<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Italian Honey Project &#187; Report</title>
	<atom:link href="http://www.honeynet.it/category/report/feed" rel="self" type="application/rss+xml" />
	<link>http://www.honeynet.it</link>
	<description>The Italian chapter of the Honeynet Research Alliance</description>
	<lastBuildDate>Wed, 11 Jan 2012 11:44:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Comprehensive report on Botnets released by ENISA : we&#8217;ve made our contribution too</title>
		<link>http://www.honeynet.it/botnet/comprehensive-report-on-botnets-released-by-enisa-weve-made-our-contribution-too</link>
		<comments>http://www.honeynet.it/botnet/comprehensive-report-on-botnets-released-by-enisa-weve-made-our-contribution-too#comments</comments>
		<pubDate>Mon, 14 Mar 2011 17:11:04 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[The Dorothy Project]]></category>
		<category><![CDATA[The Italian Honeynet Project]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[ENISA]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=403</guid>
		<description><![CDATA[
Last week ENISA has released two interesting documents totally dedicated on the Botnet threat. We&#8217;re glad to notice that Dorothy has been mentioned in the &#8220;Botnets: Measurement, Detection, Disinfection and Defence&#8221; report These documents were also presented last week during a dedicated workshop hosted in Cologne, where different experts from various sectors has attended the [...]
]]></description>
			<content:encoded><![CDATA[<p>Last week <a href="http://www.enisa.europa.eu/">ENISA</a> has released <a href="http://www.enisa.europa.eu/act/res/botnets">two</a> interesting documents totally dedicated on the Botnet threat.<br />
We&#8217;re glad to notice that Dorothy has been mentioned in the  &#8220;Botnets: Measurement, Detection, Disinfection and Defence&#8221; report <img src='http://www.honeynet.it/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>These documents were also presented last week during a dedicated workshop hosted in Cologne, where different experts from various sectors has attended the event.  </p>
<pre>
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/comprehensive-report-on-botnets-released-by-enisa-weve-made-our-contribution-too/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dorothy @APWG in Dallas</title>
		<link>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas</link>
		<comments>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas#comments</comments>
		<pubDate>Thu, 14 Oct 2010 09:16:18 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Paper]]></category>
		<category><![CDATA[Project News]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[APWG]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Dorothy]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=366</guid>
		<description><![CDATA[
On next Tuesday (October 19) I&#8217;m going to present a research in progress paper that I wrote with the e-Crime team of Barcelona Digital and Marco Cremonini from Department of Information Technology of the Università degli Studi di Milano. The title of our paper is &#8220;A Framework For Financial Botnet Analysis&#8220;  and will be presented [...]
]]></description>
			<content:encoded><![CDATA[<p>On next Tuesday (October 19) I&#8217;m going to present a research in progress paper that I wrote with the e-Crime team of <a href="http://www.bdigital.org/EN/rdi/Pages/Security.aspx" target="_blank">Barcelona Digital</a> and Marco Cremonini from <a href="http://dti.unimi.it/"><em>Department of Information Technology</em></a> of the Università degli Studi di  <em>Milano.</em></p>
<p>The title of our paper is &#8220;<em>A Framework For Financial Botnet Analysis</em>&#8220;  and will be presented at the Anti Phishing Working Group (<a href="http://apwg.org/events/2010_gm.html#agenda">APWG</a>) conference that this year will be held in Dallas.  Our work  represents a research study that is still in progress that is  based on developing new detection and mitigation strategies to cope with financial botnets.</p>
<p>The proposed research partially relies on a customized version of the <em>Dorothy Framework</em> by improving its overall development status. The Italian Chapter of the <a href="http://www.honeynet.org/">Honeynet Project</a> is proud to see that its work is going to be useful also for such purpose, and this publication will encourage its future research.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/dorothy-apwg-in-dallas/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IODEF approved by IETF for e-crimes</title>
		<link>http://www.honeynet.it/report/iodef-approved-by-ietf-for-e-crimes</link>
		<comments>http://www.honeynet.it/report/iodef-approved-by-ietf-for-e-crimes#comments</comments>
		<pubDate>Mon, 04 Oct 2010 07:54:09 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[legal]]></category>
		<category><![CDATA[notification]]></category>
		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=362</guid>
		<description><![CDATA[
The Internet Engineering Task Force IETF approved a customized version of the XML-based Instant Object Description Exchange Format IODEF. Extensions have been added to it that are appropriate for creating standard e-crime reports. The format allows for unambiguous time stamps, support for different languages and a feature to attach samples of malicious code. It solves [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The Internet Engineering Task Force IETF approved a customized version of the XML-based Instant Object Description Exchange Format IODEF. Extensions have been added to it that are appropriate for creating standard e-crime reports.</p>
