<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ZeuS Trojan Attack Spoofs IRS, Twitter, Youtube</title>
	<atom:link href="http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 21:31:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: CS</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-7083</link>
		<dc:creator>CS</dc:creator>
		<pubDate>Thu, 24 Jun 2010 18:47:01 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-7083</guid>
		<description>Oops, sorry about that; I must&#039;ve grabbed the wrong link. VT seems to be having some issues recently too. I was stoked when they added the comment and login features, but that seems to have only lasted about a day. Hopefully they will bring it back at some point. 

Anyway, I put up a fairly detailed post about this topic here: http://www.redcondor.com/blog/?p=246

That has the correct VT links... ;)</description>
		<content:encoded><![CDATA[<p>Oops, sorry about that; I must&#8217;ve grabbed the wrong link. VT seems to be having some issues recently too. I was stoked when they added the comment and login features, but that seems to have only lasted about a day. Hopefully they will bring it back at some point. </p>
<p>Anyway, I put up a fairly detailed post about this topic here: <a href="http://www.redcondor.com/blog/?p=246" rel="nofollow">http://www.redcondor.com/blog/?p=246</a></p>
<p>That has the correct VT links&#8230; <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7083" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7083', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7083-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7083" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7083', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7083-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-7042</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Wed, 23 Jun 2010 14:16:50 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-7042</guid>
		<description>Domain &quot;srvdll&quot; was up and down all morning today. It appears to have finally gone offline at about 10:00 (UTC -400). I know of no other active NauNet domains referencing the botnet hosting the Zeus trojan.</description>
		<content:encoded><![CDATA[<p>Domain &#8220;srvdll&#8221; was up and down all morning today. It appears to have finally gone offline at about 10:00 (UTC -400). I know of no other active NauNet domains referencing the botnet hosting the Zeus trojan.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7042" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7042', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7042-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7042" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7042', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7042-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-7036</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Wed, 23 Jun 2010 11:28:13 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-7036</guid>
		<description>Early this morning, domains &quot;msdll&quot;,  &quot;pdll&quot; and &quot;filedrv&quot; became inactive, leaving &quot;srvdll&quot; as the only NauNet active domain.</description>
		<content:encoded><![CDATA[<p>Early this morning, domains &#8220;msdll&#8221;,  &#8220;pdll&#8221; and &#8220;filedrv&#8221; became inactive, leaving &#8220;srvdll&#8221; as the only NauNet active domain.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7036" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7036', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7036-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7036" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7036', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7036-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-7020</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Tue, 22 Jun 2010 19:34:46 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-7020</guid>
		<description>The domain “srvdll” has been re-activated this afternoon. That makes at least 4 active domains referencing the fast-flux server on this botnet. So the zeus trojan is still being delivered using the IRS ‘fraud statement’ exploit and several banks are being faked.

The same ccTLD of “ru” is being used. This is still compliments of registrar “NAUNET-REG-RIPN (NauNet SP)”.

Registrar URL: http://www.naunet.ru.
Registrar Email: domreg@naunet.ru

This makes the fifth straight day that this registrar has had active domains to deliver the zeus trojan.</description>
		<content:encoded><![CDATA[<p>The domain “srvdll” has been re-activated this afternoon. That makes at least 4 active domains referencing the fast-flux server on this botnet. So the zeus trojan is still being delivered using the IRS ‘fraud statement’ exploit and several banks are being faked.</p>
<p>The same ccTLD of “ru” is being used. This is still compliments of registrar “NAUNET-REG-RIPN (NauNet SP)”.</p>
<p>Registrar URL: <a href="http://www.naunet.ru" rel="nofollow">http://www.naunet.ru</a>.<br />
Registrar Email: <a href="mailto:domreg@naunet.ru">domreg@naunet.ru</a></p>
<p>This makes the fifth straight day that this registrar has had active domains to deliver the zeus trojan.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-7020" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('7020', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-7020-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-7020" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('7020', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-7020-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-6960</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Sun, 20 Jun 2010 12:36:32 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-6960</guid>
		<description>The domain names &quot;pdll&quot; and &quot;msdll&quot; have been re-registered this morning. So the zeus trojan is still being delivered using the IRS &#039;fraud statement&#039; exploit and banks are being faked.

