<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Intelligence</title>
	<atom:link href="http://www.honeynet.it/category/intelligence/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>New Zeus affiliated botnet discovered by AVG : &#8220;Mumba&#8221;</title>
		<link>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba</link>
		<comments>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:41:57 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mumba]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=327</guid>
		<description><![CDATA[
According to a newly published report by AVG, upon obtaining access to a mini ZeuS botnet dubbed Mumba, part of Avalanche group’s online operations, they found 60GB of stolen data such as, accounting details for social networking sites, banking accounts, credit card numbers and intercepted emails. via Researchers peek inside a mini ZeuS botnet, find [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>According to a newly published report by <a href="http://thompson.blog.avg.com/2010/08/todays-battle-with-cyber-criminals-is-a-bit-like-the-old-fashioned-cops-and-robbers-stories-of-years-agothe-police-were-cons.html" target="_blank">AVG</a>, upon obtaining access to a mini ZeuS botnet dubbed <a href="http://avg.typepad.com/files/revised-mumba-botnet-whitepaper_approved_yi_fv.pdf" target="_blank">Mumba</a>, part of Avalanche group’s online operations, they found 60GB of stolen data such as, accounting details for social networking sites, banking accounts, credit card numbers and intercepted emails.</p></blockquote>
<p>via <a href="http://www.zdnet.com/blog/security/researchers-peek-inside-a-mini-zeus-botnet-find-60gb-of-stolen-data/7018?tag=mantle_skin;content">Researchers peek inside a mini ZeuS botnet, find 60GB of stolen data | ZDNet</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zeus-affiliated-botnet-discovered-by-avg-mumba/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Boss operation : Check Counterfeiting Ring &#8211; by SecureWorks</title>
		<link>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks</link>
		<comments>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:35:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Counterfeiting]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=325</guid>
		<description><![CDATA[
Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam. SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam. via Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam.  SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam.</p></blockquote>
<p>via <a href="http://www.secureworks.com/research/threats/big-boss/?threat=big-boss">Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus Version 3 – Hit Spain 26%, UK 22% , USA 19%</title>
		<link>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19</link>
		<comments>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19#comments</comments>
		<pubDate>Tue, 13 Jul 2010 11:34:32 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=307</guid>
		<description><![CDATA[
The latest Zeus bot configuration contains list of targeted financial institution from Spain, Germany, United Kingdom, and USA. The previous versions contains all the list of financial institutions from different countries around the world, while the new version only contains two targeted countries and currently paired as: Spain-Germany and UK-USA via Zeus Version 3 – [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The latest Zeus bot configuration contains list of targeted financial institution from Spain, Germany, United Kingdom, and USA. The previous versions contains all the list of financial institutions from different countries around the world, while the new version only contains two targeted countries and currently paired as: Spain-Germany and UK-USA</p></blockquote>
<p>via <a href="http://community.ca.com/blogs/securityadvisor/archive/2010/07/12/zeus-version-3-target-spain-germany-uk-and-usa-banks.aspx">Zeus Version 3 – Target Spain, Germany, UK, and USA Banks &#8211; CA Security Advisor Research Blog</a>.</p>
<p>According to CA , Spanish financial institutions appears to be the most targeted (26%) by this new version of ZBot.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Zeus bot targets Russian Banks</title>
		<link>http://www.honeynet.it/botnet/new-zeus-bot-targets-russian-banks</link>
		<comments>http://www.honeynet.it/botnet/new-zeus-bot-targets-russian-banks#comments</comments>
		<pubDate>Wed, 07 Jul 2010 08:02:21 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=291</guid>
		<description><![CDATA[
This is the first time I’ve seen ZeuS target Russian banks given that online banking is not so popular in Russia. I can recall a few ZeuS/ZBOT samples targeting Yandex services, but I definitely can’t recall anyone targeting MDM Bank or other online Russian banking systems. via ZeuS/ZBOT Targets Russian Banks &#124; Malware Blog &#124; [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>This is the first time I’ve seen ZeuS target Russian banks given that online banking is not so popular in Russia. I can recall a few ZeuS/ZBOT samples targeting Yandex services, but I definitely can’t recall anyone targeting MDM Bank or other online Russian banking systems.</p></blockquote>
<p>via <a href="http://blog.trendmicro.com/zeuszbot-targets-russian-banks/">ZeuS/ZBOT Targets Russian Banks | Malware Blog | Trend Micro</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/new-zeus-bot-targets-russian-banks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The rise of Regional banking Trojans</title>