<p>The format allows for unambiguous time stamps, support for different languages and a feature to attach samples of malicious code. It solves the problem facing the security industry of inconsistent reports, which make it harder to spot trends and react faster. [..]</p></blockquote>
<p>via <a href="http://www.computerworld.com/s/article/9186778/IETF_approves_e_crime_reporting_format">IETF approves e-crime reporting format &#8211; Computerworld</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/report/iodef-approved-by-ietf-for-e-crimes/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus (1.2.7.19) toolkit analysis</title>
		<link>http://www.honeynet.it/botnet/zeus-1-2-7-19-toolkit-analysis</link>
		<comments>http://www.honeynet.it/botnet/zeus-1-2-7-19-toolkit-analysis#comments</comments>
		<pubDate>Mon, 20 Sep 2010 13:27:59 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=354</guid>
		<description><![CDATA[
[..] Over the years Zeus has been released in a lot of different versions, adding or changing functionality, and is highly flexible in it’s configuration so this is just a snapshot of one version (1.2.7.19), giving an overview of it’s functionality. In the early part of this blog I will disclose the process involved in [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p><em>[..]</em></p>
<p>Over the years Zeus has been released in a lot of different versions, adding or changing functionality, and is highly flexible in it’s configuration so this is just a snapshot of one version (1.2.7.19), giving an overview of it’s functionality.</p>
<p>In the early part of this blog I will disclose the process involved in building and distributing Zeus botnet in the wild. In the later part, I will discuss how Zeus captures personal information by injecting code dynamically, and finally some thoughts on Command and Control.</p>
<p><em>[..]</em></p></blockquote>
<p>via <a href="http://www.avertlabs.com/research/blog/index.php/2010/09/20/zeus-crimeware-toolkit/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+McafeeAvertLabsBlog+%28McAfee+Avert+Labs+Blog%29">Computer Security Research &#8211; McAfee Labs Blog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-1-2-7-19-toolkit-analysis/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Boss operation : Check Counterfeiting Ring &#8211; by SecureWorks</title>
		<link>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks</link>
		<comments>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:35:08 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Counterfeiting]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=325</guid>
		<description><![CDATA[
Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam. SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam. via Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks.
]]></description>
			<content:encoded><![CDATA[<blockquote><p>Three-month-long investigation by CTU uncovers inner workings of Russian check counterfeiting operation. SecureWorks has notified and is working with law enforcement on this scam.  SecureWorks has protections in place for both the Zeus and the Gozi Trojans which are utilized in this scam.</p></blockquote>
<p>via <a href="http://www.secureworks.com/research/threats/big-boss/?threat=big-boss">Big Boss Check Counterfeiting Ring &#8211; Research &#8211; SecureWorks</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/big-boss-operation-check-counterfeiting-ring-by-secureworks/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus Version 3 – Hit Spain 26%, UK 22% , USA 19%</title>
		<link>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19</link>
		<comments>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19#comments</comments>
		<pubDate>Tue, 13 Jul 2010 11:34:32 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=307</guid>
		<description><![CDATA[
The latest Zeus bot configuration contains list of targeted financial institution from Spain, Germany, United Kingdom, and USA. The previous versions contains all the list of financial institutions from different countries around the world, while the new version only contains two targeted countries and currently paired as: Spain-Germany and UK-USA via Zeus Version 3 – [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>The latest Zeus bot configuration contains list of targeted financial institution from Spain, Germany, United Kingdom, and USA. The previous versions contains all the list of financial institutions from different countries around the world, while the new version only contains two targeted countries and currently paired as: Spain-Germany and UK-USA</p></blockquote>
<p>via <a href="http://community.ca.com/blogs/securityadvisor/archive/2010/07/12/zeus-version-3-target-spain-germany-uk-and-usa-banks.aspx">Zeus Version 3 – Target Spain, Germany, UK, and USA Banks &#8211; CA Security Advisor Research Blog</a>.</p>
<p>According to CA , Spanish financial institutions appears to be the most targeted (26%) by this new version of ZBot.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/zeus-version-3-%e2%80%93-hit-spain-26-uk-22-usa-19/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tequila Botnet Targets Mexican Users</title>
		<link>http://www.honeynet.it/botnet/tequila-botnet-targets-mexican-users</link>
		<comments>http://www.honeynet.it/botnet/tequila-botnet-targets-mexican-users#comments</comments>
		<pubDate>Fri, 11 Jun 2010 07:57:47 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[mexico]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=272</guid>
		<description><![CDATA[
