<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam</title>
	<atom:link href="http://blog.mxlab.eu/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Tue, 09 Mar 2010 15:11:21 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab &#8211; all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Email with subject &#8220;scan upon download&#8221; contains trojan</title>
		<link>http://blog.mxlab.eu/2010/03/09/email-with-subject-scan-upon-download-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/03/09/email-with-subject-scan-upon-download-contains-trojan/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 14:36:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[TibsPk-D]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=786</guid>
		<description><![CDATA[MX Lab started to intercept a few emails with the subject &#8220;scan upon download&#8221; coming from randomly spoofed email addresses.
The trojan is named Suspicious:W32/Malware!Gemini (F-Secure) or Mal/TibsPk-D (Sophos) and is able to create malicious executable files on the infected system.
The body of the email:
Dear Sirs,
We have prepared a contract and added the paragraphs that you [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=786&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept a few emails with the subject &#8220;scan upon download&#8221; coming from randomly spoofed email addresses.</p>
<p>The trojan is named Suspicious:W32/Malware!Gemini (F-Secure) or Mal/TibsPk-D (Sophos) and is able to create malicious executable files on the infected system.</p>
<p>The body of the email:</p>
<blockquote><p>Dear Sirs,<br />
We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree with all the provisions we are ready to make the payment on Friday for the first consignment. We are enclosing the file with the prepared contract.</p></blockquote>
<p>The email has the ZIP archive attached named Contract.zip, a 202 kB large file, and once extracted an executable file named Contract.exe appears.</p>
<p>The following files are created:</p>
<p>%AppData%\av.exe<br />
%AppData%\v7LsGuo3u6bku</p>
<p>A new process is created:</p>
<p>%AppData%\av.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/9b32a91c218314c78c53d85da50d653e37687490db454a7f345dbc40fb7866ff-1268137725" target="_blank">permlink</a> and MD5: 99b165be9e35f83b811925ccbb9be36d.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/786/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/786/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/786/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/786/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/786/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/786/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/786/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/786/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/786/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/786/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=786&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/09/email-with-subject-scan-upon-download-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Directory scam: Registration of the World Business Directory 2010/2011</title>
		<link>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/</link>
		<comments>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 10:05:14 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[directory scam]]></category>
		<category><![CDATA[EU Business Services Ltd]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[World Business Directory]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=778</guid>
		<description><![CDATA[MX Lab reported in 2009 about the misleading marketing trick that the World Business Directory uses. Guess what, they are back!
MX Lab received a new registration form from the World Business Directory and again, we want to point out a few things before you sign their contract.
The email comes from info@companyworld2010.com, with the subject &#8220;Registration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=778&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab reported in 2009 about <a href="http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/" target="_blank">the misleading marketing trick that the World Business Directory uses</a>. Guess what, they are back!</p>
<p>MX Lab received a new registration form from the World Business Directory and again, we want to point out a few things before you sign their contract.</p>
<p>The email comes from info@companyworld2010.com, with the subject &#8220;Registration of the World Business Directory 2010/2011&#8243; and this is the email content:</p>
<blockquote><p>Dear Madam/Sir,</p>
<p>In order to have your company registered in the World Business<br />
Directory for 2010/2011, please print, complete and return the<br />
enclosed form (PDF file) to the following address:</p>
<p>World Business Directory<br />
Suite 149 &#8211; Rosden House &#8211; 372 Old Street<br />
EC1V 9AU / London &#8211; United Kingdom<br />
E-mail: office@companyworld2010.com<br />
Fax: +44 207 806 8157</p>
<p>Updating is free of charge!</p>
<p>To unsubscribe, please send an email to<br />
unsubscribe@companyworld2010.com</p></blockquote>
<p>Attached is a PDF file named world-businessdirectory.pdf.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100309_wbdir.gif" alt="" width="450" height="619" /></p>
