<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Search Results  &#187;  UPS+Tracking</title>
	<atom:link href="http://blog.mxlab.eu/search/UPS+Tracking/feed/rss2/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Mon, 13 Feb 2012 23:20:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Search Results  &#187;  UPS+Tracking</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>“United Parcel Service notification 48161” from UPS contains trojan</title>
		<link>http://blog.mxlab.eu/2011/03/27/%e2%80%9cunited-parcel-service-notification-48161%e2%80%9d-from-ups-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2011/03/27/%e2%80%9cunited-parcel-service-notification-48161%e2%80%9d-from-ups-contains-trojan/#comments</comments>
		<pubDate>Sun, 27 Mar 2011 19:39:01 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1312</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan variant distribution campaign by email with the subject “United Parcel Service notification 48161”, where the number in the subject may vary, with more or less the same email characteristics of the previous campaign MX Lab posted earlier this week but with with a very low detection [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1312&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan variant distribution campaign by email with the subject “United Parcel Service notification 48161”, where the number in the subject may vary, with more or less the same email characteristics of the <a href="http://blog.mxlab.eu/2011/03/23/united-parcel-service-notification-from-ups-contains-trojan/" target="_blank">previous campaign</a> MX Lab posted earlier this week but with with a very low detection rate at the time of writing: only 5 of the 43 AV engines did detect the trojan at Virus Total!</p>
<p>The email is send from the spoofed addresses “United Parcel Service &lt;****@ups.com&gt;” where *** is filled in with various combinations like:</p>
<blockquote><p>infoads@ups.com<br />
infoad111@ups.com<br />
infoad@ups.com<br />
infosec@ups.com<br />
infosec1@ups.com<br />
infosec3@ups.com<br />
infosec4@ups.com<br />
infoser@ups.com<br />
infoser1@ups.com<br />
infoser2@ups.com<br />
infoser3@ups.com<br />
infoser4@ups.com<br />
infosec8@ups.com<br />
&#8230;</p></blockquote>
<p>The message has the following body:</p>
<blockquote><p>Dear customer.</p>
<p>The parcel was sent your home address.<br />
And it will arrive within 3 business day.</p>
<p>More information and the tracking number are attached in document below.</p>
<p>Thank you.<br />
© 1994-2011 United Parcel Service of America, Inc.</p></blockquote>
<p>The attached ZIP file has the name UPS-document.zip and contains the 20 kB large file UPS-document.exe.</p>
<p>The trojan is known as Artemis!08BA3C182674 (MacAfee), Trj/CI.A (Panda).</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=29dffb943636ba065a91a7318036096413f2df51ab5550d85c471dbe6393faa7-1301251830" target="_blank">permalink</a> and MD5: 08ba3c182674398cd2190cad5dc327ef.</p>
<p>The trojan will install itself on an infected computer and will obtain data from the following URLs:</p>
<ul>
<li>http://109.94.220.52/lol2.exe</li>
<li>http://109.94.220.52/pod.exe</li>
<li>http://109.94.220.52/spm.exe</li>
<li>http://91.213.29.175/lol2.exe</li>
<li>http://91.213.29.175/pod.exe</li>
<li>http://91.213.29.175/spm.exe</li>
</ul>
<p>For each of the files we have the following report:</p>
<blockquote><p>lol2.exe:</p>
<p>FakeAlert-CN.gen.h (MacAfee), FraudTool.Win32.FakeRean.b (Vipree)<br />
Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=d39ba2c8badb59e32065b1df4c4703b5abcdff5a445e90319e116dc0a072d511-1301253556" target="_blank">permalink</a> &#8211; MD5: 43b84209a37ebdee99996b073562203e</p>
<p>Will install the file %AppData%\pux.exe, modify registry, connects to IP 69.50.209.138 on port 80 and will request URL hxxp://vogunemymyko.com/1017000412</p></blockquote>
