gt; tra cui&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-xex88ggVv0s/Tut-Jf4kM3I/AAAAAAAAmZ8/Hj4peFSeEcM/s1600/asset%2Bman%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 310px;" src="http://3.bp.blogspot.com/-xex88ggVv0s/Tut-Jf4kM3I/AAAAAAAAmZ8/Hj4peFSeEcM/s320/asset%2Bman%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777656128058226" border="0" /&gt;&lt;/a&gt;e questo quello usato&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-ovDES9pom_I/Tut-JdUHMaI/AAAAAAAAmaI/UjdjemDQFNM/s1600/asset%2Bman%2B2%2Busato.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 308px; height: 320px;" src="http://2.bp.blogspot.com/-ovDES9pom_I/Tut-JdUHMaI/AAAAAAAAmaI/UjdjemDQFNM/s320/asset%2Bman%2B2%2Busato.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777655438291362" border="0" /&gt;&lt;/a&gt;che ha permesso di uploadare&lt;span style="font-weight: bold;"&gt; il codice di redirect (notare la data attuale)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-HnFPrHaGISw/Tut-KYaFhgI/AAAAAAAAmas/PXdHRRRJDSY/s1600/red%2Bcode%2Bnew%2Bhtm.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 194px;" src="http://4.bp.blogspot.com/-HnFPrHaGISw/Tut-KYaFhgI/AAAAAAAAmas/PXdHRRRJDSY/s320/red%2Bcode%2Bnew%2Bhtm.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777671301039618" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Il clone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-AwaFkVHNPBs/Tut-J30TZKI/AAAAAAAAmaY/DkYJiM5Tl3U/s1600/fake%2Blogin.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 266px;" src="http://4.bp.blogspot.com/-AwaFkVHNPBs/Tut-J30TZKI/AAAAAAAAmaY/DkYJiM5Tl3U/s320/fake%2Blogin.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777662552630434" border="0" /&gt;&lt;/a&gt;e' attualmente ospitato&lt;span style="font-weight: bold;"&gt; su server Altervista come si nota dal whois&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-Z3AjJPXy8js/Tut-1ImPtEI/AAAAAAAAmbE/OwOtqJCM0qU/s1600/alterwh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 154px;" src="http://1.bp.blogspot.com/-Z3AjJPXy8js/Tut-1ImPtEI/AAAAAAAAmbE/OwOtqJCM0qU/s320/alterwh.jpg" alt="" id="BLOGGER_PHOTO_ID_5686778405791446082" border="0" /&gt;&lt;/a&gt;Interessante utilizzare la possibilita' offerta dal&lt;span style="font-weight: bold;"&gt; servizio di registrazione di Altervista &lt;/span&gt;che permette di 'datare' la probabile&lt;span style="font-weight: bold;"&gt; registrazione del dominio utilizzato da parte del phisher&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-7cJu-Mc1TCo/Tut-KNiz3DI/AAAAAAAAmag/bHQ3XaQ9K9g/s1600/forum%2Be%2Bdatat%2Breg%2Buser%2Bph.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 133px;" src="http://1.bp.blogspot.com/-7cJu-Mc1TCo/Tut-KNiz3DI/AAAAAAAAmag/bHQ3XaQ9K9g/s320/forum%2Be%2Bdatat%2Breg%2Buser%2Bph.jpg" alt="" id="BLOGGER_PHOTO_ID_5686777668384840754" border="0" /&gt;&lt;/a&gt;Si scopre cosi' che detto dominio&lt;span style="font-weight: bold;"&gt; e' attivo gia' da qualche giorno &lt;/span&gt;e la conferma la abbiamo su un &lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://www.denisfrati.it/2011/12/15/phishing-news-40a-week/"&gt;post pubblicato da Denis Frati&lt;/a&gt; dove viene evidenziato un phishing&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;span style="color: rgb(255, 102, 102); font-weight: bold;"&gt;Banca Reale Mutua&lt;/span&gt; (portato avanti probabilmente sempre dai medesimi personaggi) la cui data di &lt;span style="font-weight: bold;"&gt;'attivazione' coincide con quella presente su Altervista &lt;/span&gt;ed il cui dominio utilizzato e' lo &lt;span style="font-weight: bold;"&gt;stesso usato oggi per il phishing&lt;span style="color: rgb(255, 0, 0);"&gt; Monteparma.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0); font-style: italic;"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-9114977325210575056?