<p>The 1st point that needs your attention is the text block 1:</p>
<blockquote><p>To update your company profile, please print, complete and return<br />
this form (Updating is free of charge). Only sign if you want to<br />
place an insertion.</p></blockquote>
<p>As you can read, updating is free of charge but if you want your company get listed in this directory you will need to sign and have to pay.</p>
<p>What is the price of this directory you may ask yourself? Well, you have to go to text block 2 with the very small letters and this includes:</p>
<blockquote><p>I WILL HAVE AN INSERTION INTO ITS DATA BASE FOR THREE YEARS. THE PRICE PER YEAR IS GBP 980.</p></blockquote>
<p>And there you have it, this contract will cost your business a total amount of GBP 2940 over 3 years. After the 3 years subscription you can stop your contract if you inform them on time:</p>
<blockquote><p>THE SUBSCRIPTION WILL BE AUTOMATICALLY EXTENDED EVERY YEAR FOR ANOTHER YEAR, UNLESS SPECIFIC WRITTEN NOTICE IS RECEIVED BY THE SERVICE PROVIDER OR THE SUBSCRIBER TWO MONTHS BEFORE THE EXPIRATION OF THE SUBSCRIPTION.</p></blockquote>
<p>A few arguments from our side that this is a scam:</p>
<p>The from email address contains the domain companyworld2010.com and when trying to see if there is a site online we got the notification &#8220;This account has been suspended&#8221;. We might see new emails from the World Business Directory appear with other domains.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100309_wbdir_2.gif" alt="" width="450" height="208" /></p>
<p>When getting some WHOIS information on the domain we got the following:</p>
<table border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td></td>
<td colspan="4">
<pre>Registrant:
 international group c/o Free Private Reg
 P.O. Box 81024
 Burnaby, BC V5H 4K2
 CA

 Domain name: COMPANYWORLD2010.COM

 Administrative Contact:
    boot, cornelis  companyworld2010.com@freeprivateregistration.com
    P.O. Box 81024
    Burnaby, BC V5H 4K2
    CA
    852-3594-1708
 Technical Contact:
    Hostmaster, Domain  hostmaster@doteasy.com
    Suite 210 - 3602 Gilmore Way
    Burnaby, BC V5G 4W9
    CA
    (604) 434-4307    Fax: (604) 608-6832

 Registrar of Record: In2net Network Inc.
 Record last updated on 05-Mar-2010.
 Record expires on 05-Mar-2011.
 Record created on 05-Mar-2010.

 Domain servers in listed order:
    DNS8.DOTEASY.COM   65.61.199.14
    DNS7.DOTEASY.COM   65.61.198.14

 Domain status: clientTransferProhibited
                clientUpdateProhibited</pre>
</td>
</tr>
</tbody>
</table>
<p>The registrant information is rather vague and points to a PO Box and the administrative contact has the same address. The domain freeprivateregistration.com in the email address of the administrative contact is just a domain alias from doteasy.com. These details must be fake.</p>
<p>In 2009, the PDF document needed to be returned to an address in The Netherlands, in this 2010/2011 edition it needs to be returned to an address in London, UK.</p>
<p>When visiting their site at <a href="http://www.world-businessdirectory.com/" target="_blank">http://www.world-businessdirectory.com/</a> on the &#8216;About us&#8217; page we found the following text:</p>
<blockquote><p>The World Business Directory online is product of EU Business Services Ltd, a corporation organized and existing under the laws of Nevis, West Indies.</p></blockquote>
<p>We also  found the UK address on the &#8216;Contact us&#8217; page.</p>
<p>Our recommendation is: <strong>don&#8217;t sign the document and don&#8217;t do business with this company</strong>.</p>
<p>Follow these guidelines if  you are a victim of this directory scam:</p>
<ul>
<li>Do not pay, even if they imply to take your case to court.</li>
<li>If you have paid a certain amount, stop the next payments. Expect that you won&#8217;t get a refund either.</li>
<li>Send them a letter informing them you have been misled and telling them to cancel the contract.</li>
<li>If possible, report to (local) authorities.</li>
</ul>
<p>Additional information:</p>
<p><a href="http://stopecg.org/world_business_directory.htm" target="_blank">Stop EU Business Services Ltd Trading As World Business Directory</a><br />
<a href="http://www.stopwbd.za.org/" target="_blank">Stop world-businessdirectory.com</a></p>
<p>On the <a href="http://www.richardcorbett.org.uk/directoryscams.htm" target="_blank">web site of Richard Corbett</a> you can find some background information about directory scams and what to do when you are a victim of such a scam.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/778/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=778&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100309_wbdir.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100309_wbdir_2.gif" medium="image" />
	</item>
		<item>
		<title>Web site creator hosts are being abused in spam campaigns</title>
		<link>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/</link>
		<comments>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 11:30:46 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=773</guid>
		<description><![CDATA[Spammers are not afraid to abuse community sites or blog creators like blogspot.com in their spam campaigns. In some cases, the content is published on these site or a redirect is embedded and forwards the visitor to the web site of their choice offering porn, pills and other stuff.
