<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Truth About Two Malware Families Related to Operation Aurora</title>
	<atom:link href="http://blog.damballa.com/?feed=rss2&#038;p=578" rel="self" type="application/rss+xml" />
	<link>http://blog.damballa.com/?p=578</link>
	<description>An Ongoing Conversation About Targeted Attacks</description>
	<lastBuildDate>Tue, 17 Aug 2010 12:49:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: delightedzuk</title>
		<link>http://blog.damballa.com/?p=578&#038;cpage=1#comment-252</link>
		<dc:creator>delightedzuk</dc:creator>
		<pubDate>Sat, 27 Mar 2010 21:58:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.damballa.com/?p=578#comment-252</guid>
		<description>On a second look, those domains looks very very similar to Aurora&#039;s domains...

Check my presentation which I gave on technical details regarding the Aurora activity at :
http://www.ihackbanme.com/presentation/Google%20Vs.%20China%20Presentation_updated.pdf


I think someone is trying to copy the way of acting on those malware... just so Aurora can be accused once the malware is being caught. Or it&#039;s the other way around -&gt; Aurora&#039;s writers made this malware so no one will suspect of the real owners (Chinese ?)...


Interesting.</description>
		<content:encoded><![CDATA[<p>On a second look, those domains looks very very similar to Aurora&#8217;s domains&#8230;</p>
<p>Check my presentation which I gave on technical details regarding the Aurora activity at :<br />
<a href="http://www.ihackbanme.com/presentation/Google%20Vs.%20China%20Presentation_updated.pdf" rel="nofollow">http://www.ihackbanme.com/presentation/Google%20Vs.%20China%20Presentation_updated.pdf</a></p>
<p>I think someone is trying to copy the way of acting on those malware&#8230; just so Aurora can be accused once the malware is being caught. Or it&#8217;s the other way around -&gt; Aurora&#8217;s writers made this malware so no one will suspect of the real owners (Chinese ?)&#8230;</p>
<p>Interesting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: delightedzuk</title>
		<link>http://blog.damballa.com/?p=578&#038;cpage=1#comment-251</link>
		<dc:creator>delightedzuk</dc:creator>
		<pubDate>Sat, 27 Mar 2010 21:53:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.damballa.com/?p=578#comment-251</guid>
		<description>Hey there! Nice article!
You say that the sys file is related to operation aurora, but after analyzing the sys file myself in operation aurora, I can say that it contained another file, and was not a driver.
Check out my external file analysis since proper binary analysis couldn&#039;t have been made at the current status of the file : 

http://imthezuk.blogspot.com/2010/03/aurora-sys-file-used-in-attack-external.html

Check this out :)

So, if in this case the msconfig32.sys is a driver, it&#039;s just means they both used the same name, but it doesn&#039;t mean nothing more.
I don&#039;t think myself it&#039;s related to a malwares common over the net, I think it was a dedicated attack for fortune 500 companies / other interesting companies to steal info from.

You can contact me via my blog if needed. Good luck

http://imthezuk.blogspot.com</description>
		<content:encoded><![CDATA[<p>Hey there! Nice article!<br />
You say that the sys file is related to operation aurora, but after analyzing the sys file myself in operation aurora, I can say that it contained another file, and was not a driver.<br />
Check out my external file analysis since proper binary analysis couldn&#8217;t have been made at the current status of the file : </p>
<p><a href="http://imthezuk.blogspot.com/2010/03/aurora-sys-file-used-in-attack-external.html" rel="nofollow">http://imthezuk.blogspot.com/2010/03/aurora-sys-file-used-in-attack-external.html</a></p>
<p>Check this out <img src='http://blog.damballa.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So, if in this case the msconfig32.sys is a driver, it&#8217;s just means they both used the same name, but it doesn&#8217;t mean nothing more.<br />
I don&#8217;t think myself it&#8217;s related to a malwares common over the net, I think it was a dedicated attack for fortune 500 companies / other interesting companies to steal info from.</p>
<p>You can contact me via my blog if needed. Good luck</p>
<p><a href="http://imthezuk.blogspot.com" rel="nofollow">http://imthezuk.blogspot.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Truth About Two Malware Families Related to Operation Aurora &#171; &#34;The CTI Blog&#34;</title>
		<link>http://blog.damballa.com/?p=578&#038;cpage=1#comment-247</link>
		<dc:creator>The Truth About Two Malware Families Related to Operation Aurora &#171; &#34;The CTI Blog&#34;</dc:creator>
		<pubDate>Tue, 23 Mar 2010 15:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.damballa.com/?p=578#comment-247</guid>
		<description>[...] Truth About Two Malware Families Related to Operation&#160;Aurora By skeoseyan  The Truth About Two Malware Families Related to Operation Aurora: &#8220;The Truth About Two Malware Families Related to Operation [...]</description>
		<content:encoded><![CDATA[<p>[...] Truth About Two Malware Families Related to Operation&nbsp;Aurora By skeoseyan  The Truth About Two Malware Families Related to Operation Aurora: &#8220;The Truth About Two Malware Families Related to Operation [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