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/9114977325210575056/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=9114977325210575056' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/9114977325210575056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/9114977325210575056'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/ritorna-il-phishing-ai-danni-di-banca.html' title='Ritorna il phishing ai danni di Banca Monteparma (16 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-nZKNTrxkNBc/Tut-P2D7v7I/AAAAAAAAma4/mKBLLO6LNMM/s72-c/wh%2Bredir%2B2011-12-16_233505.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4351856409156431329</id><published>2011-12-15T20:52:00.007+07:00</published><updated>2011-12-15T21:40:20.580+07:00</updated><title type='text'>Distribuzione malware attraverso mail di spam.(15 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Si tratta di una&lt;span style="font-weight: bold;"&gt; mail segnalatami da Denis Frati,&lt;/span&gt; che punta ad &lt;span style="font-weight: bold;"&gt;exploit tramite link a codice su sito IT compromesso e serie di redirect.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il testo in mail si riferisce,&lt;span style="font-weight: bold;"&gt; peraltro in maniera molto confusa &lt;/span&gt;( e che fa pensare ad origine straniera della mail), &lt;span style="font-weight: bold;"&gt;ad un fatto di cronaca recente&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-style: italic; color: rgb(0, 51, 51); text-align: center;"&gt; “............Il sindaco di Roma ancora una volta ha inviato una lettera con proiettili   …..........  '&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt; ed e ' seguito da questo link&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-weight: bold; color: rgb(51, 102, 255); text-align: center;"&gt; hxxp: //www. nomedelsito.it/posta/&lt;span style="color: rgb(255, 102, 0);"&gt;LunaIT.php.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;Come si nota si &lt;span style="font-weight: bold;"&gt;tratta di un codice php incluso nel sito IT&lt;/span&gt; compromesso che tra l'altro presenta anche un&lt;span style="font-weight: bold;"&gt; iframe nascosto&lt;/span&gt; (che non pare piu' attivo) sula homepage, segno di precedente attacco.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-FCbOMbFsj_0/TuoCSoxaI4I/AAAAAAAAmXc/_mchOSv2GDE/s1600/1.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 132px;" src="http://1.bp.blogspot.com/-FCbOMbFsj_0/TuoCSoxaI4I/AAAAAAAAmXc/_mchOSv2GDE/s320/1.jpg" alt="" id="BLOGGER_PHOTO_ID_5686359998714225538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Il caso odierno comunque ,&lt;span style="font-weight: bold;"&gt; dal punto di vista 'operativo' assomiglia di piu' a quanto vediamo nei consueti casi di phishing con link a redirect su sito compromesso per arrivare a clone (in questo caso codice di exploit) su sito creato probabilmente solo per ospitare il malware.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-JpBw-mnbkz4/TuoCSrRgo4I/AAAAAAAAmXk/N_gt2iYD61o/s1600/2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 114px;" src="http://3.bp.blogspot.com/-JpBw-mnbkz4/TuoCSrRgo4I/AAAAAAAAmXk/N_gt2iYD61o/s320/2.jpg" alt="" id="BLOGGER_PHOTO_ID_5686359999385740162" border="0" /&gt;&lt;/a&gt;Il php &lt;span style="font-weight: bold;"&gt;LunaIT.php.&lt;/span&gt; Redirige infatti&lt;span style="font-weight: bold;"&gt; su sito compromesso di OSCommerce con whois USA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-k3Pi7YxcIFU/TuoCSwiX69I/AAAAAAAAmX0/mm_a4au_ojU/s1600/3.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 169px;" src="http://3.bp.blogspot.com/-k3Pi7YxcIFU/TuoCSwiX69I/AAAAAAAAmX0/mm_a4au_ojU/s320/3.jpg" alt="" id="BLOGGER_PHOTO_ID_5686360000798649298" border="0" /&gt;&lt;/a&gt;che punta a sua&lt;span style="font-weight: bold;"&gt; volta a sito con whois ukraino&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-OsKm--5eFZo/TuoDpP6RTAI/AAAAAAAAmYo/7EMERKHjxW4/s1600/6.