MX Lab noticed an increase the last [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=773&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers are not afraid to abuse community sites or blog creators like blogspot.com in their spam campaigns. In some cases, the content is published on these site or a redirect is embedded and forwards the visitor to the web site of their choice offering porn, pills and other stuff.</p>
<p>MX Lab noticed an increase the last few days of URLs in spam messages that point to (free) web site creater hosts or less well know blog creators. Some of the latest victims are doodlekit.com, sitekreator.com, webs.com, webstarts.com and blogdrive.com.</p>
<p>Some examples of the spam:</p>
<blockquote><p>of necromancer beyond power drill ostensibly wily<br />
dissidents customer<br />
PornstarMikaTanAnalFingering hxxp://trhombic.blogdrive.com<br />
because girls</p></blockquote>
<blockquote><p>dissidents blotched greedily</p>
<p>mirror about starlet likeable<br />
WorldOfLustyAmatteurGalsFujckkingOnCameraWithBigCodfckedLadsAndBelovedSelxToys hxxp://sitekreator.com/Dewtty/sdfgty.html</p>
<p>haunchestoward</p></blockquote>
<blockquote><p>for cleavage inside carelessly womanly<br />
bubble baths scythe<br />
AsianSuckingAndFuckingHardcore hxxp://wilfredorz.webs.com<br />
or tea parties</p></blockquote>
<blockquote><p>over and accidentally</p>
<p>tea parties flabby<br />
WorldOfLustyAmatenurGalsFujckkingOnCameraWithBigCobckedLadsAndBelovedSjexToys hxxp://s2.webstarts.com/ssey/q2.html</p>
<p>philosopherssecretly</p></blockquote>
<p>What we also notice is the use of random words in the spam message again. This is a very common technique being used in the past to avoid detected by Bayesian filters and/or to compromise and corrupt the knowledge database of the Bayesian filter when the message is used to train the filter.</p>
<p>This technique is also present in the latest spam campaign of the Canadian Pharmacy:</p>
<blockquote><p>This is a link to our shop http://bc.greatsilent.ru/</p>
<p>gazoive dyojefip eicyla uxamo kajoubemi zitykiboto yejy<br />
irewyumuco izaafoe samin uypoi nyqii asydado<br />
hoxyaogeqa eokinap asiwy yziuboaxoj alomem kawuqyxy<br />
ajitikumoa fiaxe oqoce qiahow yvenouwa bosyebuje ucotaley<br />
yeqa uhybyo nidodyziru logu noboma uuju uedywaby<br />
&#8230;. (cut)&#8230;.</p></blockquote>
<p>New web site creator hosts are being used each day. When I visited a few of those web site creator host I found out that subscription is so easy to do. You can automate account requests quite easily up to a certain point without being blocked by some way of security measure or by clicking on an activation link by email.</p>
<p>On doodlekit.com we found a CAPTCHA security on the subscription web form but I believe that a good CAPTCHA should have letters that are less readable than this one. But, this is a start.</p>
<p>On webs.com I did set up a dummy web site account with the site address http://tryviagra.webs.com without any security measure! This means that anyone can set up an free web site creator account when completing the webforms.</p>
<p>In this particular case, I can even automate every step and let a bot do all the work for you. I could create from 10 to 100 accounts on a day and perhaps the site administrators wouldn&#8217;t even notice this. It is a very efficient way of getting coverage on the internet, getting free hosting for my site or redirect visitors to my site.</p>
<p>To make it worse, I can also place malware on this site and try to infect each visitor on my site with malware, ransomware or other malicious files.</p>
<p>As a spammer, I have the advantage over Intent Anyalisis tools or SURBL, tools that examine and block messages based on the included URLs, by generating mutliple URLs each day and changing URLs in the spam message.</p>
<p>Again, it shows that internet security is a responsability of everyone and everyone should get involved. If we want to stop spammers, we also have to make sure that some of the features that spammers have today &#8211; this is a nice example I think &#8211; can&#8217;t be used tomorrow.</p>
<p>Feel free to comment on this post.</p>
<p>Disclaimer: it is not our intention to attack webs.com on their lack of security &#8211; perhaps in a certain way it is &#8211; but to point out how easy it is to abuse certain online tools.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/773/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=773&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Email regarding Conflicker.B Infection Alert contains a trojan</title>
		<link>http://blog.mxlab.eu/2010/02/17/email-regarding-conflicker-b-infection-alert-contains-a-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/02/17/email-regarding-conflicker-b-infection-alert-contains-a-trojan/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 13:56:42 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Conflicker]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=769</guid>
		<description><![CDATA[MX Lab started to intercept emails with the subject &#8220;Conflicker.B Infection Alert&#8221;. The trojan is names Win32:Bredolab-CC (Avast), Generic Dropper.lr (McAfee) or Trojan.Win32.Bredolab.Gen.2 (Sunbelt).
