<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
	<atom:link href="http://blog.mxlab.eu/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Sat, 04 Feb 2012 17:44:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Spam in fake LinkedIn messages</title>
		<link>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/</link>
		<comments>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 16:30:24 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Family Pharmacy]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1583</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, has noticed a large spam campaign on behalf of the Canadian Family Pharmacy in fake LinkedIn messages. The messages come the spoofed email address &#60;member@linkedin.com&#62; with the authors like: Fenella Macdonald via LinkedIn &#60;member@linkedin.com&#62; Catriona Bailey via LinkedIn &#60;member@linkedin.com&#62; Susan Jones via LinkedIn &#60;member@linkedin.com&#62; .... Subjects in use: Can i place your [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1583&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, has noticed a large spam campaign on behalf of the Canadian Family Pharmacy in fake LinkedIn messages.</p>
<p>The messages come the spoofed email address &lt;member@linkedin.com&gt; with the authors like:</p>
<pre>Fenella  Macdonald via LinkedIn &lt;member@linkedin.com&gt;
Catriona  Bailey via LinkedIn &lt;member@linkedin.com&gt;
Susan  Jones via LinkedIn &lt;member@linkedin.com&gt;
....</pre>
<p>Subjects in use:</p>
<p>Can i place your photo on my site?<br />
Can i place your photo on our facebook page?<br />
Can i place your information on our web page?<br />
Can i place your video on our web site?<br />
Can i place your video on my facebook page?<br />
Can i place your contacts on our twitter page?<br />
&#8230;..</p>
<p>Example of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin.jpg" alt="" width="450" height="263" /></p>
<p>The URL in the message point to different web hosts and pages with an redirect HTML:</p>
<p>&lt;html&gt;&lt;head&gt;&lt;title&gt;Buy Viagra Online &#8211; Online Pharmacy&lt;/title&gt;&lt;style type=&#8221;text/css&#8221;&gt; a { font-size: 24pt; } &lt;/style&gt;&lt;script type=&#8221;text/javascript&#8221;&gt;var a = &#8220;hxxp://viagralevitratestosterone.com&#8221;;window.location = a;&lt;/script&gt;&lt;/head&gt;&lt;body&gt;&lt;center&gt;&lt;h1&gt;#1 Online Pharmacy&lt;/h1&gt;&lt;br&gt;Online DrugStore&lt;br&gt;&lt;a href=&#8221;hxxp://viagralevitratestosterone.com&#8221;&gt;Buy Viagra Online&lt;/a&gt;&lt;/center&gt;&lt;/body&gt;&lt;/html&gt;</p>
<p>In return, the redirect points to hxxp://viagralevitratestosterone.com.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin_2.jpg" alt="" width="450" height="352" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1583/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1583&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin_2.jpg" medium="image" />
	</item>
		<item>
		<title>Kelihos botnet taken down by Microsoft</title>
		<link>http://blog.mxlab.eu/2011/09/28/kelihos-botnet-taken-down-by-microsoft/</link>
		<comments>http://blog.mxlab.eu/2011/09/28/kelihos-botnet-taken-down-by-microsoft/#comments</comments>
		<pubDate>Wed, 28 Sep 2011 08:33:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Kelihos]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Rustoc]]></category>
		<category><![CDATA[takedown]]></category>
		<category><![CDATA[Waledac]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1466</guid>
		<description><![CDATA[According to an article on the official Microsoft Blog, the botnet Kelihos, also known as Waledac 2.0, has been taken down on the 27th of September 2011 by Microsoft in an operation codenamed “Operation b79”. Read the full story.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1466&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>According to <a href="http://blogs.technet.com/b/microsoft_blog/archive/2011/09/27/microsoft-neutralizes-kelihos-botnet-names-defendant-in-case.aspx" target="_blank">an article on the official Microsoft Blog</a>, the botnet Kelihos, also known as Waledac 2.0, has been taken down on the 27th of September 2011 by Microsoft in an operation codenamed “Operation b79”.</p>
<p><a href="http://blogs.technet.com/b/microsoft_blog/archive/2011/09/27/microsoft-neutralizes-kelihos-botnet-names-defendant-in-case.aspx" target="_blank">Read the full story</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1466/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1466/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1466/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1466/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1466/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1466/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1466/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1466/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1466&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/09/28/kelihos-botnet-taken-down-by-microsoft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Emails &#8220;Sent via Google Maps&#8221; is a redirect to the Canadian Pharmacy</title>
