<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>MW-Blog</title>
	<link>http://www.teamfurry.com/wordpress</link>
	<description>About malware, packers and reverse engineering</description>
	<pubDate>Mon, 15 Jun 2009 16:41:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>
	<language>en</language>
			<item>
		<title>Unsubscribing for the worse</title>
		<link>http://www.teamfurry.com/wordpress/2009/06/15/unsubscribing-for-the-worse/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/06/15/unsubscribing-for-the-worse/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 16:41:25 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/06/15/unsubscribing-for-the-worse/</guid>
		<description><![CDATA[Have you ever unsubscribed from various bulk mailing programs? Be them opt-out (fancy name for spam), coupons, market research or whatnot?
]]></description>
			<content:encoded><![CDATA[<p>Have you ever unsubscribed from various bulk mailing programs? Be them opt-out (fancy name for spam), coupons, market research or whatnot? <a href="http://www.teamfurry.com/wordpress/2009/06/15/unsubscribing-for-the-worse/#more-234" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/06/15/unsubscribing-for-the-worse/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Unpacking NakedPacker</title>
		<link>http://www.teamfurry.com/wordpress/2009/05/30/unpacking-nakedpacker/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/05/30/unpacking-nakedpacker/#comments</comments>
		<pubDate>Sat, 30 May 2009 04:38:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Tips and Tricks]]></category>

		<category><![CDATA[Packer-Magic]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/05/30/unpacking-nakedpacker/</guid>
		<description><![CDATA[NakedPacker is somewhat commonly seen in malware. Though its only a compressor I guess the name and the easy GUI make the teenage mutant wannabe-ninja herders come flocking to it.
]]></description>
			<content:encoded><![CDATA[<p>NakedPacker is somewhat commonly seen in malware. Though its only a compressor I guess the name and the easy GUI make the teenage mutant wannabe-ninja herders come flocking to it. <a href="http://www.teamfurry.com/wordpress/2009/05/30/unpacking-nakedpacker/#more-232" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/05/30/unpacking-nakedpacker/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Great loss for the RE community</title>
		<link>http://www.teamfurry.com/wordpress/2009/05/08/great-loss-for-the-re-community/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/05/08/great-loss-for-the-re-community/#comments</comments>
		<pubDate>Fri, 08 May 2009 05:54:49 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/05/08/great-loss-for-the-re-community/</guid>
		<description><![CDATA[Just heard the news that Fjalar Ravia, better known as Fravia, passed away on Sunday, 3rd May 2009 after a long illness.
]]></description>
			<content:encoded><![CDATA[<p>Just heard the news that Fjalar Ravia, better known as Fravia, passed away on Sunday, 3rd May 2009 after a long illness. <a href="http://www.teamfurry.com/wordpress/2009/05/08/great-loss-for-the-re-community/#more-231" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/05/08/great-loss-for-the-re-community/feed/</wfw:commentRss>
		</item>
		<item>
		<title>L0L at l0lw0rm</title>
		<link>http://www.teamfurry.com/wordpress/2009/05/04/l0l-at-l0lw0rm/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/05/04/l0l-at-l0lw0rm/#comments</comments>
		<pubDate>Mon, 04 May 2009 06:54:02 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<category><![CDATA[Malware FreakShow]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/05/04/l0l-at-l0lw0rm/</guid>
		<description><![CDATA[I was looking through a repository of malware source codes the other day when I noticed a pretty small rar package, only 11kb in size and decided to take a closer look. The package was called l0lw0rm.rar.
]]></description>
			<content:encoded><![CDATA[<p>I was looking through a repository of malware source codes the other day when I noticed a pretty small rar package, only 11kb in size and decided to take a closer look. The package was called l0lw0rm.rar. <a href="http://www.teamfurry.com/wordpress/2009/05/04/l0l-at-l0lw0rm/#more-230" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/05/04/l0l-at-l0lw0rm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Sour Marketing?</title>
		<link>http://www.teamfurry.com/wordpress/2009/04/15/sour-marketing/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/04/15/sour-marketing/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 05:14:17 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/04/15/sour-marketing/</guid>
		<description><![CDATA[I received an newsletter from eEye yesterday. Normally I just dismiss those without taking a second look but this time I actually got pretty pissed.
]]></description>
			<content:encoded><![CDATA[<p>I received an newsletter from<a href="http://www.eeye.com"> eEye</a> yesterday. Normally I just dismiss those without taking a second look but this time I actually got pretty pissed. <a href="http://www.teamfurry.com/wordpress/2009/04/15/sour-marketing/#more-229" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/04/15/sour-marketing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Some people just don&#8217;t learn</title>
		<link>http://www.teamfurry.com/wordpress/2009/04/06/some-people-just-dont-learn/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/04/06/some-people-just-dont-learn/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 17:25:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/04/06/some-people-just-dont-learn/</guid>
		<description><![CDATA[For those who haven&#8217;t read or just don&#8217;t remember, read this first.