The from address is spoofed and can contain &#8220;Microsoft Team&#8221;. The emails is signed by &#8220;Microsoft Windows Computer Safety Division&#8221; to make it appears that it is from Microsoft itself.
The email has the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=769&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept emails with the subject &#8220;Conflicker.B Infection Alert&#8221;. The trojan is names Win32:Bredolab-CC (Avast), Generic Dropper.lr (McAfee) or Trojan.Win32.Bredolab.Gen.2 (Sunbelt).</p>
<p>The from address is spoofed and can contain &#8220;Microsoft Team&#8221;. The emails is signed by &#8220;Microsoft Windows Computer Safety Division&#8221; to make it appears that it is from Microsoft itself.</p>
<p>The email has the attachment open.zip and inside the ZIP archive the executable open.exe (16 kB).</p>
<p>As you can read, the email contains instructions to use the attached file to scan your network after an detected virus infection by the Conflicker worm.</p>
<blockquote><p>Dear Microsoft Customer,</p>
<p>Starting 12/11/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.</p>
<p>To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.</p>
<p>Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.</p>
<p>Regards,<br />
Microsoft Windows Agent #2 (Hollis)<br />
Microsoft Windows Computer Safety Division</p></blockquote>
<p>At the time of writing, 21 of the 40 AV engines at Virus Total did detect the threat correctly. Our recommendation is that you never following instructions, send by email, like this one. Microsoft, or any other company, will spread security tools by email.</p>
<p>This trojan is a serious security risk because it will display fake alerts regarding a virus infection in order to lead you to buy rogue anti virus/anti spyware products. The trojan also has the capabilities to send out emails with a build-in SMTP engine.</p>
<p>A new windows will be created after executing the file open.exe:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100217_rogueAV_1.gif" alt="" width="248" height="130" /></p>
<p>The following files are created:</p>
<p>%CommonAppData%\28701826\28701826.exe<br />
%DesktopDir%\Security Tool.lnk<br />
%Programs%\Security Tool.lnk<br />
%Windir%\Temp\_ex-08.exe</p>
<p>The following directory is created:</p>
<p>%CommonAppData%\28701826</p>
<p>New processes are created:</p>
<p>_ex-08.exe in %Windir%\temp\_ex-08.exe<br />
28701826.exe in C:\DOCUME~1\ALLUSE~1\APPLIC~1\28701826\28701826.exe</p>
<p>The Windows registry will be modified and the malware can open the TCP ports 1066 and 1067 ports on an infected system.</p>
<p>Connection to remote hosts (port 80):</p>
<p>221.150.130.37<br />
94.102.50.131<br />
95.143.192.40</p>
<p>Remote downloands:</p>
<p>    * hxxp://221.150.130.37/qmbzxqbitqs.htm<br />
    * hxxp://221.150.130.37/gyxk.htm<br />
    * hxxp://221.150.130.37/xwxwkg.htm<br />
    * hxxp://94.102.50.131/in.php?affid=43400&amp;url=5&amp;win=Windows%20XP+2.0&amp;sts=<br />
    * hxxp://95.143.192.40/pr/pic/sys.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/22b4d35e6310d11ceebb046d7eede09a83c8489121dbb492fbd7702d6eb2fe8d-1266412310" target="_blank">permlink</a> and MD5: 76cf8a523c11f4d2ab86a7b99c89c9e0.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/769/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=769&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/17/email-regarding-conflicker-b-infection-alert-contains-a-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100217_rogueAV_1.gif" medium="image" />
	</item>
		<item>
		<title>Spam campaign from Canadian Pharmacy also contains web based threats</title>
		<link>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/</link>
		<comments>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 09:46:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[HTML exploits]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=766</guid>
		<description><![CDATA[MX Lab detected several email based threats in a spam campaign from Canadian Pharmacy masked as an order confirmation of Amazon.