<blockquote><p>pod.exe:</p>
<p>Worm/Rorpian.A (AntiVir), W32/Worm-FAO!1B984534DCC8 (McAfee)<br />
Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=f3aac810a100bc09f02c5e13df23264406569e3faeb10bd697de5282e7049233-1301139078" target="_blank">permalink</a> &#8211; MD5: 1b984534dcc8d761703437f10a9cf179</p>
<p>Will install the file %Temp%\srvB8.tmp, connects to IP 188.138.48.178 on port 80 and will request URL hxxp://188.138.48.178/service/listener.php?affid=50039</p></blockquote>
<blockquote><p>spm.exe:</p>
<p>Artemis!CCB935935C60 (MacAfee), W32/Spammer.AQZ.worm (Panda)<br />
Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=669961f90b8c4e554fb20609e409056128ef46b73ecb5a49bd9a9a8c41e5491d-1301218958" target="_blank">permalink</a> &#8211; MD5: ccb935935c60b7c931201daa9efd6af4</p>
<p>Will install the files %System%\mhmhbrog.dll and %System%\tmp.tmp, modify the registry, and make connections to the following IPs:</p>
<p>124.108.116.109, on port 25<br />
67.195.168.31, on port 25<br />
98.137.54.237, on port 25<br />
98.139.54.60, on port 25<br />
46.4.10.7, on port 8000 and 8001</p>
<p>This malware will also generate SMTP traffic from the spoofed email addresses:</p>
<ul>
<li>&lt;info1goyoy@ups.com&gt;</li>
<li>&lt;info47dynu@ups.com&gt;</li>
<li>&lt;info42s@ups.com&gt;</li>
<li>&lt;info2yu@ups.com&gt;</li>
</ul>
</blockquote>
<p>This malicious payload will create the following files:</p>
<p>%CommonAppData%\472v34rbtx7a80t655b4m22u3yx11w233mh156g3<br />
%AppData%\472v34rbtx7a80t655b4m22u3yx11w233mh156g3<br />
%Temp%\472v34rbtx7a80t655b4m22u3yx11w233mh156g3<br />
%Templates%\472v34rbtx7a80t655b4m22u3yx11w233mh156g3<br />
%AppData%\Microsoft\conhost.exe<br />
%AppData%\xbr.exe<br />
%Temp%\srvC8.tmp<br />
%System%\mtcaqnbx.dll<br />
%System%\musawolc.dll</p>
<p>The following processes will be created:</p>
<p>conhost.exe: %AppData%\Microsoft\conhost.exe<br />
xbr.exe: %AppData%\xbr.exe</p>
<p>The following hostnames are requested from the host database:</p>
<ul>
<li>ponel.biz</li>
<li>itisformebaby.biz</li>
<li>zuzosahule.com</li>
<li>dafatesomyz.com</li>
<li>jumonevetode.com</li>
<li>gokuzajylot.com</li>
<li>lukofymela.com</li>
<li>jebuponip.com</li>
<li>quxovasuced.com</li>
<li>laqoduhisegu.com</li>
<li>xyseditacif.com</li>
<li>dihemehypuq.com</li>
<li>wylyxaqunowy.com</li>
<li>qepovexidysopy.com</li>
<li>bebecebyt.com</li>
<li>rumesexyzobuz.com</li>
<li>kyxiteruk.com</li>
<li>kexigulat.com</li>
<li>jarynokab.com</li>
<li>lefurasacaveta.com</li>
<li>cicabijyni.com</li>
<li>ridibasofetevi.com</li>
<li>sihorarofiqiha.com</li>
<li>ropunonic.com</li>
<li>xyxukinasacujo.com</li>
<li>tapahagupaji.com</li>
<li>zonotunev.com</li>
<li>raxukakudumow.com</li>
<li>vogunemymyko.com</li>
<li>zufonabubi.com</li>
<li>bynoripuqoxyl.com</li>
<li>kytelaticik.com</li>
<li>qyvexyhun.com</li>
<li>myhofociv.com</li>
<li>dalebihyku.com</li>
<li>kijyjajutava.com</li>
<li>decufysohyh.com</li>
<li>sezixalekur.com</li>
<li>lolypositole.com</li>
<li>hohimedag.com</li>
<li>hikiniribep.com</li>
<li>fyxinolydima.com</li>
<li>gonifyzadiby.com</li>
<li>wavupinycom.com</li>
<li>xykecolun.com</li>
<li>hisepelihyzex.com</li>
<li>xixeriwihat.com</li>
<li>vetidicawisos.com</li>
<li>dijipabamefuw.com</li>
<li>naxucerybaqecy.com</li>
<li>hegylocimemyja.com</li>
<li>roboralipijago.com</li>
<li>samykacagatet.com</li>
<li>fusipemura.com</li>
<li>sazulipum.com</li>
<li>fuxawekugygil.com</li>
</ul>
<p>A connection attempt to itisformebaby.biz on port 8000 is executed and a connection is established to the IP 188.138.48.178 on port 80 with the request service/listener.php?affid=50039.</p>
<p>The following HTTP URLs were started reading:</p>
<ul>
<li>hxxp://vogunemymyko.com/1017000412</li>
<li>hxxp://zufonabubi.com/1017000412</li>
<li>hxxp://bynoripuqoxyl.com/1017000412</li>
<li>hxxp://kytelaticik.com/1017000412</li>
<li>hxxp://qyvexyhun.com/1017000412</li>
