<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network Forensics Blog &#187; cybercrime</title>
	<atom:link href="http://www.networkforensics.com/category/cybercrime/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkforensics.com</link>
	<description></description>
	<lastBuildDate>Tue, 21 Jun 2011 22:54:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<div id='fb-root'></div>
					<script>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>Cyber-Crime or Cyber-Espionage?</title>
		<link>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/</link>
		<comments>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 17:54:03 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=606</guid>
		<description><![CDATA[Brian Krebs posted an article on his blog this morning that documents a recent spam attack on U.S. government employees that occurred around christmas time. http://krebsonsecurity.com/2011/01/white-house-ecard-dupes-dot-gov-geeks/ which has in-depth technical coverage at: http://contagiodump.blogspot.com/2011/01/general-file-information-file-card.html Using a very simple ruse of &#8220;Merry Christmas from the White House&#8221;, this message used the common &#8220;ecard&#8221; social engineering hook to [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2011/01/03/cyber-crime-or-cyber-espionage/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Bredolab Takedown – Just the tip of the Iceberg</title>
		<link>http://www.networkforensics.com/2010/11/04/bredolab-takedown-%e2%80%93-just-the-tip-of-the-iceberg/</link>
		<comments>http://www.networkforensics.com/2010/11/04/bredolab-takedown-%e2%80%93-just-the-tip-of-the-iceberg/#comments</comments>
		<pubDate>Thu, 04 Nov 2010 12:06:59 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=487</guid>
		<description><![CDATA[This post discusses the Bredolab trojan and the findings from a 3-month NetWitness investigation which clearly show that Bredolab is much, much more than an advanced trojan threat. Bredolab is actually part of a multi-faceted profit center leveraging dynamic techniques to stay ahead of detection systems such as anti-virus and serve multiple constituencies' criminal activities.]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/11/04/bredolab-takedown-%e2%80%93-just-the-tip-of-the-iceberg/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>It&#8217;s Malware!</title>
		<link>http://www.networkforensics.com/2010/10/18/its-malware/</link>
		<comments>http://www.networkforensics.com/2010/10/18/its-malware/#comments</comments>
		<pubDate>Mon, 18 Oct 2010 12:33:46 +0000</pubDate>
		<dc:creator>Gary Golomb</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=461</guid>
		<description><![CDATA[Zeus is evolving. In regards to a new release, one Anti-Virus vendor recently noted: “[the new exe] uses techniques designed to avoid automatic heuristics-based detection.” The discussion then proceeds to examine how the exe is different from previous versions of the malware. Should we be alarmed that Zeus is getting so sophisticated that it evades [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/10/18/its-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>They are watching you&#8230;and your security vendors.</title>
		<link>http://www.networkforensics.com/2010/05/30/they-are-watching-you-and-your-security-vendors/</link>
		<comments>http://www.networkforensics.com/2010/05/30/they-are-watching-you-and-your-security-vendors/#comments</comments>
		<pubDate>Sun, 30 May 2010 13:32:43 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[bluehost]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[godaddy]]></category>
		<category><![CDATA[Gumblar]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hostgator]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Martuz]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[network solutions]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[e-crime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=309</guid>
		<description><![CDATA[If you&#8217;ve ever seen me, or any of the NetWitness crew, speak on malware, advanced threats or the current threat environment, you&#8217;ll generally hear more than one recurring theme, one of which is: Your anti-virus solution isn&#8217;t working like you think it is. This is occurring for a variety of reasons and is ultimately the result of [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/05/30/they-are-watching-you-and-your-security-vendors/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Kneber Update</title>
		<link>http://www.networkforensics.com/2010/02/19/kneber-update/</link>
		<comments>http://www.networkforensics.com/2010/02/19/kneber-update/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 18:05:25 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[Competitor Hype]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[e-crime]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network forensics]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=207</guid>
		<description><![CDATA[There was a significant amount of coverage yesterday on research performed by NetWitness into a large set of stolen information recovered from a ZeuS botnet.  Some of the information, analysis, and commentary was very beneficial to the broader discussion of threats such as these.  There is, however, some information that we feel we should address. [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/02/19/kneber-update/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Move over China, here comes Russia</title>
		<link>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/</link>
		<comments>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 03:10:53 +0000</pubDate>
		<dc:creator>tim</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Data Leakage]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Network Forensics]]></category>
		<category><![CDATA[Network Visbility]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[e-crime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network forensics]]></category>

		<guid isPermaLink="false">http://www.networkforensics.com/?p=187</guid>
		<description><![CDATA[While the world took pause to consider the implications of Operation Aurora, and Google lent considerable voice to the concept of Advanced and Persistent Threats (APT), we can ill-afford to believe even for a moment that they are alone in their sophistication or capability.   According to the FBI more than 100 nations have offensive [...]]]></description>
		<wfw:commentRss>http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