The campaign comes from the spoofed email address Customer Support &#60;***.***@service.amazon.com&#62; and has the possible following subjects (*** numbers will vary):
Confirm #***
Confirmation Order #***
Notice #***
Notify #***
Notification #***
Order Confirmation #***
Order Notice #***
Order Notify #***
Order Notification #***
The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=766&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected several email based threats in a spam campaign from Canadian Pharmacy masked as an order confirmation of Amazon.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>The campaign comes from the spoofed email address Customer Support &lt;***.***@service.amazon.com&gt; and has the possible following subjects (*** numbers will vary):</p>
<p>Confirm #***<br />
Confirmation Order #***<br />
Notice #***<br />
Notify #***<br />
Notification #***<br />
Order Confirmation #***<br />
Order Notice #***<br />
Order Notify #***<br />
Order Notification #***</p>
<p>The body of the email:</p>
<blockquote><p>Your Order S\n:10444064511 Accepted.<br />
Details hxxp://www.klaudiusz.ramtel.pl/afrikaners.html</p>
<p>Thank you.<br />
Amazon.com Customer Support</p></blockquote>
<p>The campaign is detected yesterday but today we found a few threaths when following the included URLs. One threat was named HTML:iFrame-LZ[Trj] (Avast).</p>
<p>HTML:iFrame-LZ[Trj] is a malicious HTML script that may be downloaded unknowingly by a user when visiting malicious Web sites. The script will make connection to sites to download file(s). As a result, malicious routines of the downloaded files are exhibited on the affected system.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/766/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=766&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>Twitter, Google and Hi5 being abused in Prolaco worm distribution</title>
		<link>http://blog.mxlab.eu/2010/02/10/twitter-google-and-hi5-being-abused-in-prolaco-worm-distribution/</link>
		<comments>http://blog.mxlab.eu/2010/02/10/twitter-google-and-hi5-being-abused-in-prolaco-worm-distribution/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 23:12:06 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Prolaco]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=754</guid>
		<description><![CDATA[Twitter, Google and the social networking site Hi5 are being abused in an email campaign to distribute the Prolaco worm. The campaigns have the following characteristics. Note that the email addresses are spoofed.
The malware is known as Worm.Win32.Prolaco.gen (Sunbelt), Worm:Win32/Prolaco.gen!C (Microsoft) and Worm.Win32.Prolaco (Ikarus).
Twitter
From: &#60;invitations@twitter.com&#62;
Subject: Your friend invited you to twitter!
Attachment: Invitation Card.zip (approx 348 kB)
Body [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=754&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Twitter, Google and the social networking site Hi5 are being abused in an email campaign to distribute the Prolaco worm. The campaigns have the following characteristics. Note that the email addresses are spoofed.</p>
<p>The malware is known as Worm.Win32.Prolaco.gen (Sunbelt), Worm:Win32/Prolaco.gen!C (Microsoft) and Worm.Win32.Prolaco (Ikarus).</p>
<p><strong>Twitter</strong></p>
<p>From: &lt;invitations@twitter.com&gt;<br />
Subject: Your friend invited you to twitter!</p>
<p>Attachment: Invitation Card.zip (approx 348 kB)</p>
<p>Body of the email:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100210_prolaco_1.jpg" alt="" width="450" height="156" /></p>
<p>In this campaign, Twitter is being used to get the attachment clicked upon. The email instructs you to open the attachment to see who invited you on Twitter.</p>
<p><strong>Google</strong></p>
<p>From: &lt;resume-thanks@google.com&gt;<br />
Subject: Thank you from Google!</p>
<p>Attachment: CV-20100120-112.zip (approx 348 kB)</p>
<p>Body of the email:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100210_prolaco_2.jpg" alt="" width="450" height="354" /></p>
<p>Google is thanking you for the resume that you send to them for an open position. To review your submitted application you should open the attachment, according to the instructions in the email.</p>
<p><strong>Hi5</strong></p>
<p>From: &lt;invitations@hi5.com&gt;<br />
Subject: Jessica would like to be your friend on hi5!</p>
<p>Attachment: Invitation Card.zip (approx 348 kB)</p>
<p>Body of the email:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100210_prolaco_3.jpg" alt="" width="450" height="274" /></p>
<p>The social network Hi5 has been used in previous campaigns and also in phishing campaigns. This time you are invited to connect to Jessica and she has attached her invitation card for you to open.</p>
<p>Be aware, that when you connect to a person on Hi5, or want to follow a person on Twitter, you never have to download and install a piece of software, in these cases malware. All actions are done through their web sites so do not attempt to open the attachments in similar future campaigns.</p>