]]></description>
			<content:encoded><![CDATA[<p>For those who haven&#8217;t read or just don&#8217;t remember, read <a href="http://www.teamfurry.com/wordpress/2009/03/13/a-little-something-that-brightened-my-day/">this</a> first. <a href="http://www.teamfurry.com/wordpress/2009/04/06/some-people-just-dont-learn/#more-227" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/04/06/some-people-just-dont-learn/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Breaking news: Conficker became self aware!</title>
		<link>http://www.teamfurry.com/wordpress/2009/04/01/breaking-news-conficker-became-self-aware/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/04/01/breaking-news-conficker-became-self-aware/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 22:01:57 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[April Fools' Day]]></category>

		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/04/01/breaking-news-conficker-became-self-aware/</guid>
		<description><![CDATA[This is what security experts around the world have feared for a long time. The conficker worm botnet grew big enough and 1 minute past midnight, on April 1st, it finally gained consciousness.
]]></description>
			<content:encoded><![CDATA[<p>This is what security experts around the world have feared for a long time. The conficker worm botnet grew big enough and 1 minute past midnight, on April 1st, it finally gained consciousness. <a href="http://www.teamfurry.com/wordpress/2009/04/01/breaking-news-conficker-became-self-aware/#more-226" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/04/01/breaking-news-conficker-became-self-aware/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A /16 netblock banned from teamfurry.com</title>
		<link>http://www.teamfurry.com/wordpress/2009/03/25/a-16-netblock-banned-from-teamfurrycom/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/03/25/a-16-netblock-banned-from-teamfurrycom/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 12:25:27 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/03/25/a-16-netblock-banned-from-teamfurrycom/</guid>
		<description><![CDATA[I&#8217;m doing this with a bit mixed feelings since I know I might be blocking away valid users. But I feel this is the only way to start showing ISPs and other companies that they can&#8217;t go on doing whatever they like.
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m doing this with a bit mixed feelings since I know I might be blocking away valid users. But I feel this is the only way to start showing ISPs and other companies that they can&#8217;t go on doing whatever they like. <a href="http://www.teamfurry.com/wordpress/2009/03/25/a-16-netblock-banned-from-teamfurrycom/#more-225" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/03/25/a-16-netblock-banned-from-teamfurrycom/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Scans for default Tomcat admin passwords</title>
		<link>http://www.teamfurry.com/wordpress/2009/03/24/scans-for-default-tomcat-admin-passwords/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/03/24/scans-for-default-tomcat-admin-passwords/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 06:01:19 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/03/24/scans-for-default-tomcat-admin-passwords/</guid>
		<description><![CDATA[I went through some sinkhole stats and spotted a few scans that looked like this: &#8220;GET/manager/html HTTP/1.1&#8243;.
]]></description>
			<content:encoded><![CDATA[<p>I went through some sinkhole stats and spotted a few scans that looked like this: &#8220;GET/manager/html HTTP/1.1&#8243;. <a href="http://www.teamfurry.com/wordpress/2009/03/24/scans-for-default-tomcat-admin-passwords/#more-224" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/03/24/scans-for-default-tomcat-admin-passwords/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Botnet running on MIPS CPU devices.</title>
		<link>http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 20:05:13 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<category><![CDATA[Malware FreakShow]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/</guid>
		<description><![CDATA[Finally, something new :) An IRC capable bot has been making the rounds. Now, instead of infecting PC&#8217;s or servers this baby goes after DSL modems.
]]></description>
			<content:encoded><![CDATA[<p>Finally, something new :) An IRC capable bot has been making the rounds. Now, instead of infecting PC&#8217;s or servers this baby goes after DSL modems. <a href="http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/#more-223" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/03/23/botnet-running-on-mips-cpu-devices/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A little something that brightened my day</title>
		<link>http://www.teamfurry.com/wordpress/2009/03/13/a-little-something-that-brightened-my-day/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/03/13/a-little-something-that-brightened-my-day/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 14:21:00 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/03/13/a-little-something-that-brightened-my-day/</guid>
		<description><![CDATA[So, I received a mail from &#8220;Peter Hu&#8221;, asking me to list him as a friend on Yahoo! IM. All the links in the mail led to yahoo.com so I figured what the heck, maybe someone want&#8217;s to congratulate me on my birthday. I&#8217;ve never used Yahoo! IM before so I figured &#8216;let&#8217;s see what&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>So, I received a mail from &#8220;Peter Hu&#8221;, asking me to list him as a friend on Yahoo! IM. All the links in the mail led to yahoo.com so I figured what the heck, maybe someone want&#8217;s to congratulate me on my birthday. I&#8217;ve never used Yahoo! IM before so I figured &#8216;let&#8217;s see what&#8217;s behind this&#8217;. <a href="http://www.teamfurry.com/wordpress/2009/03/13/a-little-something-that-brightened-my-day/#more-222" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/03/13/a-little-something-that-brightened-my-day/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Microsoft published a $250000 bounty on Downadup/Conficker</title>
		<link>http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/</link>
		<comments>http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 20:46:20 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/</guid>
		<description><![CDATA[The network worm known as Downadup or Conficker or Kido has been on the lips of the entire information security community for some while now and it has been keeping people busy, including myself. Microsoft published today $250000 bounty on tips/leads leading to arrest and conviction on the person(s) behind the worm.
