<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Botnet</title>
	<atom:link href="http://www.honeynet.it/category/botnet/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Tue, 10 Aug 2010 12:54:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Zbot authors forge Kaspersky Digital Signature</title>
		<link>http://www.honeynet.it/botnet/zbot-authors-forge-kaspersky-digital-signature</link>
		<comments>http://www.honeynet.it/botnet/zbot-authors-forge-kaspersky-digital-signature#comments</comments>
		<pubDate>Fri, 06 Aug 2010 07:43:00 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zbot]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=333</guid>
		<description><![CDATA[
Security researchers warn that multiple recent Zbot variants are using a forged digital signature in an attempt to bypass antivurs detection. Ironically the digital signature was copied from a ZeuS removal tool developed by Kaspersky Lab. [..] There have been isolated cases of digitally-signed malware before, but the practice never really took off, primarily because [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Security researchers warn that multiple recent Zbot variants are using a forged digital signature in an attempt to bypass antivurs detection. Ironically the digital signature was copied from a ZeuS removal tool developed by Kaspersky Lab.</p>
<p>[..]</p>
<p>There have been isolated cases of digitally-signed malware before, but the practice never really took off, primarily because malware authors believed the effort doesn&#8217;t justify the benefits.</p>
<p>[..]</p></blockquote>
<p>via <a href="http://news.softpedia.com/news/Zbot-Authors-Forge-Kaspersky-Digital-Signature-150817.shtml">Zbot Authors Forge Kaspersky Digital Signature &#8211; Copy it from ZeuZ removal tool &#8211; Softpedia</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zbot-authors-forge-kaspersky-digital-signature/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another Zeus botnet (100k bot) uncovered by Trusteer</title>
		<link>http://www.honeynet.it/botnet/another-zeus-botnet-100k-bot-uncovered-by-trusteer</link>
		<comments>http://www.honeynet.it/botnet/another-zeus-botnet-100k-bot-uncovered-by-trusteer#comments</comments>
		<pubDate>Wed, 04 Aug 2010 11:21:31 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=329</guid>
		<description><![CDATA[
Trusteer, the leading provider of secure browsing services, today announced that it has uncovered a large Zeus version 2 botnet being used to conduct financial fraud in the UK which is operated and controlled from Eastern Europe. The botnet appears to be controlling more than 100,000 infected computers, 98% of which are UK Internet users. [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Trusteer, the leading provider of secure browsing services, today announced that it has uncovered a large Zeus version 2 botnet being used to conduct financial fraud in the UK which is operated and controlled from Eastern Europe. The botnet appears to be controlling more than 100,000 infected computers, 98% of which are UK Internet users.</p></blockquote>
<p>via <a href="http://www.tmcnet.com/usubmit/-trusteer-trusteer-uncovers-zeus-botnet-that-plunders-over-/2010/08/03/4937294.htm">Trusteer: Trusteer uncovers Zeus botnet that plunders over 100,000 UK Internet user credentials</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/another-zeus-botnet-100k-bot-uncovered-by-trusteer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Zeus affiliated botnet discovered by AVG : &#8220;Mumba&#8221;</title>
		<link>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba</link>
		<comments>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:41:57 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mumba]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=327</guid>
		<description><![CDATA[
According to a newly published report by AVG, upon obtaining access to a mini ZeuS botnet dubbed Mumba, part of Avalanche group’s online operations, they found 60GB of stolen data such as, accounting details for social networking sites, banking accounts, credit card numbers and intercepted emails. via Researchers peek inside a mini ZeuS botnet, find [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>According to a newly published report by <a href="http://thompson.blog.avg.com/2010/08/todays-battle-with-cyber-criminals-is-a-bit-like-the-old-fashioned-cops-and-robbers-stories-of-years-agothe-police-were-cons.html" target="_blank">AVG</a>, upon obtaining access to a mini ZeuS botnet dubbed <a href="http://avg.typepad.com/files/revised-mumba-botnet-whitepaper_approved_yi_fv.pdf" target="_blank">Mumba</a>, part of Avalanche group’s online operations, they found 60GB of stolen data such as, accounting details for social networking sites, banking accounts, credit card numbers and intercepted emails.</p></blockquote>