		<link>http://www.honeynet.it/botnet/the-rise-of-regional-banking-trojans</link>
		<comments>http://www.honeynet.it/botnet/the-rise-of-regional-banking-trojans#comments</comments>
		<pubDate>Fri, 02 Jul 2010 06:53:02 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[Regional Banking Trojan]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=289</guid>
		<description><![CDATA[
Cybercrooks have developed regionally-targeted banking Trojans that are more likely to slip under the radar of anti-virus defences.[...] [...]Trusteer cites two pieces of regional malware targeted at UK banking consumers. Silon.var2 crops up on one in every 500 computers in the UK compared to one in 20 000 in the US. Another strain of malware [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Cybercrooks have developed regionally-targeted banking Trojans that are more likely to slip under the radar of anti-virus defences.[...]</p></blockquote>
<blockquote><p>[...]Trusteer cites two pieces of regional malware targeted at UK banking consumers. Silon.var2  crops up on one in every 500 computers in the UK compared to one in 20 000 in the US. Another strain of malware  dubbed Agent-DBJP  was found on one in 5 000 computers in the UK compared to one in 60 000 in the US[...]</p></blockquote>
<blockquote><p>[...]Unlike known malware kits such as Zeus  Torpig  and Ambler which simultaneously target hundreds of banks and enterprises around the world and are on the radar of all security vendors  regional financial malware such as Silon.var2 and Agent.DBJP are highly targeted &#8221; said Mickey Boodaei  Trusteer s chief exec.[...]</p></blockquote>
<blockquote><p>[...]Silon  DBJP  and other regional financial malware have been identified through Trusteer s Flashlight service and analysis and investigation results have been shared between participating banks ” explained Amit Klein  CTO of Trusteer. &#8220;If a bank in a specific region experiences fraud from a new piece of regional malware there is an 80 per cent chance that other banks in the same region will experience in the near future similar losses from this malware &#8221; he added.&#8221;</p></blockquote>
<p>via <a href="http://www.theregister.co.uk/2010/07/01/regional_trojan_threat/">Regional banking Trojans sneak past security defences • The Register</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/the-rise-of-regional-banking-trojans/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kraken Botnet resurrection</title>
		<link>http://www.honeynet.it/botnet/kraken-botnet-resurrection</link>
		<comments>http://www.honeynet.it/botnet/kraken-botnet-resurrection#comments</comments>
		<pubDate>Fri, 25 Jun 2010 07:26:09 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[kraken]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=283</guid>
		<description><![CDATA[
The Kraken botnet &#8212; one of the Internet&#8217;s largest and most difficult to detect in 2008 &#8212; is rearing its ugly head again. &#8230; So far, the resurrected Kraken is primarily a spam distributor, focusing most of its output on ads for male enhancement and erectile dysfunction, Royal says. The botnet&#8217;s performance is prodigious: a [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The Kraken botnet &#8212; one of the Internet&#8217;s largest and most difficult to detect in 2008 &#8212; is rearing its ugly head again.</p>
<p>&#8230;</p>
<p>So far, the resurrected Kraken is primarily a spam distributor, focusing most of its output on ads for male enhancement and erectile dysfunction, Royal says. The botnet&#8217;s performance is prodigious: a single node with a DSL-speed connection was detected sending more than 600,000 spam messages in a 24-hour period.</p>
<p>&#8230;</p>
<p>The resurrected Kraken is usually installed by another botnet, using botnet malware such as Butterfly, Royal reports. It&#8217;s not clear whether Kraken installation is handled by the same criminal group as Kraken operations, but it may be an example of specialized criminal groups working together, he suggests.</p></blockquote>
<p>via <a href="http://www.darkreading.com/vulnerability_management/security/antivirus/showArticle.jhtml?articleID=225701438&amp;cid=RSSfeed_DR_News">Kraken Botnet Making A Resurgence, Researcher Says &#8211; botnets/Security &#8211; DarkReading</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/kraken-botnet-resurrection/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Belgian pump and dump botnet</title>
		<link>http://www.honeynet.it/botnet/belgian-pump-and-dump-botnet</link>
		<comments>http://www.honeynet.it/botnet/belgian-pump-and-dump-botnet#comments</comments>
		<pubDate>Tue, 22 Jun 2010 15:46:12 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=276</guid>
		<description><![CDATA[
According to a report in Belgian newspaper De Tijd, malware has been used to compromise the online portfolios of Belgian investors. The botnet was then used to influence stock prices, making the criminals more than 100,000 Euros. The investigation has remained secret until today. “With a push of a button the botmaster instructs all the [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>According to a report in Belgian newspaper De Tijd,  malware has been used to compromise the online portfolios of Belgian investors. The botnet was then used to influence stock prices, making the criminals more than 100,000 Euros. The investigation has remained secret until today.</p></blockquote>