<p>About Prolaco:</p>
<p>Prolaco will create the following files on your system:</p>
<p>%AppData%\SystemProc\lsass.exe<br />
%ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul<br />
%ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest<br />
%ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf<br />
%System%\GoogleUpdater.exe </p>
<p>The following directories are created:</p>
<p>%AppData%\SystemProc<br />
%ProgramFiles%\Mozilla Firefox<br />
%ProgramFiles%\Mozilla Firefox\extensions<br />
%ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}<br />
%ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome<br />
%ProgramFiles%\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content</p>
<p>The following services are modified:</p>
<p>ERSvc	Error Reporting Service<br />
&#8220;Stopped&#8221;	%System%\svchost.exe -k netsvcs</p>
<p>wscsvc	Security Center<br />
&#8220;Stopped&#8221;	%System%\svchost.exe -k netsvcs</p>
<p>The trojan will modify the Windows registry and can make UDP connections over port 1069 and 1070.</p>
<p>27 out of the 41 AV engines detect the Prolaco worm at the time of writing this article.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/b9c0caf85609633cf87a21768e8729ec5097e11490631da7136bafa44b3ebe55-1265724751" target="_blank">permlink</a> and MD5: c0464909947c92c07f5a91f9d675f03d</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/754/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/754/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/754/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/754/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/754/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/754/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/754/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/754/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/754/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/754/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=754&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/10/twitter-google-and-hi5-being-abused-in-prolaco-worm-distribution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100210_prolaco_1.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100210_prolaco_2.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100210_prolaco_3.jpg" medium="image" />
	</item>
		<item>
		<title>&#8220;updated account agreement&#8221; email contains Bredolab trojan</title>
		<link>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 22:26:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=751</guid>
		<description><![CDATA[MX Lab started to intercept emails with the subject &#8220;updated account agreement&#8221; that contains the Bredolab trojan. The campaign is designed for Facebook users because of the content. The email comes from the spoofed email address and contains &#8220;Facebook Team&#8221;.
The body of the email:
Dear Facebook user,
Due to Facebook policy changes, all Facebook users must submit [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=751&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept emails with the subject &#8220;updated account agreement&#8221; that contains the Bredolab trojan. The campaign is designed for Facebook users because of the content. The email comes from the spoofed email address and contains &#8220;Facebook Team&#8221;.</p>
<p>The body of the email:</p>
<blockquote><p>Dear Facebook user,</p>
<p>Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date.</p>
<p>Accounts that do not submit the updated account agreement by the deadline will have restricted.</p>
<p>Please unzip the attached file and run “agreement.exe” by double-clicking it.</p>
<p>Thanks,<br />
The Facebook Team</p></blockquote>
<p>The email has the ZIP archive agreement.zip attached, once unpacked the file 28 kB big file agreement.exe is available.</p>
<p>Facebook, or any other company, will never distribute agreements,  software updates and patches or anything else in emails. Our recommendation is to delete the email immediatly because a lot of AV engines do not detect this variant very well at the moment.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/3eea167a650a747dad1ec304cf2f46ffaa9be273152d723aeda6d908cf8023d8-1265839538" target="_blank">permlink</a> and MD5: cc632e1dad8775e2bb558a6cd247b94b.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/751/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=751&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Bredolab trojan on the move</title>
		<link>http://blog.mxlab.eu/2010/02/04/bredolab-trojan-on-the-move/</link>
		<comments>http://blog.mxlab.eu/2010/02/04/bredolab-trojan-on-the-move/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 16:52:50 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=747</guid>
		<description><![CDATA[MX Lab noticed an increase in intercepted Bredolab trojan variants that are spread by email. The Bredolab variants are distributed by different campaigns.
Do you like to find a girlfriend like me ?