We recently received a report of a new phishing attack that originated from Mexico. It takes advantage of the controversial news about an allegedly missing four-year-old girl, Paulette Gebara Farah, who was later found dead in her own bedroom. Users who are following the said news may fall prey to this attack by visiting the [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>We recently received a report of a new phishing attack that originated from Mexico. It takes advantage of the controversial news about an allegedly missing four-year-old girl, Paulette Gebara Farah, who was later found dead in her own bedroom.</p></blockquote>
<blockquote><p>Users who are following the said news may fall prey to this attack by visiting the page <a href="http://www.knijo.">http://www.knijo.</a>{BLOCKED}0.net/fotografias-al-desnudo-de-la-mama-de-paulette.htm, which contains an article about Paulette and claims to show nude photos of her mother. When a user accesses this page, a fake dialog box pops up and requests the user to download and install Adobe Flash Player.</p></blockquote>
<p>via <a href="http://blog.trendmicro.com/tequila-botnet-targets-mexican-users/">Tequila Botnet Targets Mexican Users | Malware Blog | Trend Micro</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/tequila-botnet-targets-mexican-users/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>At a Glance: New ZeuS Variants</title>
		<link>http://www.honeynet.it/botnet/at-a-glance-new-zeus-variants</link>
		<comments>http://www.honeynet.it/botnet/at-a-glance-new-zeus-variants#comments</comments>
		<pubDate>Tue, 27 Apr 2010 16:28:15 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=244</guid>
		<description><![CDATA[
This time, the malware upholds it notorious reputation with a new version related to previous detections TSPY_ZBOT.CRM and TSPY_ZBOT.CQJ. ZBOT variants steal account credentials when users visit various social networking, online shopping, and bank-related websites. They have rapidly become popular tools for cybercriminals to use, thanks to exceptional information-stealing routines and rootkit capabilities, which allows [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>This time, the malware upholds it notorious reputation with a new version related to previous detections TSPY_ZBOT.CRM and TSPY_ZBOT.CQJ.</p></blockquote>
<blockquote><p>ZBOT variants steal account credentials when users visit various social networking, online shopping, and bank-related websites. They have rapidly become popular tools for cybercriminals to use, thanks to exceptional information-stealing routines and rootkit capabilities, which allows them to stay stealthy and to affect users’ systems without their knowledge.</p></blockquote>
<p>via <a href="http://blog.trendmicro.com/at-a-glance-new-zeus-variants/">Trend Micro</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/at-a-glance-new-zeus-variants/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PandaLabs: 61% of new threats are banker Trojans</title>
		<link>http://www.honeynet.it/intelligence/pandalabs-61-of-new-threats-are-banker-trojans</link>
		<comments>http://www.honeynet.it/intelligence/pandalabs-61-of-new-threats-are-banker-trojans#comments</comments>
		<pubDate>Tue, 30 Mar 2010 15:12:16 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=206</guid>
		<description><![CDATA[
PandaLabs published its report analyzing the IT security events and incidents of the first three months of the year. The amount of new malware in circulation has continued to increase. In this first quarter, the most prevalent category was once again banker Trojans, accounting for 61% of all new malware. The second placed category was [...]
]]></description>
			<content:encoded><![CDATA[<blockquote><p>PandaLabs published its report analyzing the IT security events and incidents of the first three months of the year.</p>
<p>The amount of new malware in circulation has continued to increase. In this first quarter, the most prevalent category was once again banker Trojans, accounting for 61% of all new malware.</p>
<p>The second placed category was traditional viruses (15.13%) despite having practically disappeared in recent years.</p></blockquote>
<p>via <a href="http://www.net-security.org/malware_news.php?id=1276&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29&amp;utm_content=Google+Reader">61% of new threats are banker Trojans</a>.</p>
<p style="text-align: center;"><a href="http://www.net-security.org/malware_news.php?id=1276&amp;utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29&amp;utm_content=Google+Reader"><img src='http://www.honeynet.it/wp-content/uploads/q12010panda.jpg' alt='' /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/intelligence/pandalabs-61-of-new-threats-are-banker-trojans/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Report: ZeuS Banking Trojan Report</title>
		<link>http://www.honeynet.it/botnet/report-zeus-banking-trojan-report</link>
		<comments>http://www.honeynet.it/botnet/report-zeus-banking-trojan-report#comments</comments>
		<pubDate>Fri, 12 Mar 2010 08:57:58 +0000</pubDate>
		<dc:creator>marco.riccardi</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Financial Botnet]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.honeynet.it/?p=190</guid>
		<description><![CDATA[
Another Zeus Trojan report provided by SecureWorks.
]]></description>
			<content:encoded><![CDATA[<p>Another Zeus Trojan report provided by <a href="http://www.secureworks.com/research/threats/zeus/?threat=zeus">SecureWorks</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.honeynet.it/botnet/report-zeus-banking-trojan-report/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