		<link>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/</link>
		<comments>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 09:27:32 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1447</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted some spam messages with subjects like: Sent via Google Maps: Brett Lepper sent you: A Maps link Sent via Google Maps: Brenna Eber sent you: A Maps link Sent via Google Maps: Theodora Cavitt sent you: A Maps link &#8230; The subjects start with &#8216;Sent via Google Maps:&#8217; and end with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1447&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercepted some spam messages with subjects like:</p>
<p>Sent via Google Maps: Brett Lepper sent you: A Maps link<br />
Sent via Google Maps: Brenna Eber sent you: A Maps link<br />
Sent via Google Maps: Theodora Cavitt sent you: A Maps link<br />
&#8230;</p>
<p>The subjects start with &#8216;Sent via Google Maps:&#8217; and end with &#8216;A Maps link&#8217;.<br />
The from email address is spoofed but starts with &#8216;admin@&#8217; combined with a subdomain address.</p>
<p>Message body examples:</p>
<blockquote>
<div>
<div lang="x-western">
<div>This email was sent to you by a user on Google Maps:</div>
<div>Hi</div>
<hr noshade="noshade" size="1" />
<div>hxxp://gertie8kthv.blogginc.asia/10/8/gertie-bawa.html</div>
</div>
</div>
</blockquote>
<div lang="x-western">
<blockquote>
<div>This email was sent to you by a user on Google Maps:</div>
<div>Hi</div>
<hr noshade="noshade" size="1" />
<div>hxxp://elmira4221c.blogsun.asia/11/10/elmira-antoniuk.html</div>
</blockquote>
</div>
<p>The URLs in the message will redirect the user to the website of the Canadian Pharmacy at hxxp://www.bestrxs.com/.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1447/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1447&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Google Picasa scam</title>
		<link>http://blog.mxlab.eu/2011/06/10/google-picasa-scam/</link>
		<comments>http://blog.mxlab.eu/2011/06/10/google-picasa-scam/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 08:49:38 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[Google Picasa]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1419</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, reported earlier regarding emails that offer an alternative to the official Adobe PDF Reader and the VOIP add ons for Skype. It now seems that Google Picasa is the next victim of the same type of scam. We intercepted a few messages with the subject &#8220;The iTunes of Photo Organization&#8221; coming for the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1419&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, reported earlier regarding emails that offer <a href="http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/" target="_blank">an alternative to the official Adobe PDF Reader</a> and <a href="http://blog.mxlab.eu/2010/09/14/malicious-spam-campaign-regarding-adobe-acrobat-2010-pdf-reader-and-voip-addons-for-skype/" target="_blank">the VOIP add ons for Skype</a>.</p>
<p>It now seems that Google Picasa is the next victim of the same type of scam. We intercepted a few messages with the subject &#8220;The iTunes of Photo Organization&#8221; coming for the email address Picture Tools &lt;megantivir@aphyet.com&gt;. This is the message:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_1.jpg" alt="" width="450" height="582" /></p>
<p>The message has a download URL in the format hxxp://aphyet.com/re.php?lnk=1203683910&amp;e=****.****@****.be. Following the link takes us to hxxp://officialversion.su/pics/1/index.asp?aff=11677&amp;camp=esp_may09hld_picasa_jun10 with the following web site:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_2.jpg" alt="" width="450" height="419" /></p>
<p>Notice the button on the right &#8220;Download Picasa&#8221; now and the mention of 24/7 support. This is very familiar and did ring a bell at the MX Lab HQ. We started to investigate the web site further.</p>
<p>We found a registration and order process very similar to the past cases with the Adobe PDF Reader 2011 and the VOIP add ons for Skype.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_3.jpg" alt="" width="450" height="347" /></p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_4.jpg" alt="" width="450" height="345" /></p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_5.jpg" alt="" width="450" height="399" /></p>
<p>The payment transaction appears to be processed on an unsecure HTTP connection but a look into the HTML learns us that the payment form in embedded in an &lt;iframe&gt; and the form is processed by hxxps://secure-signupway.com/p06/?siteid=6882. This domain is know for fraudulent payment processing so your credit card details will end up in the wrong hands.</p>
<p>As expected, the domain license details are protected and the domain is registered a few days ago.</p>
<pre>Domain Name: APHYET.COM 

