<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; keylogger</title>
	<atom:link href="http://hijack-this.co.uk/tag/keylogger/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 01 Dec 2011 08:19:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cybercriminals Hoping You’ll Bite iPhone 5 Bait</title>
		<link>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/</link>
		<comments>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/#comments</comments>
		<pubDate>Wed, 25 May 2011 07:20:24 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Iphone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=480</guid>
		<description><![CDATA[Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5. The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. [...]]]></description>
			<content:encoded><![CDATA[<p>Online criminals know there are enough gadget hounds out there to make a scam surrounding any shiny new Apple device a surefire moneymaker. To that end, they’ve already begun sending out phishing emails for the iPhone 5.</p>
<p>The phishing emails appear to be official emails from Apple.com, with the title “Finally. The amazing iPhone 5. Now available in black edition.” The body of the message shows a hand holding a transparent iPhone, followed by an enticing offer to “check it out,” according to <a title="MacRumors" href="http://www.macrumors.com/2011/05/22/phishing-and-malware-emails-posing-as-apple-and-the-iphone-5-launch/" target="_blank">MacRumors</a>.</p>
<p>Although there’s been much speculation about the next generation iPhone, Apple has not set a release date for it. In fact, Apple hasn’t even announced it yet, but that isn’t stopping this cleverly crafted Mac-themed scam from spreading.</p>
<p>So what are you checking out when you click the link to see the new iPhone 5?</p>
<p>You won’t receive any info about the smartphone, but you will enable a rigged Windows file to run malicious code on your computer. And you’ll also be taken to a phony Apple Web page that asks for your Apple ID and other sensitive information.</p>
<p>Apple announces new products, especially ones of this magnitude, in highly publicized press conferences. So if you receive an unsolicited email purporting to have information about the new iPhone 5, ignore it, DELETE IT WITHOUT EVEN READING IT.</p>
<p>story from: <a href="http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/">http://www.securitynewsdaily.com/cybercriminals-hoping-youll-bite-iphone-5-bait-0813/</a></p>
<p>This malware is quite well detected by many antivirus companies, but not all. It is a fairly standard Zapchast IRC trojan that will attempt to download lots of other crap &amp; malware to your computer.</p>
<p>It also appears to try to  perform a DDOS flood attack against several other competing Mirc users and channels to block their channels, so no doubt will turn out to be connected to the typical fake AV scams and stealing your money</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F05%2Fcybercriminals-hoping-you%25e2%2580%2599ll-bite-iphone-5-bait%2F&amp;title=Cybercriminals%20Hoping%20You%E2%80%99ll%20Bite%20iPhone%205%20Bait" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/05/cybercriminals-hoping-you%e2%80%99ll-bite-iphone-5-bait/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware of New year e-cards</title>
		<link>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/</link>
		<comments>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 17:18:00 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=412</guid>
		<description><![CDATA[Please avoid all untrusted Happy New Year e-card links. The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs. New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0? http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230 Those of us here at Shadowserver hope you&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<p>Please avoid all untrusted Happy New Year e-card links.  The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs.</p>
<p>New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0?<br />
<a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230</a><br />
Those of us here at Shadowserver hope you&#8217;re having a wonderful holiday season and are ready to bring in the new year. We were trying to relax and enjoy relatively quiet times until we noticed a new spam campaign that recently started. At first it looked like your regular old holiday e-card scams that have been around for years. </p>
<p>However, upon closer inspection it looks like we could be dealing with the next generation of Storm Worm or Waledac. If you consider Waledac to be Storm Worm 2.0, this looks like it could be version 3.0 or at least Waledac 2.0. There are no real version numbers of course, but we don&#8217;t have anything else to call it yet. What&#8217;s it involve you ask? </p>
<p> CHARACTERISTICS OF NEW BOTNET </p>
<p>Well here&#8217;s the list of what we&#8217;ve seen so far: </p>
<p>* Large scale Spam campaigns sending out e-mails with links<br />
* New malicious domains that are fast flux! (TTL of 0 and name servers that frequently update IPs)<br />
* Links are to several hacked websites hosting HTML pages that refresh to new malicious domains<br />
* Links are also directly to new malicious domains<br />
* Malicious domains hosting links to fake flash player and refreshes to exploit pages<br />
* Malware installs that begin beaching to several hosts over HTTP (what we dubbed HTTP2p with Waledac)<br />
* Malware that&#8217;s been updated to look a bit more like legitimate than past variants<br />
* A very buggy network that is not often available (upstream devices not available)<br />
* Changing/Updated binaries</p>
<p>  AVOID THESE E-CARD MESSAGES: </p>
<p>Let&#8217;s start with the Spam Campaign. We&#8217;ve seen a multitude of subject lines and bodies. Below you&#8217;ll find a list of subjects we&#8217;ve seen and an example e-mail message. These are coming from all over the Internet with spoofed sender addresses. </p>
<p> Greeting for you!<br />
 Greeting you with heartiest New Year wishes<br />
 Greetings to You<br />
 Happy New Year greetings e-card is waiting for you<br />
 Happy New Year greetings for you<br />
 Happy New Year greetings from your friend<br />
 Have a happy and colorful New Year!<br />
 l want to share Greeting with you<br />
 New Year 2011 greetings for you<br />
 You have a greeting card<br />
 You have a New Year Greeting!<br />
 You have received a greetings card<br />
 You&#8217;ve got a Happy New Year Greeting Card!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F01%2Fbeware-of-new-year-e-cards%2F&amp;title=Beware%20of%20New%20year%20e-cards" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WOW  wowmatrix keylogger</title>
		<link>http://hijack-this.co.uk/2009/11/wow-keylogger/</link>
		<comments>http://hijack-this.co.uk/2009/11/wow-keylogger/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 11:00:42 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[games]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[world of warcraft]]></category>
		<category><![CDATA[wowmatrix]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=227</guid>
		<description><![CDATA[I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version [...]]]></description>
			<content:encoded><![CDATA[<p><br />
I was notified of a google advert for a fake wowmatrix site. The original genuine wowmatrix is seen by many games players as not completely within the rules of the games<br />
Wowmatrix is an addon that makes it easier to update and install other tweaks and addons to your game. Obviously using a fake version that downloads false addons &#038; tweaks and installs them leaves you open to a lot of problems. </p>
<p>The advert on google looks like a search listing and it is only apparant that it is a sponsored listing or advert on close inspection</p>
<p><a class="thickbox" rel="227" href="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix.PNG" ><img class="size-medium wp-image-228 aligncenter" title="wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/wowmatrix-300x148.PNG" alt="wowmatrix" width="300" height="148" /></a><span id="more-227"></span></p>
<p>if you look at the screenshots of the 2 sites, you will see that there is very little difference between them and an unwary visitor can soon get infected</p>
<p>Don&#8217;t get caught out by it and get your passwords stolen. The downloads on the fake site are recognized by several antiviruses as a password stealer and downloads lots of other trojans and malware</p>
<p>the genuine site is on the left, the fake site on the right</p>
<table border="0">
<tbody>
<tr>
<td><a class="thickbox" rel="227" href="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix.PNG" ><img title="genuine_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/genuine_wowmatrix-300x297.PNG" alt="genuine_wowmatrix" width="300" height="297" /></a></td>
<td><a class="thickbox" rel="227" href="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1.PNG" ><img title="fake_wowmatrix" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/fake_wowmatrix1-300x291.PNG" alt="fake_wowmatrix" width="300" height="291" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2009%2F11%2Fwow-keylogger%2F&amp;title=WOW%20%20wowmatrix%20keylogger" id="wpa2a_6"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/wow-keylogger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