]]></description>
			<content:encoded><![CDATA[<p>The network worm known as Downadup or Conficker or Kido has been on the lips of the entire information security community for some while now and it has been keeping people busy, including myself. Microsoft published today $250000 bounty on tips/leads leading to arrest and conviction on the person(s) behind the worm. <a href="http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/#more-219" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2009/02/12/microsoft-published-a-250000-bounty-on-downadupconficker/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Zeus/Wsnpoem/Zbot targets</title>
		<link>http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/#comments</comments>
		<pubDate>Tue, 04 Nov 2008 20:27:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<category><![CDATA[Malware FreakShow]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/</guid>
		<description><![CDATA[I ran into an interesting Zbot sample today. I haven&#8217;t peeked at them often and I was surprised to see a big bunch of various poker sites in the configuration as stealing targets. That prompted me to do a quick search on zbots seen in the last few days and I ended up downloading the [...]]]></description>
			<content:encoded><![CDATA[<p>I ran into an interesting Zbot sample today. I haven&#8217;t peeked at them often and I was surprised to see a big bunch of various poker sites in the configuration as stealing targets. That prompted me to do a quick search on zbots seen in the last few days and I ended up downloading the encrypted configuration files from the C&#038;C servers that I saw were online. 22 of them active :) <a href="http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/#more-218" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/11/04/zeuswsnpoemzbot-targets/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MS08-067 fun started</title>
		<link>http://www.teamfurry.com/wordpress/2008/11/03/ms08-067-fun-started/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/11/03/ms08-067-fun-started/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 17:20:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<category><![CDATA[Malware FreakShow]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/11/03/ms08-067-fun-started/</guid>
		<description><![CDATA[Yup, took this long for someone to start properly abusing the MS08-067 vulnerability. There&#8217;s a worm now on the loose that uses the exploit. The worm component comes coupled with a kernel mode DDOS bot that&#8217;s been doing the rounds for a while now.
]]></description>
			<content:encoded><![CDATA[<p>Yup, took this long for someone to start properly abusing the MS08-067 vulnerability. There&#8217;s a worm now on the loose that uses the exploit. The worm component comes coupled with a kernel mode DDOS bot that&#8217;s been doing the rounds for a while now.<br />
 <a href="http://www.teamfurry.com/wordpress/2008/11/03/ms08-067-fun-started/#more-217" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/11/03/ms08-067-fun-started/feed/</wfw:commentRss>
		</item>
		<item>
		<title>First PoCs targeting english Windows OS&#8217;s on MS08-067</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/31/first-pocs-targeting-english-windows-oss-on-ms08-067/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/10/31/first-pocs-targeting-english-windows-oss-on-ms08-067/#comments</comments>
		<pubDate>Fri, 31 Oct 2008 12:13:34 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/10/31/first-pocs-targeting-english-windows-oss-on-ms08-067/</guid>
		<description><![CDATA[This lovely morning saw the first Proof of Concept binaries targeting the English localized Windows OS&#8217;s that are vulnerable to the MS08-067. The exploit payload adds the guest account to the administrators group. Still no worm, but one step closer.