Registrant:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Creation Date: 06-Jun-2011
Expiration Date: 06-Jun-2012

Domain servers in listed order:
    ns1.reg.ru
    ns2.reg.ru

Administrative Contact:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Technical Contact:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Billing Contact:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676</pre>
<p>Our recommendation is not to fill in any credit card details &#8211; your credit card details will likely be abused &#8211;  and download this software. Please note that for the real Picasa you need to go to the Google web site at <a href="http://picasa.google.com/" target="_blank">http://picasa.google.com/</a>. And it&#8217;s free.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1419/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1419&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/06/10/google-picasa-scam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_3.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_4.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_5.jpg" medium="image" />
	</item>
		<item>
		<title>Message from YouTube Administration is spam that leads to the Canadian Family Pharmacy</title>
		<link>http://blog.mxlab.eu/2011/05/26/message-from-youtube-administration-is-spam-that-leads-to-the-canadian-family-pharmacy/</link>
		<comments>http://blog.mxlab.eu/2011/05/26/message-from-youtube-administration-is-spam-that-leads-to-the-canadian-family-pharmacy/#comments</comments>
		<pubDate>Thu, 26 May 2011 09:54:24 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Family Pharmacy]]></category>
		<category><![CDATA[You Tube spam]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1407</guid>
		<description><![CDATA[For several days now, MX Lab, http://www.mxlab.eu, is intercepting a spam campaign with the subject &#8220;YouTube Administration sent you a message: Your video on the TOP of YouTube&#8221; sent from the spoofed email address YouTube Service &#60;service@youtube.com&#62;. Again, this is a great example of using a well known brand to mislead the public. The body of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1407&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>For several days now, MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, is intercepting a spam campaign with the subject &#8220;YouTube Administration sent you a message: Your video on the TOP of YouTube&#8221; sent from the spoofed email address YouTube Service &lt;service@youtube.com&gt;. Again, this is a great example of using a well known brand to mislead the public.</p>
<p>The body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110526_youtube_spam.gif" alt="" width="450" height="193" /></p>
<p>The URLs are pointing to sites like:</p>
<p>hxxp://fotoramblas.com/simplified.html<br />
hxxp://www.afmp.pt/warmth.html<br />
hxxp://hdwhc.com/nimbler.html<br />
hxxp://dallascodecamp.com/desire.html<br />
and many others</p>
<p>These sites will redirect the visitor to the Canadian Family Pharmacy at hxxp://tabletrxdrugspills.com/</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110526_youtube_spam_2.gif" alt="" width="450" height="353" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1407/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1407&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/05/26/message-from-youtube-administration-is-spam-that-leads-to-the-canadian-family-pharmacy/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110526_youtube_spam.gif" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110526_youtube_spam_2.gif" medium="image" />
	</item>
		<item>
		<title>Spam messages using the LinkedIn brand</title>
		<link>http://blog.mxlab.eu/2011/05/06/spam-messages-using-the-linkedin-brand/</link>
		<comments>http://blog.mxlab.eu/2011/05/06/spam-messages-using-the-linkedin-brand/#comments</comments>
		<pubDate>Fri, 06 May 2011 14:35:42 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1403</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a spam campaign by email with the subject&#8221;check it out&#8221; or &#8220;mother days flowers&#8221; where the LinkedIn email template is being used. The email is sent from the spoofed email address &#8220;Mark Johnson via LinkedIn &#60;mark844@daukskosos.com&#62;&#8221; and has the following body: The message has a lay out that LinkedIn [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1403&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a spam campaign by email with the subject&#8221;check it out&#8221; or &#8220;mother days flowers&#8221; where the LinkedIn email template is being used.</p>
<p>The email is sent from the spoofed email address &#8220;Mark Johnson via LinkedIn &lt;mark844@daukskosos.com&gt;&#8221; and has the following body:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110506_spam.gif" alt="" width="450" height="276" /></p>
<p>The message has a lay out that LinkedIn is using in communication with their members.</p>
<p>Notice that this spam has an embedded imageat the end with the instructions on how to unsubscribe. The URL behind points to hxxp://gy-qes.daukskosos.com/ followed by some numbers.</p>
<p>When following the URin the spam message we got the following messages in our browser:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110506_spam_2.gif" alt="" width="308" height="113" /></p>
<p>A few seconds later we are redirected and get the following message in  our browser:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110506_spam_3.gif" alt="" width="531" height="117" /></p>
<p>Domain registration details:</p>
<pre>Registration Service Provided By: Namecheap.com
Contact: support@namecheap.com
Visit: http://namecheap.com