The same ccTLD of &quot;ru&quot; and same registrar are being used.

Registrar URL: http://www.naunet.ru.
Registrar Email: domreg@naunet.ru

It appears as long as a registrar pays their dues they are allowed to participate in internet criminal activity with no interference by any governing body.</description>
		<content:encoded><![CDATA[<p>The domain names &#8220;pdll&#8221; and &#8220;msdll&#8221; have been re-registered this morning. So the zeus trojan is still being delivered using the IRS &#8216;fraud statement&#8217; exploit and banks are being faked.</p>
<p>The same ccTLD of &#8220;ru&#8221; and same registrar are being used.</p>
<p>Registrar URL: <a href="http://www.naunet.ru" rel="nofollow">http://www.naunet.ru</a>.<br />
Registrar Email: <a href="mailto:domreg@naunet.ru">domreg@naunet.ru</a></p>
<p>It appears as long as a registrar pays their dues they are allowed to participate in internet criminal activity with no interference by any governing body.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6960" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6960', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6960-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6960" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6960', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6960-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-6939</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Fri, 18 Jun 2010 21:16:23 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-6939</guid>
		<description>They came back again this afternoon. This time the domain &quot;filedrv&quot;, same ccTLD of &quot;ru&quot;, same registrar &quot;NAUNET-REG-RIPN (NauNet SP)&quot;.

They are using a fast-flux server with 8 sites per domain. They have added BBVA bank to their American Express, Banco de Espana and IRS exploits on these sites.

Registrar URL: http://www.naunet.ru.
Registrar Email: domreg@naunet.ru</description>
		<content:encoded><![CDATA[<p>They came back again this afternoon. This time the domain &#8220;filedrv&#8221;, same ccTLD of &#8220;ru&#8221;, same registrar &#8220;NAUNET-REG-RIPN (NauNet SP)&#8221;.</p>
<p>They are using a fast-flux server with 8 sites per domain. They have added BBVA bank to their American Express, Banco de Espana and IRS exploits on these sites.</p>
<p>Registrar URL: <a href="http://www.naunet.ru" rel="nofollow">http://www.naunet.ru</a>.<br />
Registrar Email: <a href="mailto:domreg@naunet.ru">domreg@naunet.ru</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6939" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6939', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6939-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6939" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6939', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6939-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-6931</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Fri, 18 Jun 2010 19:15:49 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-6931</guid>
		<description>Thanks for the info. I got an &#039;object not found&#039; on your link, however.

I am going to have to start digging into the javascript myself. Zeus seems to be giving up on the ff botnets. Maybe just doesn&#039;t provide the level of protection they once enjoyed. They sure stopped using the 15 site ff servers referred to as &#039;avalanche&#039;. Last time I saw them use that was late february of this year. But they are still trying ff servers with 8 sites like this last exploit.</description>
		<content:encoded><![CDATA[<p>Thanks for the info. I got an &#8216;object not found&#8217; on your link, however.</p>
<p>I am going to have to start digging into the javascript myself. Zeus seems to be giving up on the ff botnets. Maybe just doesn&#8217;t provide the level of protection they once enjoyed. They sure stopped using the 15 site ff servers referred to as &#8216;avalanche&#8217;. Last time I saw them use that was late february of this year. But they are still trying ff servers with 8 sites like this last exploit.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6931" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6931', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6931-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6931" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6931', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6931-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: CS</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-6913</link>
		<dc:creator>CS</dc:creator>
		<pubDate>Fri, 18 Jun 2010 00:49:42 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-6913</guid>
		<description>I am not seeing the ff hosts being used to distribute the malware anymore either. They appear to have switched to using compromised hosts.

