<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam</title>
	<atom:link href="http://blog.mxlab.eu/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Sat, 04 Feb 2012 17:44:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails regarding rejected ACH payment contains security risk</title>
		<link>http://blog.mxlab.eu/2012/01/31/emails-regarding-rejected-ach-payment-contains-security-risk/</link>
		<comments>http://blog.mxlab.eu/2012/01/31/emails-regarding-rejected-ach-payment-contains-security-risk/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 19:08:02 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security risk]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1601</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subjects like: Rejected ACH transaction Rejected ACH payment Your ACH transfer &#8230; The email is send from the spoofed addresses like: &#8220;\&#8221;The Electronic Payments Association\&#8221; risk.manager&#8221;@nacha.org &#8220;\&#8221;The Electronic Payments Association\&#8221; alerts&#8221;@nacha.org &#8220;\&#8221;The Electronic Payments Association\&#8221; risk&#8221;@nacha.org &#8220;\&#8221;The Electronic Payments Association\&#8221; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1601&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subjects like:</p>
<p>Rejected ACH transaction<br />
Rejected ACH payment<br />
Your ACH transfer<br />
&#8230;</p>
<p>The email is send from the spoofed addresses like:</p>
<p>&#8220;\&#8221;The Electronic Payments Association\&#8221; risk.manager&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; alerts&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; risk&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; transfers&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; ach&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; payment&#8221;@nacha.org<br />
&#8230;</p>
<p>The email has the following body:</p>
<blockquote><p>The ACH transaction (ID: 02710822288793), recently sent from your checking account (by you or any other person), was rejected by the Electronic Payments Association.</p>
<p>Canceled transaction<br />
Transaction ID: 02710822288793<br />
Reason for rejection See details in the report below<br />
Transaction Report report_02710822288793.doc (Microsoft Word Document)</p>
<p>13450 Sunrise Valley Drive, Suite 100<br />
Herndon, VA 20171</p>
<p>2011 NACHA &#8211; The Electronic Payments Association</p></blockquote>
<p>A sample of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120131_ACH_risk.jpg" alt="" width="450" height="283" /></p>
<p>The URLs for the transaction report are different and in some cases no longer valid. Some examples:</p>
<p>hxxp://minalimo.com/f9oYYmiY/index.html<br />
hxxp://maerlipinte.ch/LaV4inWa/index.html<br />
hxxp://hotel-sicily.it/aRpcdCjd/index.html<br />
&#8230;</p>
<p>One of the URLs did give us a result: hxxp://ftp.samisalami.com/8KQZuSAy/index.html.</p>
<p>When investigating the HTML code of this web page we got the following:</p>
<blockquote><p>&lt;html&gt;<br />
&lt;h1&gt;WAIT PLEASE&lt;/h1&gt;<br />
&lt;h3&gt;Loading&#8230;&lt;/h3&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://firstnamestore.com/utn08WYD/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://ftp.adamsmarketing.com/VRssE3iH/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://mediapoolstarnberg.de/WrqeCaoy/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://paolomisirochi.com/nqrmZKRC/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://lonnytyler.com/MZF0uXsc/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://orquestrachapo.com/jAmCDzeM/js.js&#8221;&gt;&lt;/script&gt;</p>
<p>&lt;/html&gt;</p></blockquote>
<p>As you can see, some Javascripts are loaded when opening this web page. Some URLs to the javascripts are also obsolete but some of them returns the code: &#8220;document.location=&#8217;hxxp://sulusate.com/forum/index.php?showtopic=997439&#8242;;&#8221;.</p>
<p>The above URL gives us the web page with the following code:</p>
<blockquote><p>&lt;body&gt;<br />
&lt;applet code=&#8217;Verifa.class&#8217; archive=&#8217;rhi.jar&#8217; width=&#8217;24&#8242; height=&#8217;22&#8242;&gt;<br />
&lt;param name=&#8221;dest&#8221; value=&#8221;lxxt&gt;33wypywexi2gsq3jsvyq3pseh2tltCwls{jsvyqAvlmrs&#8221;&gt;<br />
&lt;/applet&gt;<br />
&lt;/body&gt;&lt;body&gt;<br />
&lt;applet code=&#8217;Ooo.class&#8217; archive=&#8217;Ooo.jar&#8217; width=&#8217;24&#8242; height=&#8217;22&#8242;&gt;<br />
&lt;param name=&#8221;dest&#8221; value=&#8221;lxxt&gt;33wypywexi2gsq3jsvyq3pseh2tltCwls{jsvyqAsfi&#8221;&gt;<br />