Domain name: DAUKSKOSOS.COM

Registrant Contact:
   NA
   Anna Shay ()

   Fax:
   NAa
   Olympic Valley, CA 96146
   US

Administrative Contact:
   NA
   Anna Shay (shay.touchsound@gmail.com)
   +1.5305808370
   Fax:
   NAa
   Olympic Valley, CA 96146
   US

Technical Contact:
   NA
   Anna Shay (shay.touchsound@gmail.com)
   +1.5305808370
   Fax:
   NAa
   Olympic Valley, CA 96146
   US

Status: Locked

Name Servers:
   dns1.registrar-servers.com
   dns2.registrar-servers.com
   dns3.registrar-servers.com
   dns4.registrar-servers.com
   dns5.registrar-servers.com

Creation date: 05 May 2011 00:19:00
Expiration date: 04 May 2012 19:19:00</pre>
<p>The domain was registered yesterday at a low cost domain registrar and is now in use for spam campaigns. This domain is obviously registered in a bulk domain registrations with the intention to send spam from it for a while and then change domain again.</p>
<p>From this domain we have intercepted some other spam campaigns as well. Check them out:</p>
<blockquote><p>Bidooka</p>
<p>Apple products &#8211; It&#8217;s all at your fingertips</p>
<p>Be a part of the Hottest Online Shopping Craze since eBay</p>
<p>Bid Now<br />
hxxp://gy-qes.daukskosos.com/576ade776569dcd6338911a7e58cafabfd7233</p>
<p>Watch as the site unloads the biggest brand name products for pennies on the dollar</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
To unsubscribe please go here:<br />
hxxp://gy-qes.daukskosos.com/576ade776569dcd6338912a7e58cafabfd7233</p>
<p>or send mail to:<br />
Unsubscribe<br />
4759 Boles Ct<br />
Fremont, CA 94538</p>
<p>Click this link to unsubscribe: hxxp://gy-qes.daukskosos.com/a7e58cafabfd72333576ade776569dcd6</p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1403/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1403/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1403/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1403/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1403/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1403/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1403/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1403/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1403&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/05/06/spam-messages-using-the-linkedin-brand/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110506_spam.gif" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110506_spam_2.gif" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110506_spam_3.gif" medium="image" />
	</item>
		<item>
		<title>Receive a bonus of 2000 € &#8211; not everything is what it looks like</title>
		<link>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/</link>
		<comments>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 16:17:41 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[SMS scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1364</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercept a large spam campaign what in fact appears to be an SMS scam system. Email messages are sent from no-reply-xxx@finance-magazine.eu, where the XXX stands for random numbers. The domain finance-magazine.eu is from the The European CFO Magazine. Many different subjects in the French language are being used to get some attraction: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1364&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercept a large spam campaign what in fact appears to be an SMS scam system.</p>
<p>Email messages are sent from no-reply-xxx@finance-magazine.eu, where the XXX stands for random numbers. The domain finance-magazine.eu is from the The European CFO Magazine.</p>
<p>Many different subjects in the French language are being used to get some attraction:</p>
<p>Une offre qou vous ne pouvez pas refuser<br />
Une opportunite unique d&#8217;une vie<br />
Faire de l&#8217;argent n&#8217;a jamais ete aussi facile!<br />
Etes-vous interesse ?<br />
&#8230;</p>
<p>This is the email content:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_1.jpg" alt="" width="450" height="223" /></p>
<p>The embedded URLs directs visitors to hxxp://berborso.com/c/8D1DB23B.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_2.jpg" alt="" width="450" height="362" /></p>
<p>On this landing page you will need to fill in your details including your mobile phone number.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_3.jpg" alt="" width="450" height="468" /></p>
<p>When your details are submitted, you&#8217;ll receive an SMS with an activation code. This code needs to be filled in again on this webform together with some additional details.</p>
<p>I haven&#8217;t filled in my real phone number but I&#8217;m pretty sure that this is a complete SMS scam. I wouldn&#8217;t be suprised if you receive more SMS messages later on that are credited on your phone bill later on.</p>
<p>This domain name is registered in the Ukraine:</p>
<pre>Service Provided By: Center of Ukrainian Internet Names
Website: http://www.ukrnames.com
Contact: +380.577626123

Domain Name: BERBORSO.COM

Creation Date: 28-Mar-2011
Modification Date: 28-Mar-2011
Expiration Date: 28-Mar-2012