<p>via <a href="http://www.zdnet.com/blog/security/researchers-peek-inside-a-mini-zeus-botnet-find-60gb-of-stolen-data/7018?tag=mantle_skin;content">Researchers peek inside a mini ZeuS botnet, find 60GB of stolen data | ZDNet</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Boss operation : Check Counterfeiting Ring &#8211; by SecureWorks</title>
		<link>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks</link>
		<comments>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:35:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Counterfeiting]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=325</guid>
		<description><![CDATA[
Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam. SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam. via Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam.  SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam.</p></blockquote>
<p>via <a href="http://www.secureworks.com/research/threats/big-boss/?threat=big-boss">Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Zbot variant discovered</title>
		<link>http://www.honeynet.it/botnet/new-zbot-variant-discovered</link>
		<comments>http://www.honeynet.it/botnet/new-zbot-variant-discovered#comments</comments>
		<pubDate>Thu, 29 Jul 2010 12:39:45 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=320</guid>
		<description><![CDATA[
SecureWorks researchers uncovered the complicated operation in April when it discovered a unique variant of the well-known Zeus Trojan that targets Windows-based PCs. In addition to stealing login credentials, the Trojan established a virtual private network VPN connection from the infected computer to a remote server using the PPTP Point-to-Point Tunneling Protocol functionality in Windows [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>SecureWorks researchers uncovered the complicated operation in April when it discovered a unique variant of the well-known Zeus Trojan that targets Windows-based PCs. In addition to stealing login credentials, the Trojan established a virtual private network VPN connection from the infected computer to a remote server using the PPTP Point-to-Point Tunneling Protocol functionality in Windows and listened to a random TCP Transmission Control Protocol port in order to serve as a SOCKS proxy.</p></blockquote>
<p>via <a href="http://news.cnet.com/8301-27080_3-20011885-245.html">Check counterfeiting using botnets and money mules | InSecurity Complex &#8211; CNET News</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zbot-variant-discovered/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mariposa botnet developers arrested in Slovenia</title>
		<link>http://www.honeynet.it/botnet/mariposa-botnet-developers-arrested-in-slovenia</link>
		<comments>http://www.honeynet.it/botnet/mariposa-botnet-developers-arrested-in-slovenia#comments</comments>
		<pubDate>Mon, 26 Jul 2010 10:52:54 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[Mariposa]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=317</guid>
		<description><![CDATA[
Slovenian police have arrested four suspects over allegations that they developed the Mariposa botnet malware. The arrests follow a joint investigation between the FBI and Slovenian police and come after the earlier arrest of three suspects in Spain, who are charged with distributing Mariposa and using it to hack into online bank accounts. via Mariposa [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Slovenian police have arrested four suspects over allegations that they developed the Mariposa botnet malware.</p>
<p>The arrests follow a joint investigation between the FBI and Slovenian police and come after the earlier arrest of three suspects in Spain, who are charged with distributing Mariposa and using it to hack into online bank accounts.</p></blockquote>
<p>via <a href="http://www.theregister.co.uk/2010/07/22/mariposa_botnet_arrests/">Mariposa botnet suspects quizzed in Slovenia • The Register</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/mariposa-botnet-developers-arrested-in-slovenia/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New New Banking Trojan 0wn two-factor auth in Belgium</title>
		<link>http://www.honeynet.it/botnet/new-new-banking-trojan-0wn-two-factor-auth-in-belgium</link>
		<comments>http://www.honeynet.it/botnet/new-new-banking-trojan-0wn-two-factor-auth-in-belgium#comments</comments>
		<pubDate>Mon, 26 Jul 2010 10:33:03 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=315</guid>
		<description><![CDATA[
Trojan horses that were planted onto the victims&#8217; computers would generate a fake error message and request that the victim re-enter the authorization code. This way, amounts up to €4,000 were transferred to money mules and thence to Eastern Europe. via Slashdot Your Rights Online Story &#124; Online Banking Trojan Stole Money From Belgians.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Trojan horses that were planted onto the victims&#8217; computers would generate a fake error message and request that the victim re-enter the authorization code. This way, amounts up to €4,000 were transferred to money mules and thence to Eastern Europe.</p></blockquote>