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 149px;" src="http://2.bp.blogspot.com/-OsKm--5eFZo/TuoDpP6RTAI/AAAAAAAAmYo/7EMERKHjxW4/s320/6.jpg" alt="" id="BLOGGER_PHOTO_ID_5686361486689127426" border="0" /&gt;&lt;/a&gt;creato di recente&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-bckGja05hMQ/TuoCTiDYb5I/AAAAAAAAmYM/hMmGWhh0-K4/s1600/5.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 224px;" src="http://3.bp.blogspot.com/-bckGja05hMQ/TuoCTiDYb5I/AAAAAAAAmYM/hMmGWhh0-K4/s320/5.jpg" alt="" id="BLOGGER_PHOTO_ID_5686360014090432402" border="0" /&gt;&lt;/a&gt;La particolarita' e' che &lt;span style="font-weight: bold;"&gt;occorre il corretto referrer &lt;/span&gt;(in questo caso il domino che effettua il redirect) &lt;span style="font-weight: bold;"&gt;per visualizzare il codice offuscato malevolo:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-V_VQf36pLNI/TuoDPLT3JVI/AAAAAAAAmYc/UeQO0Mbqm-8/s1600/4.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 144px;" src="http://4.bp.blogspot.com/-V_VQf36pLNI/TuoDPLT3JVI/AAAAAAAAmYc/UeQO0Mbqm-8/s320/4.jpg" alt="" id="BLOGGER_PHOTO_ID_5686361038777689426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Si tratta di&lt;span style="font-weight: bold;"&gt; codice offuscato abbastanza complesso&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-gAekongyImc/TuoDpffrPuI/AAAAAAAAmY0/yNzSPA58Jnw/s1600/obfuscaedcode.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 293px;" src="http://1.bp.blogspot.com/-gAekongyImc/TuoDpffrPuI/AAAAAAAAmY0/yNzSPA58Jnw/s320/obfuscaedcode.jpg" alt="" id="BLOGGER_PHOTO_ID_5686361490872549090" border="0" /&gt;&lt;/a&gt;e che  viene &lt;span style="font-weight: bold;"&gt;modificato ad ogni ulteriore download come s nota da questo screenshot&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-hj2yl9aoQnU/TuoEeQlmo0I/AAAAAAAAmZY/wAeVDNGWMhc/s1600/cambia%2Boff%2Bcode.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 143px;" src="http://4.bp.blogspot.com/-hj2yl9aoQnU/TuoEeQlmo0I/AAAAAAAAmZY/wAeVDNGWMhc/s320/cambia%2Boff%2Bcode.jpg" alt="" id="BLOGGER_PHOTO_ID_5686362397403947842" border="0" /&gt;&lt;/a&gt;Il codice, de-offuscato.  mostra  analogie con altri gia' presenti in rete ed attribuibili a noto exploit.&lt;br /&gt;&lt;br /&gt;In particolare si vede come si sia posta molta cura sia nell'individuare il sistema operativo della &lt;span style="font-weight: bold;"&gt;macchina da colpire&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-YJckSYnKEGs/TuoFFH3P7kI/AAAAAAAAmZs/S3E7_KYk8Gw/s1600/os%2Bident.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 93px;" src="http://4.bp.blogspot.com/-YJckSYnKEGs/TuoFFH3P7kI/AAAAAAAAmZs/S3E7_KYk8Gw/s320/os%2Bident.jpg" alt="" id="BLOGGER_PHOTO_ID_5686363065076936258" border="0" /&gt;&lt;/a&gt;nonche' il &lt;span style="font-weight: bold;"&gt;browser usato sul pc attaccato.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-lM5_LtzDWao/TuoFFE_2ozI/AAAAAAAAmZk/t8vsuJIO7mc/s1600/browser%2Bid.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 86px;" src="http://3.bp.blogspot.com/-lM5_LtzDWao/TuoFFE_2ozI/AAAAAAAAmZk/t8vsuJIO7mc/s320/browser%2Bid.jpg" alt="" id="BLOGGER_PHOTO_ID_5686363064307721010" border="0" /&gt;&lt;/a&gt;A riprova che si tratta di una&lt;span style="font-weight: bold;"&gt; azione di distribuzione malware attiva&lt;/span&gt;, una ulteriore analisi del redirect mostra &lt;span style="font-weight: bold;"&gt;attualmente un diverso dominio rispetto a quello linkato ieri,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-KkwTw6TFm3g/TuoEeJINuvI/AAAAAAAAmZI/RB9d3yuR9Jw/s1600/10.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 267px;" src="http://2.bp.blogspot.com/-KkwTw6TFm3g/TuoEeJINuvI/AAAAAAAAmZI/RB9d3yuR9Jw/s320/10.jpg" alt="" id="BLOGGER_PHOTO_ID_5686362395401632498" border="0" /&gt;&lt;/a&gt; sempre su medesimo &lt;span style="font-style: italic;"&gt;hoster ukraino , ma creato in data piu' recente.