<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dangerous MySpace Spam</title>
	<atom:link href="http://www.spylogic.net/2008/06/dangerous-myspace-spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.spylogic.net/2008/06/dangerous-myspace-spam/</link>
	<description></description>
	<lastBuildDate>Sun, 18 Sep 2011 21:48:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tom</title>
		<link>http://www.spylogic.net/2008/06/dangerous-myspace-spam/comment-page-1/#comment-56</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 06 Jun 2008 00:28:36 +0000</pubDate>
		<guid isPermaLink="false">#comment-56</guid>
		<description>I sent this MySpace link to Tyler over at the Security Shoggoth...he does a ton of Malware analysis and tore this one apart:&lt;br /&gt;
&lt;br /&gt;
I dl&#039;d the malware and did a quick analysis. Virustotal is a little less than helpful:&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.virustotal.com/analisis/4808aefedb734a409a60e662d0a4ded1&quot; rel=&quot;nofollow&quot;&gt;http://www.virustotal.com/a...&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
but I did some rudimentary strings analysis.  Its packed with an unmodified UPX so easy to unpack.  The following URLs are in it:&lt;br /&gt;
&lt;br /&gt;
DON&#039;T GO TO THESE!&lt;br /&gt;
hxxp://mycashloads.com/newuser.php?saff=&lt;br /&gt;
hxxp://windows-privacy-protection.com/?aid=&lt;br /&gt;
&lt;br /&gt;
It also looks to be written in VB6 as I found this in it:&lt;br /&gt;
&lt;br /&gt;
C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB&lt;br /&gt;
&lt;br /&gt;
as well as some VB-related function calls.&lt;br /&gt;
&lt;br /&gt;
There were also a bunch of these types of messages:&lt;br /&gt;
&lt;br /&gt;
Your computer is infected with spyware!&lt;br /&gt;
Windows has detected spyware infection on your PC.#CR##CR#It is recommended to u&lt;br /&gt;
pdate your antispyware protection to prevent data loss. Click here to download a&lt;br /&gt;
nd install the most up-to-date antispyware for you.#CR##CR#Click here for more i&lt;br /&gt;
nformation...&lt;br /&gt;
Warning:&lt;br /&gt;
Your computer is infected with spyware!#CR#Help to protect your computer and rem&lt;br /&gt;
ove spyware!#CR##CR#Click here for more information...&amp;&lt;br /&gt;
&lt;br /&gt;
and so on.&lt;br /&gt;
&lt;br /&gt;
If I had to guess, this is a trojan downloader which would trick you into downloading rogue anti-spyware software by putting those &quot;You&#039;ve been infected&quot; messages on your system.  IMO (and from the limited stuff I&#039;ve looked at on it) its not specifically bot-related...however, the stuff it downloads might be.</description>
		<content:encoded><![CDATA[<p>I sent this MySpace link to Tyler over at the Security Shoggoth&#8230;he does a ton of Malware analysis and tore this one apart:</p>
<p>I dl&#8217;d the malware and did a quick analysis. Virustotal is a little less than helpful:</p>
<p><a href="http://www.virustotal.com/analisis/4808aefedb734a409a60e662d0a4ded1" rel="nofollow">http://www.virustotal.com/a&#8230;</a></p>
<p>but I did some rudimentary strings analysis.  Its packed with an unmodified UPX so easy to unpack.  The following URLs are in it:</p>
<p>DON&#8217;T GO TO THESE!<br />
hxxp://mycashloads.com/newuser.php?saff=<br />
hxxp://windows-privacy-protection.com/?aid=</p>
<p>It also looks to be written in VB6 as I found this in it:</p>
<p>C:\Program Files\Microsoft Visual Studio\VB98\VB6.OLB</p>
<p>as well as some VB-related function calls.</p>
<p>There were also a bunch of these types of messages:</p>
<p>Your computer is infected with spyware!<br />
Windows has detected spyware infection on your PC.#CR##CR#It is recommended to u<br />
pdate your antispyware protection to prevent data loss. Click here to download a<br />
nd install the most up-to-date antispyware for you.#CR##CR#Click here for more i<br />
nformation&#8230;<br />
Warning:<br />
Your computer is infected with spyware!#CR#Help to protect your computer and rem<br />
ove spyware!#CR##CR#Click here for more information&#8230;&amp;</p>
<p>and so on.</p>
<p>If I had to guess, this is a trojan downloader which would trick you into downloading rogue anti-spyware software by putting those &quot;You&#8217;ve been infected&quot; messages on your system.  IMO (and from the limited stuff I&#8217;ve looked at on it) its not specifically bot-related&#8230;however, the stuff it downloads might be.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: defcon</title>
		<link>http://www.spylogic.net/2008/06/dangerous-myspace-spam/comment-page-1/#comment-54</link>
		<dc:creator>defcon</dc:creator>
		<pubDate>Wed, 04 Jun 2008 08:49:24 +0000</pubDate>
		<guid isPermaLink="false">#comment-54</guid>
		<description>ha, i got an idea, imagine if these bots start grabbing legitimate pics and names from your friends list or profile and have it resend a friend request, if the profile settings are set to private, allot of things can be grabbed by google cache eh?</description>
		<content:encoded><![CDATA[<p>ha, i got an idea, imagine if these bots start grabbing legitimate pics and names from your friends list or profile and have it resend a friend request, if the profile settings are set to private, allot of things can be grabbed by google cache eh?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