One campaign has the subject &#8220;Do you like to find a girlfriend like me ?&#8221; and targets female singles in a certain way:
Wish to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=747&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab noticed an increase in intercepted Bredolab trojan variants that are spread by email. The Bredolab variants are distributed by different campaigns.</p>
<p><strong>Do you like to find a girlfriend like me ?</strong></p>
<p>One campaign has the subject &#8220;Do you like to find a girlfriend like me ?&#8221; and targets female singles in a certain way:</p>
<blockquote><p>Wish to have a boyfriend<br />
Be able to protect me, take care of me<br />
Intolerable lonely night and would like to have your care.<br />
do you Willing ?</p>
<p>This is my photos.</p></blockquote>
<p>The email includes a ZIP archive named myphotos.zip which indicated that you will see some pictures. Instead the archive includes the file myphoto.exe which is the Bredolab trojan.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/c95c3fb721abf1255f82e851b18c94716c7e675a7bc51b9cc21ef36a2b2afa1e-1265281447" target="_blank">permlink</a> and MD5: 63936bfd3c1207ef3d2cce7b52d508da.</p>
<p><strong>DHL Office. Please get your parcel NR.6161</strong></p>
<p>The second campaign is the tradional failed package delivery style, in this case DHL coming from the spoofed email address &lt;support@dhl.com&gt;. Following subject are used:</p>
<p>DHL Office. Please get your parcel NR.6161<br />
DHL Express. Please get your parcel NR.6161<br />
DHL Express Services. You need to get a parcel NR. 3050<br />
DHL International. You need to get a parcel NR. 3050<br />
DHL Services. Please get your parcel NR. 1608<br />
DHL Customer Services.  Please get your parcel NR. 3528</p>
<p>Body of the email:</p>
<blockquote><p>Hello!</p>
<p>The courier service was not able to deliver your parcel at your address.</p>
<p>Cause: Mistake in address</p>
<p>You may pickup the parcel at our post office personally.</p>
<p>The delivery advice is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Services.</p></blockquote>
<p>There is also a Spanish version of the campaign with the spoofed email address &lt;support@dhl.es&gt; with the subject &#8220;DHL servicios. Recibir parcela NR.82140&#8243; and the email body:</p>
<blockquote><p>Estimado Cliente</p>
<p>El mensajero de nuestra Compañía no pudo entregarle el envío en su domicilio.<br />
Causa: Error en la indicación del domicilio de entrega.<br />
Puede recibir su envío personalmente en la oficina de correos cercana a su domicilio.</p>
<p>Atención!<br />
A esta carta se le adjunta una etiqueta postal. Usted debe imprimir la etiqueta para poder recibir el envío en la oficina de correos.</p>
<p>Gracias.<br />
DHL servicios.</p></blockquote>
<p><strong>UPS Delivery Problem NR 66466.</strong></p>
<p>The third campaign in also failed package delivery style but with UPS &#8216;branding&#8217; from the spoofed from address &lt;service@ups.com&gt;. Subject is UPS Delivery Problem NR 66466 and and example of the body of the email:</p>
<blockquote><p>Dear customer!</p>
<p>Unfortunately we were not able to deliver the package sent on the 24th of January in time<br />
because the addressee&#8217;s address is not correct.<br />
Please print out the invoice copy attached and collect the package at our office.</p>
<p>United Parcel Service of America.</p></blockquote>
<p>The UPS and DHL trojans have the same MD5 are are the same variant. At the time of writting this article only 14 of the 40 AV engines pick up the trojan well.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/efece73178abfe2335c088cf9d1145d24ac0ee7828d6b1b368b77e944f51b110-1265283514" target="_blank">permlink</a> and MD5:574f07d83aeae631834ff8279af8c1ed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/747/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=747&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/04/bredolab-trojan-on-the-move/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Win a Macbook Air and get the trojan Obfuscator for free</title>
		<link>http://blog.mxlab.eu/2010/02/03/win-a-macbook-air-and-get-the-trojan-obfuscator-for-free/</link>
		<comments>http://blog.mxlab.eu/2010/02/03/win-a-macbook-air-and-get-the-trojan-obfuscator-for-free/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 18:02:19 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=744</guid>
		<description><![CDATA[MX Lab intercepted emails with the subject &#8220;Congratulation!!&#8221;. The message informs you that you have won an Apple MacBook Air and for more details you will need to open the attached file.
Congratulations!! You have won todays Macbook Air.
Please open attached file and see details.