Domain servers in listed order:
ns1.hahray.in
ns2.hahray.in

Registrant:
Son Svan hdgi-domains@gmail.com
WATER STREET 45/54
CHRIST CHURCH, BB17056
BARBADOS
+1.24615566596</pre>
<p>Be carefull if you receive offers like this.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1364/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1364&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_3.jpg" medium="image" />
	</item>
		<item>
		<title>Canadian Pharmacy pops up in emails from Facebook with subject &#8220;Welcome to Facebook Goods&#8221;</title>
		<link>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/</link>
		<comments>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 10:06:47 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[facebook spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1355</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new spam campaign, since yesterday, by email with the subject &#8220;Welcome to Facebook Goods&#8221;. These messages are sent from the spoofed email addresses in the format that Facebook is using on the domain facebookmail.com. Some examples: update+bscts2qxhedj@facebookmail.com update+6i8mlfxn1svw@facebookmail.com update+6i8mlfxn1svw@facebookmail.com &#8230; This is the body of the email: Notice [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1355&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu/" target="_blank">http://www.mxlab.eu</a>, started to intercept a new spam campaign, since yesterday, by email with the subject &#8220;Welcome to Facebook Goods&#8221;. These messages are sent from the spoofed email addresses in the format that Facebook is using on the domain facebookmail.com. Some examples:</p>
<p>update+bscts2qxhedj@facebookmail.com<br />
update+6i8mlfxn1svw@facebookmail.com<br />
update+6i8mlfxn1svw@facebookmail.com<br />
&#8230;</p>
<p>This is the body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_Facebook_CanPharm.jpg" alt="" width="450" height="363" /></p>
<p>Notice that the Facebook looks are used to disguise the real purpose of the message.</p>
<p>4 different URLs are used in each message with the format: http://www.domainhere.tld/s/h/o/p/ that will redirect you to the Canadian Pharmacy at hxxp://midiclxic.ru/.</p>
<p>&nbsp;</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1355/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1355&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_Facebook_CanPharm.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Download Adobe Reader 10 Alternative scam</title>
		<link>http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/</link>
		<comments>http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 05:58:20 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Adobe reader]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[PDF 2011]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1353</guid>