]]></description>
			<content:encoded><![CDATA[<p>This lovely morning saw the first Proof of Concept binaries targeting the English localized Windows OS&#8217;s that are vulnerable to the MS08-067. The exploit payload adds the guest account to the administrators group. Still no worm, but one step closer.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/10/31/first-pocs-targeting-english-windows-oss-on-ms08-067/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ICANN Delayed the de-accreditation of ESTDomains</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/30/icann-delayed-the-de-accreditation-of-estdomains/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/10/30/icann-delayed-the-de-accreditation-of-estdomains/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 11:44:08 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/10/30/icann-delayed-the-de-accreditation-of-estdomains/</guid>
		<description><![CDATA[&#8220;ICANN received a response from EstDomains regarding the notice of termination. http://www.icann.org/correspondence/poltev-to-burnette-29oct08-en.pdf [PDF, 853K] To assess the merits of the claims made in EstDomains’ response, ICANN has stayed the termination process as ICANN analyzes these claims.&#8221;
Even though Tsastsin complained to Estonian supreme court and is &#8220;not guilty&#8221; until the verdict is finalized it&#8217;ll be fun [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;ICANN received a response from EstDomains regarding the notice of termination. <a href="http://icann.org/correspondence/poltev-to-burnette-29oct08-en.pdf">http://www.icann.org/correspondence/poltev-to-burnette-29oct08-en.pdf</a> [PDF, 853K] To assess the merits of the claims made in EstDomains’ response, ICANN has stayed the termination process as ICANN analyzes these claims.&#8221;</p>
<p>Even though Tsastsin complained to Estonian supreme court and is &#8220;not guilty&#8221; until the verdict is finalized it&#8217;ll be fun to see what happens. ESTDomains delivered a document dated to July that Tsastsin is not the CEO anymore. Instead, Konstantin Poltev is marked to be the current CEO. Not sure how far ICANN appreciates the document since the sentence that the Estonian court passed earlier was amongst other thing, for document forgery.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/10/30/icann-delayed-the-de-accreditation-of-estdomains/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ESTDomains responded to ICANN</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/30/estdomains-responded-to-icann/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/10/30/estdomains-responded-to-icann/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 08:50:58 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/10/30/estdomains-responded-to-icann/</guid>
		<description><![CDATA[Seems that ESTDomains responded to ICANN and are trying to find a way to stop the de-accreditation.
]]></description>
			<content:encoded><![CDATA[<p>Seems that ESTDomains responded to ICANN and are trying to find a way to stop the de-accreditation. <a href="http://www.teamfurry.com/wordpress/2008/10/30/estdomains-responded-to-icann/#more-214" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/10/30/estdomains-responded-to-icann/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The evil batch</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/29/the-evil-batch/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/10/29/the-evil-batch/#comments</comments>
		<pubDate>Wed, 29 Oct 2008 07:45:31 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<category><![CDATA[Malware FreakShow]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/10/29/the-evil-batch/</guid>
		<description><![CDATA[I ran into an interesting piece of malware. It basically comes in an .exe wrapper and drops a .bat file that&#8217;s about 25kb large. It&#8217;s really heavily obfuscated and it can be considered destructive since it deletes document files and does other evil things.
]]></description>
			<content:encoded><![CDATA[<p>I ran into an interesting piece of malware. It basically comes in an .exe wrapper and drops a .bat file that&#8217;s about 25kb large. It&#8217;s really heavily obfuscated and it can be considered destructive since it deletes document files and does other evil things. <a href="http://www.teamfurry.com/wordpress/2008/10/29/the-evil-batch/#more-211" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/10/29/the-evil-batch/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ESTDomains got canned by ICANN</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/29/estdomains-got-canned-by-icann/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/10/29/estdomains-got-canned-by-icann/#comments</comments>
		<pubDate>Wed, 29 Oct 2008 06:42:09 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/10/29/estdomains-got-canned-by-icann/</guid>
		<description><![CDATA[http://www.icann.org/correspondence/burnette-to-tsastsin-28oct08-en.pdf
Tears of joy :)




]]></description>
			<content:encoded><![CDATA[<p>http://www.icann.org/correspondence/burnette-to-tsastsin-28oct08-en.pdf</p>
<p>Tears of joy :)<br />
<script type="text/javascript"><!--
google_ad_client = "pub-3239091084933229";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
//2007-03-23: wordpress
google_ad_channel = "2534919240";
google_color_border = "FFFFFF";
google_color_bg = "f8f8f8";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";
//-->
</script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/10/29/estdomains-got-canned-by-icann/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Gimmiv Trojan: Glimpse at winbase.dll</title>
		<link>http://www.teamfurry.com/wordpress/2008/10/25/gimmiv-trojan-glimpse-at-winbasedll/</link>
		<comments>http://www.teamfurry.com/wordpress/2008/10/25/gimmiv-trojan-glimpse-at-winbasedll/#comments</comments>
		<pubDate>Sat, 25 Oct 2008 21:53:52 +0000</pubDate>
		<dc:creator>toni</dc:creator>
		
		<category><![CDATA[General InfoSec]]></category>

		<category><![CDATA[Malware FreakShow]]></category>

		<guid isPermaLink="false">http://www.teamfurry.com/wordpress/2008/10/25/gimmiv-trojan-glimpse-at-winbasedll/</guid>
		<description><![CDATA[Just took a close look at the winbase.dll variants I have. 5 of them with the following compilation timestamps:
]]></description>
			<content:encoded><![CDATA[<p>Just took a close look at the winbase.dll variants I have. 5 of them with the following compilation timestamps: <a href="http://www.teamfurry.com/wordpress/2008/10/25/gimmiv-trojan-glimpse-at-winbasedll/#more-209" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.teamfurry.com/wordpress/2008/10/25/gimmiv-trojan-glimpse-at-winbasedll/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