&lt;/applet&gt;<br />
&lt;/body&gt;</p></blockquote>
<p>When opening the URLs  in a web browser &#8211; something we do not recommend to even try &#8211; you will get redirected to bing.com or another web site so you won&#8217;t see this code.</p>
<p>It seems that some javascript is obfuscated and that .jar files are involved here inside an applet. The risk is that these applets in java could contain malicious code. Ooo.jar is however related to OpenOffice but in this case it can also be used for phishing.</p>
<p>This email is a security risk &#8211; a virus or a phishing attempt &#8211; for sure so do not follow any URLs or open files.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1601/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1601&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/31/emails-regarding-rejected-ach-payment-contains-security-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2012/20120131_ACH_risk.jpg" medium="image" />
	</item>
		<item>
		<title>Email &#8220;FedEx, Shipment Notification&#8221; with trojan in zip attachement</title>
		<link>http://blog.mxlab.eu/2012/01/30/email-fedex-shipment-notification-with-trojan-in-zip-attachement/</link>
		<comments>http://blog.mxlab.eu/2012/01/30/email-fedex-shipment-notification-with-trojan-in-zip-attachement/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 21:56:31 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[FedEx trojan]]></category>
		<category><![CDATA[FedEx virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1597</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;FedEx, Shipment Notification&#8221;. The email is send from the spoofed address &#8220;FedEx &#60;no-reply@fedex.com&#62;&#8221; and has the following body: The attached ZIP file has the name FedEx-Shipment-Notification_GX3553U8-Jan2012.zip and contains the 200 kB large file FedEx-Shipment-Notification.exe. The trojan is known as W32/Trojan3.DEC [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1597&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;FedEx, Shipment Notification&#8221;.</p>
<p>The email is send from the spoofed address &#8220;FedEx &lt;no-reply@fedex.com&gt;&#8221; and has the following body:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120130_FedEx_trojan.jpg" alt="" width="450" height="340" /></p>
<p>The attached ZIP file has the name FedEx-Shipment-Notification_GX3553U8-Jan2012.zip and contains the 200 kB large file FedEx-Shipment-Notification.exe.</p>
<p>The trojan is known as W32/Trojan3.DEC (F-Prot), Trojan-Spy:W32/Zbot.AVRN (F-Secure), Trojan-Dropper.Win32.Injector.clrk (Kaspersky), Trojan.Zbot (Sophos).</p>
<p>At the time of writing, only 11 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="https://www.virustotal.com/file/28aba7221fe47882164fa45d9d63c58110b96b94d9b2291b692afaa7406c2e46/analysis/1327960398/" target="_blank">permalink</a> and SHA256: 28aba7221fe47882164fa45d9d63c58110b96b94d9b2291b692afaa7406c2e46.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1597/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1597&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/30/email-fedex-shipment-notification-with-trojan-in-zip-attachement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2012/20120130_FedEx_trojan.jpg" medium="image" />
	</item>
		<item>
		<title>Dutch emails with Report.zip attached contains trojan</title>
		<link>http://blog.mxlab.eu/2012/01/20/dutch-emails-with-report-zip-attached-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2012/01/20/dutch-emails-with-report-zip-attached-contains-trojan/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 05:48:47 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1591</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the following possible subjects: Fwd: Vertel de fiscus Fwd: Niet in het derde kwartaal van dit jaar! Informeer de belastingsdienst! Order Order #98314389 Re: adviser id: 586452. Re: profile consultation id: 90616 The answer id: 79858 Your request id: 52018110. &#8230; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1591&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the following possible subjects:</p>
<p>Fwd: Vertel de fiscus<br />
Fwd: Niet in het derde kwartaal van dit jaar!<br />
Informeer de belastingsdienst!<br />
Order<br />
Order #98314389<br />
Re: adviser id: 586452.<br />
Re: profile consultation id: 90616<br />
The answer id: 79858<br />
Your request id: 52018110.<br />
&#8230;</p>
<p>The email is send from different spoofed addresses and has the following body:</p>
<blockquote><p>Hallo<br />
U moet de rekening betalen voor het einde van de week.<br />