These campaigns using the malicious iframe have largely switched to attaching the javascript downloader directly to the spam in various forms (.html, or zipped .html) instead of having the browser fetch the downloader via an iframe in the page linked by the call-to-action url. 

Also the drop site has changed from the Canadian Pharmacy to a fake Rolex site.

Or at least this was the case as of Tuesday night; I&#039;ve been on vacation :)

One item of note that I discovered the other night was that if you deobfuscate the javascript downloader through the first level of obfuscation, VT goes from 0 detections to 3. After reversing the second layer of obfuscation to obtain the raw js, detection goes up to 13 vendors on VT. Interesting that so few AV companies can detect the fairly obvious signatures inherent in obfuscated code.

Here&#039;s my scan of the raw js:

http://www.virustotal.com/file-scan/report.html?id=667eb8fb323b390165539fd577d462576e8059272f0d7c282a87e7fe4457faa0-1276690545</description>
		<content:encoded><![CDATA[<p>I am not seeing the ff hosts being used to distribute the malware anymore either. They appear to have switched to using compromised hosts.</p>
<p>These campaigns using the malicious iframe have largely switched to attaching the javascript downloader directly to the spam in various forms (.html, or zipped .html) instead of having the browser fetch the downloader via an iframe in the page linked by the call-to-action url. </p>
<p>Also the drop site has changed from the Canadian Pharmacy to a fake Rolex site.</p>
<p>Or at least this was the case as of Tuesday night; I&#8217;ve been on vacation <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>One item of note that I discovered the other night was that if you deobfuscate the javascript downloader through the first level of obfuscation, VT goes from 0 detections to 3. After reversing the second layer of obfuscation to obtain the raw js, detection goes up to 13 vendors on VT. Interesting that so few AV companies can detect the fairly obvious signatures inherent in obfuscated code.</p>
<p>Here&#8217;s my scan of the raw js:</p>
<p><a href="http://www.virustotal.com/file-scan/report.html?id=667eb8fb323b390165539fd577d462576e8059272f0d7c282a87e7fe4457faa0-1276690545" rel="nofollow">http://www.virustotal.com/file-scan/report.html?id=667eb8fb323b390165539fd577d462576e8059272f0d7c282a87e7fe4457faa0-1276690545</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6913" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6913', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6913-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6913" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6913', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6913-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-6889</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Thu, 17 Jun 2010 06:05:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-6889</guid>
		<description>All domains referencing the fast-flux server used by the botnet to deliver the zeus trojan via the IRS scam appear to have been unregistered late last night.</description>
		<content:encoded><![CDATA[<p>All domains referencing the fast-flux server used by the botnet to deliver the zeus trojan via the IRS scam appear to have been unregistered late last night.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6889" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6889', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6889-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6889" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6889', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6889-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: JCitizen</title>
		<link>http://krebsonsecurity.com/2010/06/zeus-trojan-attack-spoofs-irs-twitter-youtube/comment-page-1/#comment-6887</link>
		<dc:creator>JCitizen</dc:creator>
		<pubDate>Thu, 17 Jun 2010 03:12:59 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=3484#comment-6887</guid>
		<description>I use this site with AdBlock Plus disabled. I want to help Brian&#039;s site anyway I can, although I wouldn&#039;t know if they really look at this.

I doubt very seriously any crackers would be attacking this page; but I got to admit, it is probably a prime target for those that don&#039;t like educated information about web criminals getting out on the internet.

I trust Brian completely.</description>
		<content:encoded><![CDATA[<p>I use this site with AdBlock Plus disabled. I want to help Brian&#8217;s site anyway I can, although I wouldn&#8217;t know if they really look at this.</p>
<p>I doubt very seriously any crackers would be attacking this page; but I got to admit, it is probably a prime target for those that don&#8217;t like educated information about web criminals getting out on the internet.</p>
<p>I trust Brian completely.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-6887" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('6887', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-6887-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-6887" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('6887', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-6887-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 3/20 queries in 0.005 seconds using memcached
Object Caching 960/971 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 19:08:55 -->
