<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: ZBot variant masked as settings file for MS Outlook</title>
	<atom:link href="http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Fri, 12 Mar 2010 07:14:13 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: mxlab</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12621</link>
		<dc:creator>mxlab</dc:creator>
		<pubDate>Tue, 20 Oct 2009 14:37:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12621</guid>
		<description>&quot;Also how are they finding my users username? trial and error ?&quot;

Yes, trial and error is one of the techniques. Harvesting techniques is also popular. In this case they will create email addresses randomly, send out spam and if the spammer receives an NDR or Non Delivery Report from the mail server they know the address is not valid. If they receive nothing there is a chance that the message will be accepted.

But there is another very effective method that we don&#039;t think of. We all have an address book and we all send out emails to each other.

This means that my email address, and yours to, is present on many different computers in address books, contact lists, emails,....

In most cases these emails will be gathered and submitted to spammers/hackers/malware writers when one of these computers get infected with a trojan or virus. In that case the email addresses can be used for sending out spam, being used as a from address to spoof the spam senders origin, to send viruses to or other things that we don&#039;t like.</description>
		<content:encoded><![CDATA[<p>&#8220;Also how are they finding my users username? trial and error ?&#8221;</p>
<p>Yes, trial and error is one of the techniques. Harvesting techniques is also popular. In this case they will create email addresses randomly, send out spam and if the spammer receives an NDR or Non Delivery Report from the mail server they know the address is not valid. If they receive nothing there is a chance that the message will be accepted.</p>
<p>But there is another very effective method that we don&#8217;t think of. We all have an address book and we all send out emails to each other.</p>
<p>This means that my email address, and yours to, is present on many different computers in address books, contact lists, emails,&#8230;.</p>
<p>In most cases these emails will be gathered and submitted to spammers/hackers/malware writers when one of these computers get infected with a trojan or virus. In that case the email addresses can be used for sending out spam, being used as a from address to spoof the spam senders origin, to send viruses to or other things that we don&#8217;t like.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dr Jon Brody</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12620</link>
		<dc:creator>Dr Jon Brody</dc:creator>
		<pubDate>Tue, 20 Oct 2009 13:04:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12620</guid>
		<description>We, and almost all of our hosted clients, have recived loads of these today. However, some of the links have not even been obfuscated and point to the domain which the email relates to, but to a directory (/owa/) which does not exist. DOH! Even spammers are getting it wrong!</description>
		<content:encoded><![CDATA[<p>We, and almost all of our hosted clients, have recived loads of these today. However, some of the links have not even been obfuscated and point to the domain which the email relates to, but to a directory (/owa/) which does not exist. DOH! Even spammers are getting it wrong!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ken</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12594</link>
		<dc:creator>ken</dc:creator>
		<pubDate>Thu, 15 Oct 2009 10:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12594</guid>
		<description>What&#039;s interesting to me is that most domain tools don&#039;t show the domain as existing. If I do a lookup on nerrasssx.eu using network-tools.com (or others) the dns record doesn&#039;t show up.  How do they hide the record from tools like this?</description>
		<content:encoded><![CDATA[<p>What&#8217;s interesting to me is that most domain tools don&#8217;t show the domain as existing. If I do a lookup on nerrasssx.eu using network-tools.com (or others) the dns record doesn&#8217;t show up.  How do they hide the record from tools like this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diabolic Preacher</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12593</link>
		<dc:creator>Diabolic Preacher</dc:creator>
		<pubDate>Thu, 15 Oct 2009 09:54:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12593</guid>
		<description>If its a link in the mail, then why would it matter if you use outlook or not, as far as the damage is concerned, it will affect windows systems on the whole. you might as well have clicked the link from another mail client just being confident that you&#039;re not using outlook and infected yourself.</description>
		<content:encoded><![CDATA[<p>If its a link in the mail, then why would it matter if you use outlook or not, as far as the damage is concerned, it will affect windows systems on the whole. you might as well have clicked the link from another mail client just being confident that you&#8217;re not using outlook and infected yourself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ZBot variant masked as settings file for MS Outlook « mxlab – all &#8230; (via postie) &#124; Kantaas.Com</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12590</link>
		<dc:creator>ZBot variant masked as settings file for MS Outlook « mxlab – all &#8230; (via postie) &#124; Kantaas.Com</dc:creator>
		<pubDate>Thu, 15 Oct 2009 02:59:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12590</guid>
		<description>[...] ZBot variant masked as settings file for MS Outlook « mxlab – all &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] ZBot variant masked as settings file for MS Outlook « mxlab – all &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goldoni Jean</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12589</link>
		<dc:creator>Goldoni Jean</dc:creator>
		<pubDate>Thu, 15 Oct 2009 01:50:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12589</guid>
		<description>Good evening,

