<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for sudosecure.net</title>
	<atom:link href="http://www.sudosecure.net/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net</link>
	<description>is anything truly secure...</description>
	<pubDate>Fri, 22 Aug 2008 02:38:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Comment on Malicious Site Analysis for dota11.cn injection by Mike</title>
		<link>http://www.sudosecure.net/archives/83#comment-116</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 16 Aug 2008 07:05:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=83#comment-116</guid>
		<description>Now I'm no techy, but this mentioned .cn domain site link has replaced my profile information on an international penpal website. Seems strange, my email account has also been hacked by somebody who is now sending out emails with .cn links, not to mention the daily pile of spam sent with .cn links. Hotmail has been contacted - hopefully they can sort it out!</description>
		<content:encoded><![CDATA[<p>Now I&#8217;m no techy, but this mentioned .cn domain site link has replaced my profile information on an international penpal website. Seems strange, my email account has also been hacked by somebody who is now sending out emails with .cn links, not to mention the daily pile of spam sent with .cn links. Hotmail has been contacted - hopefully they can sort it out!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm revists love theme and postcard.exe by jeremy</title>
		<link>http://www.sudosecure.net/archives/189#comment-112</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Mon, 04 Aug 2008 18:20:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=189#comment-112</guid>
		<description>Thanks for the info...  I will capture the spam tonight in the lab to follow up.  Thanks again.

--jeremy</description>
		<content:encoded><![CDATA[<p>Thanks for the info&#8230;  I will capture the spam tonight in the lab to follow up.  Thanks again.</p>
<p>&#8211;jeremy</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm revists love theme and postcard.exe by bjou</title>
		<link>http://www.sudosecure.net/archives/189#comment-111</link>
		<dc:creator>bjou</dc:creator>
		<pubDate>Mon, 04 Aug 2008 17:58:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=189#comment-111</guid>
		<description>There's new domains now. Waiting for insight into the spam messages :)
&lt;a href="http://bjou.homeunix.net/blog/2008/08/new-storm-campaign-and-domains/" rel="nofollow"&gt;http://bjou.homeunix.net/blog/2008/08/new-storm-campaign-and-domains/&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>There&#8217;s new domains now. Waiting for insight into the spam messages <img src='http://www.sudosecure.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<a href="http://bjou.homeunix.net/blog/2008/08/new-storm-campaign-and-domains/" rel="nofollow">http://bjou.homeunix.net/blog/2008/08/new-storm-campaign-and-domains/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm revists love theme and postcard.exe by New Storm Campaign and Domains &#124; BjOG - Bjou's Blog, that is!</title>
		<link>http://www.sudosecure.net/archives/189#comment-110</link>
		<dc:creator>New Storm Campaign and Domains &#124; BjOG - Bjou's Blog, that is!</dc:creator>
		<pubDate>Mon, 04 Aug 2008 17:56:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=189#comment-110</guid>
		<description>[...] Now I am not a tracker of storm campaigns nor binaries, I am just a casual binary analyst, but today while running a storm gateway for research purposes, I found some new domains going along with the revisited love theme and its postcard.exe. [...]</description>
		<content:encoded><![CDATA[<p>[...] Now I am not a tracker of storm campaigns nor binaries, I am just a casual binary analyst, but today while running a storm gateway for research purposes, I found some new domains going along with the revisited love theme and its postcard.exe. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm new &#8220;Currency Theme&#8221; campaign begins by Henry van Wyk</title>
		<link>http://www.sudosecure.net/archives/181#comment-105</link>
		<dc:creator>Henry van Wyk</dc:creator>
		<pubDate>Wed, 23 Jul 2008 04:33:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=181#comment-105</guid>
		<description>Another site...

hxxp://65.33.188.122/</description>
		<content:encoded><![CDATA[<p>Another site&#8230;</p>
<p>hxxp://65.33.188.122/</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm new &#8220;Currency Theme&#8221; campaign begins by Omar</title>
		<link>http://www.sudosecure.net/archives/181#comment-104</link>
		<dc:creator>Omar</dc:creator>
		<pubDate>Tue, 22 Jul 2008 19:45:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=181#comment-104</guid>
		<description>Thanks for the info.