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Wimj6V5p8YA/TuoEeDC3SBI/AAAAAAAAmZA/-bpNsCnppcg/s1600/8.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 174px;" src="http://4.bp.blogspot.com/-Wimj6V5p8YA/TuoEeDC3SBI/AAAAAAAAmZA/-bpNsCnppcg/s320/8.jpg" alt="" id="BLOGGER_PHOTO_ID_5686362393768577042" border="0" /&gt;&lt;/a&gt;Un po come succede&lt;span style="font-weight: bold;"&gt; per il phishing ai danni di banche,&lt;/span&gt; le continue modifiche degli indirizzi al malware e del codice malevolo sono eseguite per&lt;span style="font-weight: bold;"&gt; evitare eventuali blacklist dei domini malevoli e aumentare la difficolta' di riconoscimento dei codici pericolosi da parte dei softwares AV.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-4351856409156431329?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/4351856409156431329/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=4351856409156431329' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4351856409156431329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/4351856409156431329'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/distribuzione-malware-attraverso-mail.html' title='Distribuzione malware attraverso mail di spam.(15 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-FCbOMbFsj_0/TuoCSoxaI4I/AAAAAAAAmXc/_mchOSv2GDE/s72-c/1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-6339304090504570549</id><published>2011-12-15T10:32:00.006+07:00</published><updated>2011-12-15T10:50:22.076+07:00</updated><title type='text'>'Berlusconi non ha potuto nascondere queste foto'  Un'altro spam pericoloso (15 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;AVVISO    IMPORTANTE!     Ricordo che anche se alcuni links sono lasciati in    chiaro  negli    screenshot, evitate di visitare i siti elencati se non    avete preso     tutte le precauzioni del caso ! Si tratta di  pagine e   siti  che distribuiscono eseguibili MALWARE a volte anche poco  riconosciuti dai    software AV.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Bell'esempio di &lt;span style="font-weight: bold;"&gt;spam ingannevole&lt;/span&gt; attraverso questa attuale mail&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-F-G5ffiPuac/TulqzBS1Q3I/AAAAAAAAmU8/pIHuX7tT1dw/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 138px;" src="http://1.bp.blogspot.com/-F-G5ffiPuac/TulqzBS1Q3I/AAAAAAAAmU8/pIHuX7tT1dw/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5686193429285258098" border="0" /&gt;&lt;/a&gt;relativa a&lt;span style="font-weight: bold;"&gt; recenti fatti di cronaca  con testo ed allegato che tentano di indurre a cliccare sul file mascherato da immagine jpg.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;L'archivio zip&lt;/span&gt; contiene un file con  nome, fake estensione jpg&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;  e lunga serie di caratteri underscore&lt;/span&gt; che, se la finestra &lt;span style="font-weight: bold;"&gt;del programma e' dimensionata in maniera ridotta&lt;/span&gt;,&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-NHZWeXDvVm0/TulqzfCynLI/AAAAAAAAmVI/UZCOmTUwu2Y/s1600/short%2Bzip.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 71px;" src="http://3.bp.blogspot.com/-NHZWeXDvVm0/TulqzfCynLI/AAAAAAAAmVI/UZCOmTUwu2Y/s320/short%2Bzip.jpg" alt="" id="BLOGGER_PHOTO_ID_5686193437271039154" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;nascondono la reale natura di eseguibile exe del file.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Questa invece la&lt;span style="font-weight: bold;"&gt; finestra del programma con evidenziato l'intero nome del file&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-R-uO6kqKtJ0/Tulqzg5BrGI/AAAAAAAAmVU/56isQk-sLl0/s1600/long%2Bzip.