<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: FakeRean trojan is using the same subject of the latest ZBot variant</title>
	<atom:link href="http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Fri, 12 Mar 2010 07:14:13 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: steve</title>
		<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/#comment-13207</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Fri, 26 Feb 2010 16:14:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=568#comment-13207</guid>
		<description>so... how do i get rid of this virus.   my Microsoft essentials detects and gets rid of it, but it comes back at least a dozen times a day.  it is slowly chewing up my outlook program.</description>
		<content:encoded><![CDATA[<p>so&#8230; how do i get rid of this virus.   my Microsoft essentials detects and gets rid of it, but it comes back at least a dozen times a day.  it is slowly chewing up my outlook program.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mxlab</title>
		<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/#comment-12600</link>
		<dc:creator>mxlab</dc:creator>
		<pubDate>Fri, 16 Oct 2009 22:01:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=568#comment-12600</guid>
		<description>From a security stand point, a zero hour ,or 0-day protection, anti virus system is a must have these days. Virus writers are so clever that they can easily fool traditional anti virus engines and can outrun anti virus engines based on distributed AV definitions once an hour. Combined with powerfull botnets and the latest techniques they can distribute viruses and trojans variant more often. The AV vendors are just catching up on this. Sorry that I have to say this.

We do recommend each and every (potential) client not to look for anything less than a zero hour AV engine. At MX Lab we have such an engine and quite often we see our clients getting protected while others have emails with malicious attachments in their mailbox.

In the early days we had two email security appliances as gateway servers. We received hourly new definitions. In those days we often placed extra filters to block ZIP attachments based on their name to catch a virus. These appliances had 3 layered anti virus engines and they still didn&#039;t catch the malware. Of course, those gateways are ancient history by now.

I can&#039;t confirm that this virus increased in size to 500k because I haven&#039;t intercepted such one yet. What we receive is around 50k. Try to configure your appliance that it will scan large emais too but be carefull not to overload your systems. Appliances comes with hardware that can&#039;t handle heavy loads (limited RAM, older CPU,...).

At MX Lab we treat everything as supsicious until proven safe, no matter what file size it has. We quite often see spam with file sizes between 150k to 250k.

Good luck in catching them.</description>
		<content:encoded><![CDATA[<p>From a security stand point, a zero hour ,or 0-day protection, anti virus system is a must have these days. Virus writers are so clever that they can easily fool traditional anti virus engines and can outrun anti virus engines based on distributed AV definitions once an hour. Combined with powerfull botnets and the latest techniques they can distribute viruses and trojans variant more often. The AV vendors are just catching up on this. Sorry that I have to say this.</p>
<p>We do recommend each and every (potential) client not to look for anything less than a zero hour AV engine. At MX Lab we have such an engine and quite often we see our clients getting protected while others have emails with malicious attachments in their mailbox.</p>
<p>In the early days we had two email security appliances as gateway servers. We received hourly new definitions. In those days we often placed extra filters to block ZIP attachments based on their name to catch a virus. These appliances had 3 layered anti virus engines and they still didn&#8217;t catch the malware. Of course, those gateways are ancient history by now.</p>
<p>I can&#8217;t confirm that this virus increased in size to 500k because I haven&#8217;t intercepted such one yet. What we receive is around 50k. Try to configure your appliance that it will scan large emais too but be carefull not to overload your systems. Appliances comes with hardware that can&#8217;t handle heavy loads (limited RAM, older CPU,&#8230;).</p>
<p>At MX Lab we treat everything as supsicious until proven safe, no matter what file size it has. We quite often see spam with file sizes between 150k to 250k.</p>
<p>Good luck in catching them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nino Papageorgio</title>
		<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/#comment-12599</link>
		<dc:creator>Nino Papageorgio</dc:creator>
		<pubDate>Fri, 16 Oct 2009 20:40:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=568#comment-12599</guid>
		<description>I see that, not sure how I missed it (da) and I agree that it is not a logical defense method.  However many spam vendors do not have the 0 day protection in place or may be classifiying the threat incorrectly.  We have a tool within our spam device that allows the admin to block/drop individual e-mails in the event the spam filter is not catching them.  