		<description><![CDATA[MX Lab reported earlier on regarding a malicious spam campaign regarding an offer to download and buy PDF Reader/Writer for Windows and Mac in the articles Malicious spam campaign regarding Adobe Acrobat 2010 PDF Reader and VOIP Addons for Skype and Emails offering PDF Reader 2010 lead to unsecure payment site. MX Lab noticed a new version [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1353&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mxlab.eu" target="_blank">MX Lab</a> reported earlier on regarding a malicious spam campaign regarding  an offer to download and buy PDF Reader/Writer for Windows and Mac in  the articles<a href="http://blog.mxlab.eu/2010/09/14/malicious-spam-campaign-regarding-adobe-acrobat-2010-pdf-reader-and-voip-addons-for-skype/" target="_blank"> Malicious spam campaign regarding Adobe Acrobat 2010 PDF Reader and VOIP Addons for Skype</a> and<a href="http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/" target="_blank"> Emails offering PDF Reader 2010 lead to unsecure payment site</a>.</p>
<p>MX Lab noticed a new version that will offer the latest PDF Reader. The emails have the subject &#8220;Download Adobe Reader 10 Alternative&#8221;  with the email address dailynews_dec09@m120.redmediaone.com.</p>
<p>This is the body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_1.jpg" alt="" width="450" height="591" /></p>
<p>Following the link to the web site will lead us here:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_2.jpg" alt="" width="450" height="321" /></p>
<p>When clicking on the download button we have the following screen that looks very familiar:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_3.jpg" alt="" width="450" height="325" /></p>
<p>Okay, let&#8217;s go throught the registration process:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_4.jpg" alt="" width="450" height="351" /></p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_5.jpg" alt="" width="450" height="381" /></p>
<p>The registration transactions are performed on the domain secure-signupway.com. This domain is know for fraudulent payment processing so your credit card details will end up in the wrong hands.</p>
<p>Now, this is also interesting. The domain from where the message is sent, redmediaone.com, has protected registrant details in the WHOIS.</p>
<pre>Registrant:
   redmediaone.com
   c/o Whois Privacy Service
   PO BOX 501610
   San Diego, CA 92150-1610
   US

   Domain Name: REDMEDIAONE.COM

   Administrative Contact, Technical Contact, Zone Contact:
      redmediaone.com
      c/o Whois Privacy Service
      PO BOX 501610
      San Diego, CA 92150-1610
      US
      (619) 393-2111
      whois@emailaddressprotection.com

   Domain created on 18-May-2010
   Domain expires on 17-May-2012
   Last updated on 25-Mar-2011

   Domain servers in listed order:

      NS1.DOMAINDISCOVER.COM
      NS2.DOMAINDISCOVER.COM
</pre>
<p>In the message is the download URL and an unsubscribe URL present that is handled by http://list.onemediaclick.com/. And also iin this case, the registrant details are protected.</p>
<pre>Domain Name: ONEMEDIACLICK.COM
Registrar: MONIKER

Registrant [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US

Administrative Contact [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US
        Phone: +1.9549848445
        Fax:   +1.9549699155

Billing Contact [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US
        Phone: +1.9549848445
        Fax:   +1.9549699155

Technical Contact [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US
        Phone: +1.9549848445
        Fax:   +1.9549699155

Domain servers in listed order:

        NS1.DOMAINSERVICE.COM         208.73.210.41
        NS2.DOMAINSERVICE.COM         208.73.211.42
        NS3.DOMAINSERVICE.COM
        NS4.DOMAINSERVICE.COM

        Record created on:        2011-02-14 12:05:30.0
        Database last updated on: 2011-02-14 12:05:32.93
        Domain Expires on:        2012-02-14 12:05:31.0
</pre>
<p>The web site of  Onemediaclick:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_6.jpg" alt="" width="450" height="426" /></p>
<p>These guys are, according to the address on the site, located in Switzerland. When trying to contact them through the web form, nothing happens. The &lt;form&gt; tags are not included in the web form when looking at the source. Seems to me that this whole business can not be trusted.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1353/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1353&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_3.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_4.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_5.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_6.jpg" medium="image" />
	</item>
		<item>
		<title>Botnet Rustock is no longer</title>
		<link>http://blog.mxlab.eu/2011/03/28/botnet-rustock-is-no-longer/</link>
		<comments>http://blog.mxlab.eu/2011/03/28/botnet-rustock-is-no-longer/#comments</comments>
		<pubDate>Mon, 28 Mar 2011 08:57:23 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Rustock]]></category>
		<category><![CDATA[Waldec]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1305</guid>
		<description><![CDATA[As you may have read on several news sites, the botnet Rustock, one of the world’s most active spam-generating networks, is no longer since last week (R.I.P. ) on March 16th, 2011. The Microsoft Digital Crimes Unit (or DCU), together with other agencies and organisation like the U.S. Marshalls, started an operation, under the name &#8220;Operation [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1305&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As you may have read on several news sites, the botnet Rustock, one of the world’s most active spam-generating networks, is no longer since last week (R.I.P. <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ) on March 16th, 2011.</p>
<p>The Microsoft Digital Crimes Unit (or DCU), together with other agencies and organisation like the U.S. Marshalls, started an operation, under the name &#8220;Operation b107&#8243;, to take out the C&amp;C servers at multiple locations in the US, which are responsible for managing the infected zombie computers in the botnet, leading the botnet decapitated.</p>
<p>The Rustock botnet was one of the major players on the internet when it comes to spam and infected zombie computers. With an estimated account of approx 1 million infected computers it had a capacity for sending out up to 30 billion spam messages per day ranging from fake Microsoft lottery scams and offers for prescription drugs.</p>
<p>It was not the first attempt of Microsoft to take down an botnet organisation. Earlier on, in February 2010, Microsoft did managed to get hands on +250 domains  that where used in <a href="http://blogs.technet.com/b/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx" target="_blank">the Waladec botne</a>t.</p>
<p>&nbsp;</p>
<p>Read more about Rustock and the take down:</p>
<p>Microsoft: <a href="http://blogs.technet.com/b/microsoft_on_the_issues/archive/2011/03/18/taking-down-botnets-microsoft-and-the-rustock-botnet.aspx" target="_blank">Taking Down Botnets: Microsoft and the Rustock Botnet</a></p>
<p>Wall Street Journal:  <a href="http://online.wsj.com/article/SB10001424052748703328404576207173861008758.html?mod=WSJ_Tech_LEFTTopNews#printMode" target="_blank">Spam Network Shut Down</a></p>
<p>FireEye: <a href="http://blog.fireeye.com/research/2011/03/an-overview-of-rustock.html" target="_blank">An overview of Rustock</a></p>
<p>Krebs On Security: <a href="http://krebsonsecurity.com/2011/03/homegrown-rustock-botnet-fed-by-u-s-firms/" target="_blank">Rustock Botnet Fed by U.S. Firms</a></p>
<p><a href="http://krebsonsecurity.com/2011/03/homegrown-rustock-botnet-fed-by-u-s-firms/" target="_blank"></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1305/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1305&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/28/botnet-rustock-is-no-longer/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>