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 46px;" src="http://3.bp.blogspot.com/-R-uO6kqKtJ0/Tulqzg5BrGI/AAAAAAAAmVU/56isQk-sLl0/s320/long%2Bzip.jpg" alt="" id="BLOGGER_PHOTO_ID_5686193437766954082" border="0" /&gt;&lt;/a&gt;Una analisi del file attraverso virus total mostra la natura malevola del file e come successo altre volte  qualche &lt;span style="font-weight: bold;"&gt;differenza tra risposta AV se si analizza il file 'zippato'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-TBNTnootRrY/TulrXvGhwgI/AAAAAAAAmWE/RkeS_-kVhOo/s1600/vt%2Bxip%2Btop.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 70px;" src="http://3.bp.blogspot.com/-TBNTnootRrY/TulrXvGhwgI/AAAAAAAAmWE/RkeS_-kVhOo/s320/vt%2Bxip%2Btop.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194060056969730" border="0" /&gt;&lt;/a&gt;&lt;a href="http://4.bp.blogspot.com/-aOqp1_4qJSA/TulrXUmXhTI/AAAAAAAAmV8/cz3HK2F0Xcs/s1600/vt%2Bzip%2Breport.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 214px; height: 320px;" src="http://4.bp.blogspot.com/-aOqp1_4qJSA/TulrXUmXhTI/AAAAAAAAmV8/cz3HK2F0Xcs/s320/vt%2Bzip%2Breport.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194052942759218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;od il file estratto&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-lvNQIhhPZSs/Tulq0LwxNhI/AAAAAAAAmVc/Ya5g7P6ii_s/s1600/vt%2Bexe%2Btop.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 56px;" src="http://1.bp.blogspot.com/-lvNQIhhPZSs/Tulq0LwxNhI/AAAAAAAAmVc/Ya5g7P6ii_s/s320/vt%2Bexe%2Btop.jpg" alt="" id="BLOGGER_PHOTO_ID_5686193449275045394" border="0" /&gt;&lt;/a&gt;&lt;a href="http://1.bp.blogspot.com/-IUgoGsoleeo/Tulq0DCJl2I/AAAAAAAAmVw/fS1grXWMNN4/s1600/vt%2Bexe%2Brep.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 212px; height: 320px;" src="http://1.bp.blogspot.com/-IUgoGsoleeo/Tulq0DCJl2I/AAAAAAAAmVw/fS1grXWMNN4/s320/vt%2Bexe%2Brep.jpg" alt="" id="BLOGGER_PHOTO_ID_5686193446932027234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Per quanto si riferisce &lt;span style="font-weight: bold;"&gt;all'hosting dello zip linkato in mail&lt;/span&gt; si tratta di &lt;span style="font-weight: bold;"&gt;sito compromesso con whois spagnolo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-ruZmkjoBdA0/TulrYMr7N8I/AAAAAAAAmWg/C-FQskUCmIM/s1600/wh.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 119px;" src="http://3.bp.blogspot.com/-ruZmkjoBdA0/TulrYMr7N8I/AAAAAAAAmWg/C-FQskUCmIM/s320/wh.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194067998455746" border="0" /&gt;&lt;/a&gt;mentre analizzando&lt;span style="font-weight: bold;"&gt; il file eseguibile&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-CYjIPnKyxLE/Tulr-l-yQ_I/AAAAAAAAmXE/HfGAh4I9O_s/s1600/aniibis%2Bdownload.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 60px;" src="http://4.bp.blogspot.com/-CYjIPnKyxLE/Tulr-l-yQ_I/AAAAAAAAmXE/HfGAh4I9O_s/s320/aniibis%2Bdownload.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194727623476210" border="0" /&gt;&lt;/a&gt; si nota come lo stesso si connetta in rete &lt;span style="font-weight: bold;"&gt;una volta in 'run'  per scaricare un altro codice malevolo &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-n5dLbqDuVWA/Tulr-8Rr9tI/AAAAAAAAmXQ/EWVusi5vmAo/s1600/download%2Bwindow%2Bult%2Bmalw.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 136px;" src="http://2.bp.blogspot.com/-n5dLbqDuVWA/Tulr-8Rr9tI/AAAAAAAAmXQ/EWVusi5vmAo/s320/download%2Bwindow%2Bult%2Bmalw.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194733608335058" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;comunque ben rilevato&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-dcft-OSpD24/Tulr-Tiqr2I/AAAAAAAAmW0/85EZlze2U9M/s1600/vt%2Btop%2Bmalware%2Bdownlad.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 78px;" src="http://3.bp.blogspot.com/-dcft-OSpD24/Tulr-Tiqr2I/AAAAAAAAmW0/85EZlze2U9M/s320/vt%2Btop%2Bmalware%2Bdownlad.