I receive this email today with my own mail adress. 

What can i do?</description>
		<content:encoded><![CDATA[<p>Good evening,</p>
<p>I receive this email today with my own mail adress. </p>
<p>What can i do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1700 Martin Luther King Jr Way &#187; Archives &#187; The Pleasure Never Ends</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12588</link>
		<dc:creator>1700 Martin Luther King Jr Way &#187; Archives &#187; The Pleasure Never Ends</dc:creator>
		<pubDate>Thu, 15 Oct 2009 00:33:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12588</guid>
		<description>[...] This blog reports on a variant of the ZBot trojan that&#8217;s making its way through the tubes of the internet. It&#8217;s a classic scam, where the bad guys pose as, in our case, lmi.net tech support. They send you a link via email. The link is obfuscated to make it look like it points to an lmi.net server, but the actual link is to a server off-site. The server has several IP addresses, so that if one is shut down, you may still have a hope of infecting your system. The link leads to a page that tells you to download an executable called YOURNAME-settings.exe. [...]</description>
		<content:encoded><![CDATA[<p>[...] This blog reports on a variant of the ZBot trojan that&#8217;s making its way through the tubes of the internet. It&#8217;s a classic scam, where the bad guys pose as, in our case, lmi.net tech support. They send you a link via email. The link is obfuscated to make it look like it points to an lmi.net server, but the actual link is to a server off-site. The server has several IP addresses, so that if one is shut down, you may still have a hope of infecting your system. The link leads to a page that tells you to download an executable called YOURNAME-settings.exe. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cody</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12586</link>
		<dc:creator>Cody</dc:creator>
		<pubDate>Wed, 14 Oct 2009 21:22:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12586</guid>
		<description>I also have a lot of users that are recieving this email today.  One from Automailer@mydomain.com and support@mydomain.com Anyone have any luck blocking these... Also how are they finding my users username? trial and error ?</description>
		<content:encoded><![CDATA[<p>I also have a lot of users that are recieving this email today.  One from <a href="mailto:Automailer@mydomain.com">Automailer@mydomain.com</a> and <a href="mailto:support@mydomain.com">support@mydomain.com</a> Anyone have any luck blocking these&#8230; Also how are they finding my users username? trial and error ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DHannen</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12585</link>
		<dc:creator>DHannen</dc:creator>
		<pubDate>Wed, 14 Oct 2009 21:18:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12585</guid>
		<description>We have also been getting a huge amount of these today, with the domains/addresses changing per mail.  I&#039;ve instructed staff to be careful and also included this information.  Thanks for the info!</description>
		<content:encoded><![CDATA[<p>We have also been getting a huge amount of these today, with the domains/addresses changing per mail.  I&#8217;ve instructed staff to be careful and also included this information.  Thanks for the info!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcus DM</title>
		<link>http://blog.mxlab.eu/2009/10/14/zbot-variant-masked-as-settings-file-for-ms-outlook/#comment-12581</link>
		<dc:creator>Marcus DM</dc:creator>
		<pubDate>Wed, 14 Oct 2009 20:49:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=564#comment-12581</guid>
		<description>Denying users&#039;&#039; rights to download and install, may protect your network against this payload and any other variants.</description>
		<content:encoded><![CDATA[<p>Denying users&#8221; rights to download and install, may protect your network against this payload and any other variants.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