<blockquote><p>“<em><strong>With a push of a button the botmaster instructs all the  computers to buy or sell the same shares at the same time.</strong></em>“</p></blockquote>
<blockquote></blockquote>
<p>via <a href="http://countermeasures.trendmicro.eu/belgian-pump-and-dump-botnet/">Belgian pump and dump botnet » CounterMeasures</a>.</p>
<p>Although is an incident happened on April 2007, it should be seriously analyzed. Currently, Are the financial system&#8217;s security countermeasures so far away from 2007 ?  I think not.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/belgian-pump-and-dump-botnet/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mariposa might be Russian</title>
		<link>http://www.honeynet.it/botnet/mariposa-might-be-russian</link>
		<comments>http://www.honeynet.it/botnet/mariposa-might-be-russian#comments</comments>
		<pubDate>Fri, 04 Jun 2010 07:52:48 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Mariposa]]></category>
		<category><![CDATA[Russia]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=266</guid>
		<description><![CDATA[
Russian-born Kaspersky said the botnet “looks and smells like it was made in Russia”.“Mariposa has a way about it that I believe says it was made in Russia,” Kaspersky told Computerworld Australia.“In Russia you can buy a botnet and they will demonstrate it for you before you pay.“I think [the three arrested men] did not [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Russian-born Kaspersky said the botnet “looks and smells like it was made in Russia”.“Mariposa has a way about it that I believe says it was made in Russia,” Kaspersky told Computerworld Australia.“In Russia you can buy a botnet and they will demonstrate it for you before you pay.“I think [the three arrested men] did not know much about botnets. They just bought it and followed instructions.”Kaspersky said botnets are “out of control” in Russia. He said they said used by local businesses to attack rival companies and by criminals to launch international attacks.</p></blockquote>
<p>via <a href="http://www.computerworld.com.au/article/348923/mariposa_might_russian/?eid=-6787">Mariposa might be Russian &#8211; security, kaspersky, denial of service &#8211; Computerworld</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/mariposa-might-be-russian/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SpyEye’s &#8220;Kill Zeus&#8221; feature doesn&#8217;t work well..</title>
		<link>http://www.honeynet.it/botnet/spyeye%e2%80%99s-kill-zeus-feature-doesnt-work-well</link>
		<comments>http://www.honeynet.it/botnet/spyeye%e2%80%99s-kill-zeus-feature-doesnt-work-well#comments</comments>
		<pubDate>Tue, 27 Apr 2010 08:09:41 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[SpyEye]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=242</guid>
		<description><![CDATA[
Our analysis has shown that the kill Zeus feature seems to work on a limited number of Zeus samples. In March 2010, Symantec alone counted 9,779 new unique samples of what we call Trojan.Zbot. We estimate that only a small percentage of these samples can be successfully removed by SpyEye’s Kill Zeus feature. via Symantec [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Our analysis has shown that the kill Zeus feature seems to work on a limited number of Zeus samples. In March 2010, Symantec alone counted 9,779 new unique samples of what we call Trojan.Zbot. We estimate that only a small percentage of these samples can be successfully removed by SpyEye’s Kill Zeus feature.</p></blockquote>
<p>via <a href="http://www.symantec.com/connect/blogs/spyeye-s-kill-zeus-bark-worse-its-bite">Symantec Connect</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/spyeye%e2%80%99s-kill-zeus-feature-doesnt-work-well/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>(RBN): Hosting Ukraine Burnt Out &#124; HostExploit</title>
		<link>http://www.honeynet.it/intelligence/rbn-hosting-ukraine-burnt-out-hostexploit</link>
		<comments>http://www.honeynet.it/intelligence/rbn-hosting-ukraine-burnt-out-hostexploit#comments</comments>
		<pubDate>Tue, 30 Mar 2010 15:15:22 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[RBN]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=209</guid>
		<description><![CDATA[
Hosting UA in Odessa one of the main data centers and hosts in Ukraine is offline, due to a major fire. Figure 1 Hosting Ua &#8211; Fire &#8211; courtesy watcher.com.ua AS41665 HOSTING-AS National Hosting Provider, UAwith 144,384 IP addresses and was # 4 on the HostExploit Bad Hosts Report in December 2009 out of 34,000 [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Hosting UA in Odessa one of the main data centers and hosts in Ukraine is offline, due to a major fire.</p>
<p>Figure 1 Hosting Ua &#8211; Fire &#8211; courtesy watcher.com.ua</p>
<p>AS41665 HOSTING-AS National Hosting Provider, UAwith 144,384 IP addresses and was # 4 on the HostExploit Bad Hosts Report in December 2009 out of 34,000 ASNs (autonomous servers / hosts) compared for serving badness on the Internet</p></blockquote>
<p>via <a href="http://rbnexploit.blogspot.com/2010/03/hosting-ukraine-burnt-out-hostexploit.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+RussianBusinessNetwork+%28Russian+Business+Network%29&amp;utm_content=Google+Reader">Russian Business Network (RBN): Hosting Ukraine Burnt Out | HostExploit</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/intelligence/rbn-hosting-ukraine-burnt-out-hostexploit/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