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194722673700706" border="0" /&gt;&lt;/a&gt;ed ancora da sito compromesso&lt;span style="font-weight: bold;"&gt; con whois spagnolo&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-Lnfz11YZigc/Tulr-H2XgdI/AAAAAAAAmWs/GIVoILagw-k/s1600/wh%2Bdownl%2Bulteriore%2Bmalw.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 140px;" src="http://3.bp.blogspot.com/-Lnfz11YZigc/Tulr-H2XgdI/AAAAAAAAmWs/GIVoILagw-k/s320/wh%2Bdownl%2Bulteriore%2Bmalw.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194719535104466" border="0" /&gt;&lt;/a&gt;Interessante anche una&lt;span style="font-weight: bold;"&gt; analisi degli  headers in mail &lt;/span&gt;che individuano un unico  IP italiano appartenente a Fastweb come &lt;span style="font-weight: bold;"&gt;probabile source dl messaggio.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-lPws_aSSRfg/TulrXnkOyFI/AAAAAAAAmWU/46bey3EMFlo/s1600/headers%2B2011-12-15_090358.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 54px;" src="http://4.bp.blogspot.com/-lPws_aSSRfg/TulrXnkOyFI/AAAAAAAAmWU/46bey3EMFlo/s320/headers%2B2011-12-15_090358.jpg" alt="" id="BLOGGER_PHOTO_ID_5686194058034071634" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-6339304090504570549?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/6339304090504570549/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=6339304090504570549' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6339304090504570549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/6339304090504570549'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/berlusconi-non-ha-potuto-nascondere.html' title='&apos;Berlusconi non ha potuto nascondere queste foto&apos;  Un&apos;altro spam pericoloso (15 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-F-G5ffiPuac/TulqzBS1Q3I/AAAAAAAAmU8/pIHuX7tT1dw/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-3173587630328334545</id><published>2011-12-14T18:01:00.006+07:00</published><updated>2011-12-14T18:31:26.853+07:00</updated><title type='text'>On-line l'ennesimo Phishing CartaSi (14 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Ricevuta fake mail ai &lt;span style="font-weight: bold;"&gt;danni di &lt;span style="color: rgb(255, 0, 0);"&gt;CartaSi&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;, &lt;/span&gt;che si dimostra, attualmente, una delle aziende piu' prese di mira dai phishers.&lt;br /&gt;Il layout e' praticamente &lt;a style="color: rgb(51, 102, 255); font-weight: bold;" href="http://edetools.blogspot.com/2011/12/phishing-cartasi-12-dicembre.html"&gt;identico a precedenti mails,&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-sYglUMfdhHA/TuiG9R7lDZI/AAAAAAAAmUA/TbX0yXAW4Ls/s1600/mail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 287px; height: 320px;" src="http://1.bp.blogspot.com/-sYglUMfdhHA/TuiG9R7lDZI/AAAAAAAAmUA/TbX0yXAW4Ls/s320/mail.jpg" alt="" id="BLOGGER_PHOTO_ID_5685942916898688402" border="0" /&gt;&lt;/a&gt; e vede come headers anche un&lt;span style="font-weight: bold;"&gt; IP  “da queste parti “&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-elp-1D8hKuI/TuiFl1qShBI/AAAAAAAAmTg/I6KlRylV0SE/s1600/headers.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 50px;" src="http://4.bp.blogspot.com/-elp-1D8hKuI/TuiFl1qShBI/AAAAAAAAmTg/I6KlRylV0SE/s320/headers.jpg" alt="" id="BLOGGER_PHOTO_ID_5685941414661358610" border="0" /&gt;&lt;/a&gt;Il link punta questa volta &lt;span style="font-weight: bold;"&gt;a sito italiano&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-D6jqV4tN9jk/TuiG9iWC5iI/AAAAAAAAmUM/dXOw-wKb0Pk/s1600/wh%2Bit.