<p>via <a href="http://yro.slashdot.org/story/10/07/25/1954216/Online-Banking-Trojan-Stole-Money-From-Belgians?from=rss&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+Slashdot%2FslashdotIt+%28Slashdot%3A+IT%29&amp;utm_content=Google+Reader">Slashdot Your Rights Online Story | Online Banking Trojan Stole Money From Belgians</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-new-banking-trojan-0wn-two-factor-auth-in-belgium/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social networks used as C&amp;C server &#8211; Facebook?</title>
		<link>http://www.honeynet.it/botnet/social-networks-used-as-cc-server-facebook</link>
		<comments>http://www.honeynet.it/botnet/social-networks-used-as-cc-server-facebook#comments</comments>
		<pubDate>Thu, 22 Jul 2010 07:20:23 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Botnet 2.0]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=313</guid>
		<description><![CDATA[
Brazilian Banker is a financial Trojan that targets consumers of Brazilian-based banks and other banks in Latin America. The Lab recently traced a social network profile that contained encrypted instructions for a variant of the Brazilian banker Trojan via Speaking of Security&#8230; &#124; Blog Entry: RSA FraudAction Research Lab &#124; Cy: 1684. After google groups [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Brazilian Banker is a financial Trojan that targets consumers of Brazilian-based banks and other banks in Latin America. The Lab recently traced a social network profile that contained encrypted instructions for a variant of the Brazilian banker Trojan</p></blockquote>
<p>via <a href="http://rsa.com/blog/blog_entry.aspx?id=1684">Speaking of Security&#8230; | Blog Entry: RSA FraudAction Research Lab | Cy: 1684</a>.</p>
<p>After <a href="http://www.symantec.com/connect/blogs/google-groups-trojan">google groups</a> and <a href="http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/">twitter </a>, here is <a href="http://www.symantec.com/connect/blogs/trojanwhitewell-what-s-your-bot-facebook-status-today">another </a>example about how a social network  (probably Facebook)  is being (mis)used by bot headers for issuing commands to their zombies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/social-networks-used-as-cc-server-facebook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inside the Black Energy 2 Botnet</title>
		<link>http://www.honeynet.it/botnet/inside-the-black-energy-2-botnet</link>
		<comments>http://www.honeynet.it/botnet/inside-the-black-energy-2-botnet#comments</comments>
		<pubDate>Thu, 22 Jul 2010 06:54:53 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Black Energy 2]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=311</guid>
		<description><![CDATA[
Initially, the Black Energy bot was created with the aim of conducting DDoS attacks, but with the implementation of plugins in the bot’s second version, the potential of this malware family has become virtually unlimited. via Inside the Black Energy 2 Botnet &#124; threatpost. A very detailed analysis of the BE v2 bot.  Is interesting [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Initially, the Black Energy bot was created with the aim of conducting DDoS attacks, but with the implementation of plugins in the bot’s second version, the potential of this malware family has become virtually unlimited.</p></blockquote>
<p>via <a href="http://threatpost.com/en_us/blogs/inside-black-energy-2-botnet-072110">Inside the Black Energy 2 Botnet | threatpost</a>.</p>
<p>A very detailed analysis of the BE v2 bot.  Is interesting to see how the data are encrypted using the RC4 algorithm.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/inside-the-black-energy-2-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top US banks targeted by Mastercard and Visa scam</title>
		<link>http://www.honeynet.it/botnet/top-us-banks-targeted-by-mastercard-and-visa-scam</link>
		<comments>http://www.honeynet.it/botnet/top-us-banks-targeted-by-mastercard-and-visa-scam#comments</comments>
		<pubDate>Thu, 15 Jul 2010 09:19:36 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[visa]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=309</guid>
		<description><![CDATA[
Hackers have managed to copy the Verified by Visa and MasterCard SecureCode protection features in order to dupe customers at 15 top US banks, a security firm has warned. via Top US banks targeted by Mastercard and Visa scam &#124; IT PRO.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Hackers have managed to copy the Verified by Visa and MasterCard SecureCode protection features in order to dupe customers at 15 top US banks, a security firm has warned.</p></blockquote>
<p>via <a href="http://www.itpro.co.uk/625168/top-us-banks-targeted-by-mastercard-and-visa-scam">Top US banks targeted by Mastercard and Visa scam | IT PRO</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/top-us-banks-targeted-by-mastercard-and-visa-scam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
