<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog by FireHost &#187; trustwave</title>
	<atom:link href="http://www.fireblog.com/tag/trustwave/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Fri, 16 Dec 2011 00:52:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>ATM Malware Helps Hackers Target Banks</title>
		<link>http://www.fireblog.com/atm-malware-lets-hackers-target-banks/</link>
		<comments>http://www.fireblog.com/atm-malware-lets-hackers-target-banks/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 14:00:00 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Secure Cloud Hosting]]></category>
		<category><![CDATA[trustwave]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=1392</guid>
		<description><![CDATA[Recently Trustwave, a payment card industry security and compliance firm, discovered malware installed on ATMs in Russia and Ukraine. This particular hacker vulnerability can be easily modified to target multiple ATM vendors and is making it's way to other countries, including the US.]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.fireblog.com/wp-content/uploads/2009/06/atm2.jpg" alt="atm2" title="atm2" width="171" height="171" class="alignright size-full wp-image-1472" />Recently <a href="https://www.trustwave.com/" target="_blank">Trustwave</a>, a payment card industry security and compliance firm, discovered malware installed on ATMs in  Russia and Ukraine.</p>
<p>According to <a href="http://www.eweek.com/c/a/Security/ATM-Malware-Surfaces-as-Hackers-Target-Banks-in-Eastern-Europe-585110/?kc=rss" target="_blank">the article</a> on eWeek.com, <a href="http://security.firehost.com/terms/malware" target="_self">malware</a> on each of the infected machines (running Windows XP) was installed and activated through a Borland Delhi RAD (Rapd Application Development) executable dropper file by the name of isadmin.exe. The dropper binary contains a Data Resource (RCDATA) named PACKAGEINFO that contains the actual malware. The dropper file is executed when the hacker inserts a fake ATM card with the malware trigger code into the machine. Once activated, the trigger code produces the <a href="http://security.firehost.com/terms/malware" target="_self">malware</a> file Isass.exe inside the C:\\WINDOWS directory of the compromised system.</p>
<p>The eWeek.com article reports that this particular ATM hacker vulnerability can be easily modified to target multiple ATM vendors and is making it&#8217;s way to other countries, including the US.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/atm-malware-lets-hackers-target-banks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