Block to me is always prefered as then you don&#039;t run into the issue where a user may think it is legit and try to deliver it to themselves.

This specific one morphed to a new subject aroun midnight EST on 10/15 that said Microsoft outlook - also in increased in file size from 24k to 500k bypassing most if not all spam appliances just based on file size attributes.   Real-crafty!</description>
		<content:encoded><![CDATA[<p>I see that, not sure how I missed it (da) and I agree that it is not a logical defense method.  However many spam vendors do not have the 0 day protection in place or may be classifiying the threat incorrectly.  We have a tool within our spam device that allows the admin to block/drop individual e-mails in the event the spam filter is not catching them.  </p>
<p>Block to me is always prefered as then you don&#8217;t run into the issue where a user may think it is legit and try to deliver it to themselves.</p>
<p>This specific one morphed to a new subject aroun midnight EST on 10/15 that said Microsoft outlook &#8211; also in increased in file size from 24k to 500k bypassing most if not all spam appliances just based on file size attributes.   Real-crafty!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mxlab</title>
		<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/#comment-12583</link>
		<dc:creator>mxlab</dc:creator>
		<pubDate>Wed, 14 Oct 2009 21:03:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=568#comment-12583</guid>
		<description>One more thought regarding spam filters and attachment blockers:

These techniques can stop those emails coming into your mailbox but they are most of the time not doing this in real time. What I mean is that if you build and configure a rule to block messages based on the subject line, you could face new viruses coming through when the email parameters like the subject change.

It is not 100% protection for sure.</description>
		<content:encoded><![CDATA[<p>One more thought regarding spam filters and attachment blockers:</p>
<p>These techniques can stop those emails coming into your mailbox but they are most of the time not doing this in real time. What I mean is that if you build and configure a rule to block messages based on the subject line, you could face new viruses coming through when the email parameters like the subject change.</p>
<p>It is not 100% protection for sure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mxlab</title>
		<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/#comment-12582</link>
		<dc:creator>mxlab</dc:creator>
		<pubDate>Wed, 14 Oct 2009 21:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=568#comment-12582</guid>
		<description>The subject is mentioned in the article. So far we only had one version but it is possible that there are multiple versions going around the world. We can only provide information from our experience.

A possible sibject line could be: &quot;The settings for the andre@****.com mailbox&quot; as we&#039;ve seen as a variant on the latest ZBot trojan with similar content but with the difference that the payload is on a malicious host.</description>
		<content:encoded><![CDATA[<p>The subject is mentioned in the article. So far we only had one version but it is possible that there are multiple versions going around the world. We can only provide information from our experience.</p>
<p>A possible sibject line could be: &#8220;The settings for the andre@****.com mailbox&#8221; as we&#8217;ve seen as a variant on the latest ZBot trojan with similar content but with the difference that the payload is on a malicious host.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nino Papageorgio</title>
		<link>http://blog.mxlab.eu/2009/10/14/fakerean-trojan-is-using-the-same-subject-of-the-latest-zbot-variant/#comment-12580</link>
		<dc:creator>Nino Papageorgio</dc:creator>
		<pubDate>Wed, 14 Oct 2009 20:48:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=568#comment-12580</guid>
		<description>Love the site, just found it today with the 0 day exploit on 10/14/09.  Can you start including subject lines in the spam/virus e-amil you detect.  Many spam filters and attachment blockers can query by subject and that would help me and others grreatly.

Great site, really like the picture and I look forward to checking back in more.

Thanks,</description>
		<content:encoded><![CDATA[<p>Love the site, just found it today with the 0 day exploit on 10/14/09.  Can you start including subject lines in the spam/virus e-amil you detect.  Many spam filters and attachment blockers can query by subject and that would help me and others grreatly.</p>
<p>Great site, really like the picture and I look forward to checking back in more.</p>
<p>Thanks,</p>
]]></content:encoded>
	</item>
</channel>
</rss>