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 190px;" src="http://3.bp.blogspot.com/-D6jqV4tN9jk/TuiG9iWC5iI/AAAAAAAAmUM/dXOw-wKb0Pk/s320/wh%2Bit.jpg" alt="" id="BLOGGER_PHOTO_ID_5685942921304663586" border="0" /&gt;&lt;/a&gt; pesantemente compromesso  al punto che si possono rilevare anche da  una sommaria analisi,  &lt;span style="font-weight: bold;"&gt;parecchie shells php&lt;/span&gt;,&lt;span style="font-weight: bold;"&gt; file zippato contente una serie di pagine di pharmacy&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-JO0_rrSN1Sg/TuiF-dW4sEI/AAAAAAAAmTw/rv_6enQqh4o/s1600/pharma%2Bsemplice.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 260px;" src="http://4.bp.blogspot.com/-JO0_rrSN1Sg/TuiF-dW4sEI/AAAAAAAAmTw/rv_6enQqh4o/s320/pharma%2Bsemplice.jpg" alt="" id="BLOGGER_PHOTO_ID_5685941837634252866" border="0" /&gt;&lt;/a&gt;e relativo&lt;span style="font-weight: bold;"&gt; contenuto  estratto sul sito,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-fQY9OwVcXSQ/TuiF-TdUntI/AAAAAAAAmTo/OxNFJyyn3VA/s1600/list%2Bpharmacy%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 318px; height: 320px;" src="http://4.bp.blogspot.com/-fQY9OwVcXSQ/TuiF-TdUntI/AAAAAAAAmTo/OxNFJyyn3VA/s320/list%2Bpharmacy%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5685941834976894674" border="0" /&gt;&lt;/a&gt;Un folder&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-gkWL69OQcvE/TuiFl_BpduI/AAAAAAAAmTM/ka3pSn7s0BY/s1600/blog%2Bfolder.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 306px; height: 320px;" src="http://3.bp.blogspot.com/-gkWL69OQcvE/TuiFl_BpduI/AAAAAAAAmTM/ka3pSn7s0BY/s320/blog%2Bfolder.jpg" alt="" id="BLOGGER_PHOTO_ID_5685941417175250658" border="0" /&gt;&lt;/a&gt; con &lt;span style="font-weight: bold;"&gt;decine di pagine simili a blog utilizzate probabilmente per linkare ad altri siti di di dubbia affidabilita'&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-xNsABVQp0IE/TuiFlng4cLI/AAAAAAAAmTE/dGGlADbLdsQ/s1600/fake%2Bblog.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 170px;" src="http://1.bp.blogspot.com/-xNsABVQp0IE/TuiFlng4cLI/AAAAAAAAmTE/dGGlADbLdsQ/s320/fake%2Bblog.jpg" alt="" id="BLOGGER_PHOTO_ID_5685941410863804594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;ed inoltre sono&lt;span style="font-weight: bold;"&gt; anche presenti links a siti porno.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Chiaramente &lt;span style="font-weight: bold;"&gt;un sito compromesso e facilmente utilizzabile dai phishers come hosting del codice di redirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-b0fHzVgZx7Y/TuiH0QpEk7I/AAAAAAAAmUw/aT9m_N37JBo/s1600/code%2Bredir%2Bphp.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 318px; height: 108px;" src="http://4.bp.blogspot.com/-b0fHzVgZx7Y/TuiH0QpEk7I/AAAAAAAAmUw/aT9m_N37JBo/s320/code%2Bredir%2Bphp.jpg" alt="" id="BLOGGER_PHOTO_ID_5685943861445432242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;che punta &lt;span style="font-weight: bold;"&gt;a sito compromesso USA sviluppato in WordPress e che mostra questa struttura di folders che contiene il clone CartaSi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-atLcSWj92kc/TuiHduvIppI/AAAAAAAAmUo/MjUJzMqBZHA/s1600/clone%2Be%2Bphp%2B%2B2011-12-14_144943.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 155px;" src="http://1.bp.blogspot.com/-atLcSWj92kc/TuiHduvIppI/AAAAAAAAmUo/MjUJzMqBZHA/s320/clone%2Be%2Bphp%2B%2B2011-12-14_144943.jpg" alt="" id="BLOGGER_PHOTO_ID_5685943474386937490" border="0" /&gt;&lt;/a&gt;Questo uno dei&lt;span style="font-weight: bold;"&gt; codici php&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-1dhiNHiFjzA/TuiHdtJXXBI/AAAAAAAAmUY/i5ZEeN2aUzA/s1600/php%2Bcode%2Bsernd%2Bmail.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 142px;" src="http://4.bp.blogspot.com/-1dhiNHiFjzA/TuiHdtJXXBI/AAAAAAAAmUY/i5ZEeN2aUzA/s320/php%2Bcode%2Bsernd%2Bmail.jpg" alt="" id="BLOGGER_PHOTO_ID_5685943473960082450" border="0" /&gt;&lt;/a&gt;che redirigono al reale sito dopo aver inviato al phisher la mail con i dati    eventualmente sottratti a chi fosse caduto nel tranello della falsa mail.