Here's the email I just got:
----------------------------

Return-Path: 
Received: from sqyvdy (unknown [123.19.167.95])
 with SMTP id F1F231C68046
Received: from anvyd ([110.146.213.201]) by sqyvdy with Microsoft SMTPSVC(6.0.3790.0); Tue, 22 Jul 2008 17:08:05 +0700
Message-ID: 
From: 

Subject: North American Union is the reality now

Date: Tue, 22 Jul 2008 17:02:17 +0700
MIME-Version: 1.0
Content-Type: text/plain;
     format=flowed;
     charset="windows-1250";
     reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4133.2499
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2499

----------------------------
Body:
----------------------------
Death of the U.S. Dollar hxxp://24.180.53.121/</description>
		<content:encoded><![CDATA[<p>Thanks for the info.</p>
<p>Here&#8217;s the email I just got:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Return-Path:<br />
Received: from sqyvdy (unknown [123.19.167.95])<br />
 with SMTP id F1F231C68046<br />
Received: from anvyd ([110.146.213.201]) by sqyvdy with Microsoft SMTPSVC(6.0.3790.0); Tue, 22 Jul 2008 17:08:05 +0700<br />
Message-ID:<br />
From: </p>
<p>Subject: North American Union is the reality now</p>
<p>Date: Tue, 22 Jul 2008 17:02:17 +0700<br />
MIME-Version: 1.0<br />
Content-Type: text/plain;<br />
     format=flowed;<br />
     charset=&#8221;windows-1250&#8243;;<br />
     reply-type=original<br />
Content-Transfer-Encoding: 7bit<br />
X-Priority: 3<br />
X-MSMail-Priority: Normal<br />
X-Mailer: Microsoft Outlook Express 5.50.4133.2499<br />
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2499</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Body:<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Death of the U.S. Dollar hxxp://24.180.53.121/</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm new &#8220;Currency Theme&#8221; campaign begins by Henry van Wyk</title>
		<link>http://www.sudosecure.net/archives/181#comment-103</link>
		<dc:creator>Henry van Wyk</dc:creator>
		<pubDate>Tue, 22 Jul 2008 08:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=181#comment-103</guid>
		<description>Another site... hxxp://68.51.193.78/</description>
		<content:encoded><![CDATA[<p>Another site&#8230; hxxp://68.51.193.78/</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm new &#8220;Currency Theme&#8221; campaign begins by jeremy</title>
		<link>http://www.sudosecure.net/archives/181#comment-102</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Mon, 21 Jul 2008 19:24:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=181#comment-102</guid>
		<description>Thanks for the update as well.  It looks like several of you all are starting to see the spam come in.  No new domain names just links directly to the IP address.</description>
		<content:encoded><![CDATA[<p>Thanks for the update as well.  It looks like several of you all are starting to see the spam come in.  No new domain names just links directly to the IP address.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm new &#8220;Currency Theme&#8221; campaign begins by Benjamin</title>
		<link>http://www.sudosecure.net/archives/181#comment-101</link>
		<dc:creator>Benjamin</dc:creator>
		<pubDate>Mon, 21 Jul 2008 18:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=181#comment-101</guid>
		<description>I just got one of these in my spam box in my gmail account...pointing to 67.38.17.32 in this case.</description>
		<content:encoded><![CDATA[<p>I just got one of these in my spam box in my gmail account&#8230;pointing to 67.38.17.32 in this case.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm new &#8220;Currency Theme&#8221; campaign begins by jeremy</title>
		<link>http://www.sudosecure.net/archives/181#comment-100</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Mon, 21 Jul 2008 18:03:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=181#comment-100</guid>
		<description>Thanks for the update.</description>
		<content:encoded><![CDATA[<p>Thanks for the update.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
