<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Long Lived Malware Distribution Sites</title>
	<atom:link href="http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<pubDate>Fri, 21 Nov 2008 13:12:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>By: Anuj</title>
		<link>http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-333</link>
		<dc:creator>Anuj</dc:creator>
		<pubDate>Fri, 07 Jul 2006 05:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-333</guid>
		<description>Hi Jose,

I read your blog and was really amazed to find that such a site has not been banned till now. But, its true that the Internet is a huge place and how ever huge number of people work to find such things, its still a tough job to do. Maybe common people like us can make a difference here. Why don't you publish the URLs of all such malicious sites which you have? In fact, all of us can do that here and prevent people from even visiting such sites.</description>
		<content:encoded><![CDATA[<p>Hi Jose,</p>
<p>I read your blog and was really amazed to find that such a site has not been banned till now. But, its true that the Internet is a huge place and how ever huge number of people work to find such things, its still a tough job to do. Maybe common people like us can make a difference here. Why don&#8217;t you publish the URLs of all such malicious sites which you have? In fact, all of us can do that here and prevent people from even visiting such sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bleeping Malware</title>
		<link>http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-280</link>
		<dc:creator>Bleeping Malware</dc:creator>
		<pubDate>Tue, 27 Jun 2006 21:28:45 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-280</guid>
		<description>[...] After reading an article written by Jose Nazario, a security expert for Arbor Networks about a particular long lived malware distribution site located on the 217.73.66.0 network I thought it would be interesting to document what this malware does when you install it. It should be noted that I do not have a modem installed, so the results will be different on a computer with one installed. [...]</description>
		<content:encoded><![CDATA[<p>[...] After reading an article written by Jose Nazario, a security expert for Arbor Networks about a particular long lived malware distribution site located on the 217.73.66.0 network I thought it would be interesting to document what this malware does when you install it. It should be noted that I do not have a modem installed, so the results will be different on a computer with one installed. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Laudanski</title>
		<link>http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-271</link>
		<dc:creator>Paul Laudanski</dc:creator>
		<pubDate>Sun, 25 Jun 2006 16:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-271</guid>
		<description>&lt;strong&gt;Malware from long lived distrubution sites...&lt;/strong&gt;

A colleague at Arbor Networks, Jose Nazario, presents on the malware coming from a United Kingdom based host. Jose has put out a call to action against AS16238 which is responsible for the malware ridden network: 217.73.64.0/20. Block it in your host...</description>
		<content:encoded><![CDATA[<p><strong>Malware from long lived distrubution sites&#8230;</strong></p>
<p>A colleague at Arbor Networks, Jose Nazario, presents on the malware coming from a United Kingdom based host. Jose has put out a call to action against AS16238 which is responsible for the malware ridden network: 217.73.64.0/20. Block it in your host&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Suzi Turner</title>
		<link>http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-261</link>
		<dc:creator>Suzi Turner</dc:creator>
		<pubDate>Sat, 24 Jun 2006 04:12:58 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/06/long-lived-malware-distribution-sites/#comment-261</guid>
		<description>[...] In the course of my work, I see or hear about a lot of sites used for phishing and for distrubution malware.&#160;There are teams of people working constantly toward getting these shut down, but some just keep distributing malware even&#160;after the ISP/hosting company is notified. Security expert Jose Nazario of Arbor Networks blogged about one such site today. This site has been in operation since at least 2002 and is based in the UK.&#160;&#160;The site&#160;in question lives at IP address 217.73.66.1 (link to whois at&#160;domaintools.com). Nazario has a screenshot of a directory listing at the site, showing malware files with dates ranging from 11-Feb-2002 to 19-June 2006. Nazario states there are a &#34;few thousand&#34; files and explains: [...]</description>
		<content:encoded><![CDATA[<p>[...] In the course of my work, I see or hear about a lot of sites used for phishing and for distrubution malware.&nbsp;There are teams of people working constantly toward getting these shut down, but some just keep distributing malware even&nbsp;after the ISP/hosting company is notified. Security expert Jose Nazario of Arbor Networks blogged about one such site today. This site has been in operation since at least 2002 and is based in the UK.&nbsp;&nbsp;The site&nbsp;in question lives at IP address 217.73.66.1 (link to whois at&nbsp;domaintools.com). Nazario has a screenshot of a directory listing at the site, showing malware files with dates ranging from 11-Feb-2002 to 19-June 2006. Nazario states there are a &quot;few thousand&quot; files and explains: [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