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(255, 0, 0);"&gt;Edgar&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2995682656102624692-3173587630328334545?l=edetools.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://edetools.blogspot.com/feeds/3173587630328334545/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2995682656102624692&amp;postID=3173587630328334545' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3173587630328334545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2995682656102624692/posts/default/3173587630328334545'/><link rel='alternate' type='text/html' href='http://edetools.blogspot.com/2011/12/on-line-lennesimo-phishing-cartasi-14.html' title='On-line l&apos;ennesimo Phishing CartaSi (14 dicembre)'/><author><name>Edgar Bangkok</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='28' height='32' src='http://bp1.blogger.com/_-6waw8mcpyI/R15kvMhRbTI/AAAAAAAADQA/qKsBYVsfOsc/S220/avatar2.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-sYglUMfdhHA/TuiG9R7lDZI/AAAAAAAAmUA/TbX0yXAW4Ls/s72-c/mail.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2995682656102624692.post-4568284808764408010</id><published>2011-12-13T18:40:00.007+07:00</published><updated>2011-12-13T18:56:24.489+07:00</updated><title type='text'>Interessante phishing Banca Antonveneta segnalato sul DB del blog (13 dicembre)</title><content type='html'>&lt;div style="text-align: justify;"&gt;Segnalato da &lt;span style="font-weight: bold;"&gt;un lettore del blog&lt;/span&gt;, che ringrazio, questo &lt;span style="font-weight: bold;"&gt;attuale phishing &lt;span style="color: rgb(255, 0, 0);"&gt; Banca Antonveneta&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-hBe2o0AjXsE/Tuc5-mKEBqI/AAAAAAAAmRw/l6EL9iCgSL4/s1600/db%2Breg.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 49px;" src="http://4.bp.blogspot.com/-hBe2o0AjXsE/Tuc5-mKEBqI/AAAAAAAAmRw/l6EL9iCgSL4/s320/db%2Breg.jpg" alt="" id="BLOGGER_PHOTO_ID_5685576802135967394" border="0" /&gt;&lt;/a&gt;Come si legge da Wikipedia al riguardo di alcune info sulla banca&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(51, 102, 102);"&gt; “ ….......attualmente, dopo la cessione alla capogruppo Monte dei Paschi di Siena delle filiali fuori dal Nord Est,  banca Antonveneta conta circa 400 sportelli....” &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;si tratta anche in questo caso  di un phishing che colpisce &lt;span style="font-weight: bold;"&gt;una banca a prevalente diffusione regionale (Nord Est Italia)&lt;/span&gt;,e che mostra, come vedremo ancora una volta, una probabile provenienza &lt;span style="font-weight: bold;"&gt;Est Europea per questo attacco..&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ecco alcuni dettagli:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Il testo della mail presenta i consueti avvisi di possibili 'blocchi' della carta di credito per evitare i quali bisognerebbe fornire i nostri i dati personali attraverso un apposito form linkato dalla mail&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;La homepage dell'indirizzo di phishing mostra&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-HmrPcmVvEIs/Tuc5_MAYp7I/AAAAAAAAmSI/Co6ITMgfu3Y/s1600/home.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 148px;" src="http://2.bp.blogspot.com/-HmrPcmVvEIs/Tuc5_MAYp7I/AAAAAAAAmSI/Co6ITMgfu3Y/s320/home.jpg" alt="" id="BLOGGER_PHOTO_ID_5685576812295923634" border="0" /&gt;&lt;/a&gt;cosa che fa pensare&lt;span style="font-weight: bold;"&gt; a dominio creato appositamente per il supporto al clone Antonveneta,&lt;/span&gt; e di cui si trova conferma &lt;span style="font-weight: bold;"&gt;in un whois che mostra data attuale di registrazione&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-7InLTzRy_dY/Tuc6JwH5VrI/AAAAAAAAmSs/F2xKH7XaI3Y/s1600/wh%2Bregistr2011-12-13_175201.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 180px;