Details in de bijgevoegde documenten&#8230;</p></blockquote>
<p>The attached ZIP file has the name Report.zip and contains the 41 kB large file Report.Docx____**____.exe (the filename contains many underscores to hide the .exe file type extension at the end).</p>
<p>The trojan is known as W32/Yakes.B!tr (Fortinet), UDS:DangerousObject.Multi.Generic (Kaspersky), Posible_Worm32 (TheHacker).</p>
<p>At the time of writing, only 4 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="https://www.virustotal.com/file/5037236777f3d320482de732688243faa192ade3bcbbda57472407d7b1219cfe/analysis/1327038098/" target="_blank">permalink</a> and SHA256: 5037236777f3d320482de732688243faa192ade3bcbbda57472407d7b1219cfe.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1591/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1591/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1591/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1591&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/20/dutch-emails-with-report-zip-attached-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New year gift from Amazon sent by a friend contains malware</title>
		<link>http://blog.mxlab.eu/2012/01/19/new-year-gift-from-amazon-sent-by-a-friend-contains-malware/</link>
		<comments>http://blog.mxlab.eu/2012/01/19/new-year-gift-from-amazon-sent-by-a-friend-contains-malware/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 16:48:07 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1588</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercept a few samples of a new trojan found in emails with the subject  &#8221;A friend just sent you a new year gift from amazon&#8221; sent from the spoofed address &#8220;amazon seller &#60;customer_amzon.com@correo.rgm.com.co&#62;&#8221;. The email has the following body: Good day, We are to inform you that someone just sent you a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1588&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercept a few samples of a new trojan found in emails with the subject  &#8221;A friend just sent you a new year gift from amazon&#8221; sent from the spoofed address &#8220;amazon seller &lt;customer_amzon.com@correo.rgm.com.co&gt;&#8221;.</p>
<p>The email has the following body:</p>
<blockquote><p>Good day,<br />
We are to inform you that someone just sent you a gift from amazon.com,<br />
below is the recipt kindly open and track the order. Wishing you a lovely year ahead.<br />
Best regards,<br />
Amazon.com</p></blockquote>
<p>The malware  is approx. 221 kB large and listens to the name file4402_fdp.exe.</p>
<p>The trojan is known as Win32:Malware-gen (Avast), Trojan.Win32.VBKrypt.imoz (Kaspersky), Artemis!798A4ABB09D7 (McAfee), Mal/Generic-L (Sophos).</p>
<p>At the time of writing, 24 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="https://www.virustotal.com/file/40bbaa3e93e50dbdc2b615ae383c3c36c0ab358c311a39efaf6c1246b71ef903/analysis/1326991170/" target="_blank">permalink</a> and SHA256: 40bbaa3e93e50dbdc2b615ae383c3c36c0ab358c311a39efaf6c1246b71ef903.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1588/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1588/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1588/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1588&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/19/new-year-gift-from-amazon-sent-by-a-friend-contains-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Spam in fake LinkedIn messages</title>
		<link>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/</link>
		<comments>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 16:30:24 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Family Pharmacy]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1583</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, has noticed a large spam campaign on behalf of the Canadian Family Pharmacy in fake LinkedIn messages. The messages come the spoofed email address &#60;member@linkedin.com&#62; with the authors like: Fenella Macdonald via LinkedIn &#60;member@linkedin.com&#62; Catriona Bailey via LinkedIn &#60;member@linkedin.com&#62; Susan Jones via LinkedIn &#60;member@linkedin.com&#62; .... Subjects in use: Can i place your [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1583&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, has noticed a large spam campaign on behalf of the Canadian Family Pharmacy in fake LinkedIn messages.</p>
<p>The messages come the spoofed email address &lt;member@linkedin.com&gt; with the authors like:</p>
<pre>Fenella  Macdonald via LinkedIn &lt;member@linkedin.com&gt;