Seems tempting but by doing so you will in fact unleash the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=744&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted emails with the subject &#8220;Congratulation!!&#8221;. The message informs you that you have won an Apple MacBook Air and for more details you will need to open the attached file.</p>
<blockquote><p>Congratulations!! You have won todays Macbook Air.<br />
Please open attached file and see details.</p></blockquote>
<p>Seems tempting but by doing so you will in fact unleash the trojan VirTool:Win32/Obfuscator.HG (Microsoft) or Suspicious:W32/Malware!Online (F-Secure) on your system.</p>
<p>The attached file is named winner.zip, 45 kB large, and contains the 52 kB large executable winner.exe.</p>
<p>The trojan will create the following files:</p>
<p>%UserProfile%\reader_s.exe<br />
%System%\reader_s.exe</p>
<p>New processes ware created:</p>
<p>%System%\reader_s.exe<br />
%UserProfile%\reader_s.exe</p>
<p>Windows registry modifications are done to make sure that the services run when the Windows boots:</p>
<p># [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]<br />
* reader_s = &#8220;%System%\reader_s.exe&#8221;<br />
# [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]<br />
* reader_s = &#8220;%UserProfile%\reader_s.exe&#8221;</p>
<p>At the time of writing this article, only 8 of the 40 AV engines picked up the trojan when submitted to Virus Total so be carefull when receiving it. Virus Total <a href="http://www.virustotal.com/analisis/7791955e9859924a74f53b3c8a53dfda63c0d64da7fbfba364a372065e239e2c-1265213631" target="_blank">permlink</a> and MD5: 4ea90acf8a6427060f1a6d003dd3598f.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/744/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/744/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/744/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/744/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/744/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/744/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/744/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/744/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/744/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/744/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=744&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/03/win-a-macbook-air-and-get-the-trojan-obfuscator-for-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Email based update for Microsoft Outlook &#8211; Outlook Express contains trojan</title>
		<link>http://blog.mxlab.eu/2010/02/03/email-based-update-for-microsoft-outlook-outlook-express-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/02/03/email-based-update-for-microsoft-outlook-outlook-express-contains-trojan/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 00:36:28 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=741</guid>
		<description><![CDATA[MX Lab started to intercept messages with the subject &#8220;Update for Microsoft Outlook / Outlook Express (KB910721)&#8221;. These messages appear to come from the Microsoft Support department and contains instructions to install a new update for Microsoft Outlook / Outlook Express:
Brief Description
Microsoft has released an update for Microsoft Outlook / Outlook Express. This update is critical [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=741&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept messages with the subject &#8220;Update for Microsoft Outlook / Outlook Express (KB910721)&#8221;. These messages appear to come from the Microsoft Support department and contains instructions to install a new update for Microsoft Outlook / Outlook Express:</p>
<blockquote><p>Brief Description<br />
Microsoft has released an update for Microsoft Outlook / Outlook Express. This update is critical and provides you with the latest version of the Microsoft Outlook / Outlook Express and offers the highest levels of stability and security.</p>
<p>Instructions</p>
<p>* Install Update for Microsoft Outlook / Outlook Express (KB910721). To do this, follow these steps:<br />
1. Run attached file officexp-KB910721-FullFile-ENU.exe<br />
2. Restart Microsoft Outlook / Outlook Express</p>
<p>System Requirements</p>
<p>* Supported Operating Systems: Windows 2000; Windows 98; Windows ME; Windows NT; Windows Server 2003; Windows XP; Windows Vista</p>
<p>* This update applies to the following product: Microsoft Outlook / Outlook Express</p></blockquote>
<p>The email has the 12kB big ZIP archive named officexp-KB910721-FullFile-ENU.zip. The extracted file is the 24 kB big file officexp-KB910721-FullFile-ENU.exe.</p>
<p>This piece of malware is known as W32/SuspPack.BI.gen!Eldorado (F-Prot), W32/FakeAV.AM!genr (Norman) or Mal/FakeVirPk-A (Sophos).</p>
<p>It is generaly advised not to install software, updates or patches for Microsoft software or the operating system that is distributed by email. Microsoft will only offer updates and patches through the official Windows Update channel on the Windows system itself.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/2502888e66c20540f663b492595c2debadbe9860b84f30aac04921935aee1ae4-1265155340" target="_blank">permlink</a> and MD5: 925ca736b931a745b064896927cf20bc</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/741/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/741/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/741/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/741/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/741/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/741/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/741/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/741/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/741/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/741/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=741&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/03/email-based-update-for-microsoft-outlook-outlook-express-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>