Catriona  Bailey via LinkedIn &lt;member@linkedin.com&gt;
Susan  Jones via LinkedIn &lt;member@linkedin.com&gt;
....</pre>
<p>Subjects in use:</p>
<p>Can i place your photo on my site?<br />
Can i place your photo on our facebook page?<br />
Can i place your information on our web page?<br />
Can i place your video on our web site?<br />
Can i place your video on my facebook page?<br />
Can i place your contacts on our twitter page?<br />
&#8230;..</p>
<p>Example of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin.jpg" alt="" width="450" height="263" /></p>
<p>The URL in the message point to different web hosts and pages with an redirect HTML:</p>
<p>&lt;html&gt;&lt;head&gt;&lt;title&gt;Buy Viagra Online &#8211; Online Pharmacy&lt;/title&gt;&lt;style type=&#8221;text/css&#8221;&gt; a { font-size: 24pt; } &lt;/style&gt;&lt;script type=&#8221;text/javascript&#8221;&gt;var a = &#8220;hxxp://viagralevitratestosterone.com&#8221;;window.location = a;&lt;/script&gt;&lt;/head&gt;&lt;body&gt;&lt;center&gt;&lt;h1&gt;#1 Online Pharmacy&lt;/h1&gt;&lt;br&gt;Online DrugStore&lt;br&gt;&lt;a href=&#8221;hxxp://viagralevitratestosterone.com&#8221;&gt;Buy Viagra Online&lt;/a&gt;&lt;/center&gt;&lt;/body&gt;&lt;/html&gt;</p>
<p>In return, the redirect points to hxxp://viagralevitratestosterone.com.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin_2.jpg" alt="" width="450" height="352" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1583/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1583&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin_2.jpg" medium="image" />
	</item>
		<item>
		<title>Emails with subject &#8220;FDIC: About your business account&#8221; contains new trojan</title>
		<link>http://blog.mxlab.eu/2012/01/10/emails-with-subject-fdic-about-your-business-account-contains-new-trojan/</link>
		<comments>http://blog.mxlab.eu/2012/01/10/emails-with-subject-fdic-about-your-business-account-contains-new-trojan/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 11:23:31 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[FDIC]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1578</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;FDIC: About your business account QHOFB1Z84963&#8243; (the combination at the end will change with each email). The email is send from the spoofed address &#8220;Federal Deposit Insurance Company &#60;convened@fdic.gov&#62;&#8221; and has the following body: Dear Business Customer, We have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1578&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;FDIC: About your business account QHOFB1Z84963&#8243; (the combination at the end will change with each email).</p>
<p>The email is send from the spoofed address &#8220;Federal Deposit Insurance Company &lt;convened@fdic.gov&gt;&#8221; and has the following body:</p>
<blockquote><p>Dear Business Customer,<br />
We have important information about your bank.<br />
Please refer to attached file to view information.<br />
This includes information on the acquiring bank (if applicable), how your accounts and loans are affected, and how vendors can file claims against the receivership<br />
Tue, 9 Jan 2012 12:11:34 +0100</p>
<hr />
<p>FDIC USA Questions for FDIC?<br />
Contact Us<br />
Federal Insurance Company<br />
3501 Fairfax Drive<br />
Arlington VA 22226<br />
877-275-3342</p></blockquote>
<p>The attached ZIP file has the name FDIC_Information_About-your-business-account-JAN2012-223588.zip and contains the *** kB large file FDIC_Information_About-your-business-account-Jan-2012.exe (numbers will change)</p>
<p>The trojan is known as PWS-Zbot.gen.ma (McAfee), Trj/Zbot.L (Panda), Mal/Zbot-EZ (Sophos) and UDS:DangerousObject.Multi.Generic (Kaspersky).</p>
<p>At the time of writing, only 6 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=37a87ba7027951175ae99ff0eaff3890809f9c4032f9705d46e081fb3f61cd36-1326193658" target="_blank">permalink</a> and MD5:4d9e26f544458084261d715a44d13e03.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1578/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1578/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1578/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1578/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1578/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1578/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1578/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1578/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1578&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/10/emails-with-subject-fdic-about-your-business-account-contains-new-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Have a safe 2012!</title>
		<link>http://blog.mxlab.eu/2011/12/29/have-a-safe-2012/</link>
		<comments>http://blog.mxlab.eu/2011/12/29/have-a-safe-2012/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 23:50:44 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1576</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1576&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/2012_mxlab.jpg" alt="" width="430" height="574" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1576/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1576/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1576/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1576&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/12/29/have-a-safe-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/2012_mxlab.jpg" medium="image" />
	</item>
		<item>
		<title>&#8220;I&#8217;m in trouble!&#8221; email malware distribution attempt</title>
		<link>http://blog.mxlab.eu/2011/12/22/im-in-trouble-email-malware-distribution-attempt/</link>
		<comments>http://blog.mxlab.eu/2011/12/22/im-in-trouble-email-malware-distribution-attempt/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 21:17:07 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1572</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;Fwd: I&#8217;m in trouble!&#8221;. The email is send from various spoofed addresses and has the following body: I was at a party, got drunk, couldn&#8217;t drive the car, somebody gave me a lift on my car, and crossed on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1572&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;Fwd: I&#8217;m in trouble!&#8221;.</p>
<p>The email is send from various spoofed addresses and has the following body:</p>
<blockquote><p>I was at a party, got drunk, couldn&#8217;t drive the car, somebody gave me a lift on my car, and crossed on the red light!<br />
I&#8217;ve just got the pictures, maybe you know him???<br />
Here is the photo</p>
<p>I need to find him urgently!</p>
<p>Thank you<br />
Asmita</p>
<p>Fingerprint: c72d5b3c-af1af1a5</p></blockquote>
<p>At the end of the message there is a fingerprint code but don&#8217;t be filled by that. This is not a real proof that this message is secure and safe to use.</p>
<p>The URL behind &#8216;Here is the photo&#8217; will lead to a site where a redirect is a place to the malware payload. The URL can be identified quite easily because they are fairly long, will point to servers where blogs are hosted and quite often have what appears random characters and variables inside.</p>
<p>An example:</p>
<pre>hxxp://newflight.info/wp-content/themes/twentyten/wvfou.htm?
GAJLZP=Y73TY9V&amp;SS4C24F=1H9F0COJCVB2P8FAVJL&amp;Z208W=116AEU0Z&amp;XC8C
=3I1MPP6A2K42K&amp;BO77Z=67QUD1YRE9QF11FV&amp;04T9Z=4942YY7N&amp;KMLD=HUKYAXRX7AUD5R4UK&amp;"</pre>
<p>These pages will continue with a redirect, embedded in an iframe HTML tag, to for example hxxp://cgredret.ru/main.php.</p>
<p>MX Lab recommend not to follow any of the embedded URLs.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1572/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1572/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1572/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1572&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/12/22/im-in-trouble-email-malware-distribution-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Account Activity Notification with attached ZIP file contains a trojan</title>
		<link>http://blog.mxlab.eu/2011/12/21/account-activity-notification-with-attached-zip-file-contains-a-trojan/</link>
		<comments>http://blog.mxlab.eu/2011/12/21/account-activity-notification-with-attached-zip-file-contains-a-trojan/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 16:35:22 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1569</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;Account Activity Notification 2419060820NJ&#8221; &#8211; the number and letters will vary. The email is send from the spoofed address &#8220;Account Support&#8221; and has the following body: An Account Activity Notification you created has detected that the following transaction has [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1569&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;Account Activity Notification 2419060820NJ&#8221; &#8211; the number and letters will vary.</p>
<p>The email is send from the spoofed address &#8220;Account Support&#8221; and has the following body:</p>
<blockquote><p>An Account Activity Notification you created has detected that the<br />
following transaction has posted as of 12/19/11. The detail information<br />
associated with the transaction is as follows:</p>
<p>Account: XXXXXX5693</p>
<p>Transaction Description: Incoming Wire Transfer<br />
Amount: $087,390.45<br />
Type: Credit<br />
Reference Info: 1453328649OS<br />
Availability: Immediate</p>
<p>PLEASE REFER TO ATTACHED FORM FOR MORE DETAILS</p>
<p>CONFIDENTIALITY NOTICE: This electronic mail transmission may contain<br />
legally privileged, confidential information belonging to the sender. The<br />
information is intended only for the use of the individual or entity named<br />
above. If you are not the intended recipient, you are hereby notified that<br />
any disclosure, copying, distribution or taking any action based on the<br />
contents of this electronic mail is strictly prohibited. If you have<br />
received this electronic mail in error, please contact sender and delete<br />
all copies.</p></blockquote>
<p>The attached ZIP file has the name Account_Update_Notification_12192011-71714.zip and contains the 210 kB large file Account_Update_Notification_12192011.exe. The filenames will vary with each email.</p>
<p>The trojan is known as Trojan.Win32.Heur.Gen (ByteHero) or PWS-Zbot.gen.ma (McAfee).</p>
<p>At the time of writing, only 2 of the 42 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=55ae6bec5ced2ff1a2717c2d8b62a5068f283b1321ea55e494cdbca412c75cff-1324482416" target="_blank">permalink</a> and MD5: 09707085eb9812202ba72a1c6f6c5f4a.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1569/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1569/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1569/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1569&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/12/21/account-activity-notification-with-attached-zip-file-contains-a-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Emails with URL that contains /docdown/ will download malware</title>
		<link>http://blog.mxlab.eu/2011/12/08/emails-with-url-that-contains-docdown-will-download-malware/</link>
		<comments>http://blog.mxlab.eu/2011/12/08/emails-with-url-that-contains-docdown-will-download-malware/#comments</comments>
		<pubDate>Thu, 08 Dec 2011 00:59:22 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=1565</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, is intercepting emails with a potential dangerous URL embedded in the body of the email. The URL includes the part /docdown/ and will refer to an online ZIP file. Subjects will vary, the email is send from different spoofed addresses and here we have some samples: Goeie morgen, Het antwoord op uw [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1565&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, is intercepting emails with a potential dangerous URL embedded in the body of the email. The URL includes the part /docdown/ and will refer to an online ZIP file.</p>
<p>Subjects will vary, the email is send from different spoofed addresses and here we have some samples:</p>
<blockquote><p>Goeie morgen,</p>
<p>Het antwoord op uw vraag over het profiel op de website van 30.11.2011<br />
hxxp://www.quattro-stagioni.it/docdown/Factuur.zip?idinvoice=1615847338768Firma=ontario583@csk-rijssen.nl</p>
<p>We zijn blij om samen te werken in de toekomst.</p></blockquote>
<blockquote><p>Het antwoord op uw vraag over het profiel op de website van 30.11.2011<br />
hxxp://www.sanseverocommunity.com/docdown/Factuur.zip?idinvoice=27043890762Firma=info@bloemex.nl</p></blockquote>
<p>The trojan is known as Artemis!6287782884ED (McAfee), Downloader.Dromedan (Symantec), Trojan.Win32.Yakes (Ikarus), Trojan.Generic.7001815 (BitDefender).</p>
<p>At the time of writing, 37 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=b7d5d48316b61e9f4a81ceb065184cabc5ff14371ff029dda8403f54be5d2876-1323304841" target="_blank">permalink</a> and MD5: 6287782884edba7ca26df03942798739.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1565/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1565/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1565/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1565/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1565/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1565/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1565/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1565/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1565&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/12/08/emails-with-url-that-contains-docdown-will-download-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>