<li>hxxp://myhofociv.com/1017000412</li>
<li>hxxp://dalebihyku.com/1017000412</li>
<li>hxxp://kijyjajutava.com/1017000412</li>
<li>hxxp://decufysohyh.com/1017000412</li>
<li>hxxp://sezixalekur.com/1017000412</li>
<li>hxxp://lolypositole.com/1017000412</li>
<li>hxxp://hohimedag.com/1017000412</li>
<li>hxxp://hikiniribep.com/1017000412</li>
<li>hxxp://fyxinolydima.com/1017000412</li>
<li>hxxp://gonifyzadiby.com/1017000412</li>
<li>hxxp://wavupinycom.com/1017000412</li>
<li>hxxp://xykecolun.com/1017000412</li>
<li>hxxp://hisepelihyzex.com/1017000412</li>
<li>hxxp://xixeriwihat.com/1017000412</li>
<li>hxxp://vetidicawisos.com/1017000412</li>
<li>hxxp://dijipabamefuw.com/1017000412</li>
<li>hxxp://naxucerybaqecy.com/1017000412</li>
<li>hxxp://hegylocimemyja.com/1017000412</li>
<li>hxxp://roboralipijago.com/1017000412</li>
<li>hxxp://samykacagatet.com/1017000412</li>
<li>hxxp://fusipemura.com/1017000412</li>
<li>hxxp://sazulipum.com/1017000412</li>
<li>hxxp://fuxawekugygil.com/1017000412</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1312/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1312/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1312/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1312/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1312/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1312/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1312/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1312/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1312&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/27/%e2%80%9cunited-parcel-service-notification-48161%e2%80%9d-from-ups-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>59</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;United Parcel Service notification&#8221; from UPS contains trojan</title>
		<link>http://blog.mxlab.eu/2011/03/23/united-parcel-service-notification-from-ups-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2011/03/23/united-parcel-service-notification-from-ups-contains-trojan/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 16:38:28 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1296</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;United Parcel Service notification The email is send from the spoofed address &#8220;United Parcel Service &#60;****@ups.com&#62;&#8221; where *** is filled in with various combinations like: infojs@ joiner2@ joiner22@ joisupport@ups.com supportadm@ups.com &#8230;. The message has the following body: Dear customer. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1296&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;United Parcel Service notification</p>
<p>The email is send from the spoofed address &#8220;United Parcel Service &lt;****@ups.com&gt;&#8221; where *** is filled in with various combinations like:</p>
<blockquote><p>infojs@<br />
joiner2@<br />
joiner22@<br />
joisupport@ups.com<br />
supportadm@ups.com<br />
&#8230;.</p></blockquote>
<p>The message has the following body:</p>
<blockquote><p>Dear customer.</p>
<p>The parcel was sent your home address.<br />
And it will arrive within 7 business day.</p>
<p>More information and the tracking number are attached in document below.</p>
<p>Thank you.<br />
© 1994-2011 United Parcel Service of America, Inc.</p></blockquote>
<p>The attachedZIP file has the name UPSnotice.rar and contains the 16 kB large file UPS notify.exe.</p>
<p>The trojan is known as BDS/Hostil.F.9 (Antivir), TrojanDownloader:Win32/Chepvil.I (Microsoft), Mal/Bredo-K (Sophos), Backdoor.Cycbot (Symantec).</p>
<p>The following files will be created:</p>
<p>%Temp%\lol2.exe</p>
<p>The trojan can establish connection with the IP 193.105.121.33 on port 80 and data will be obtained from following URL hxxp://193.105.121.33/lol2.exe.</p>
<p>At the time of writing, only 20 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=ef5f76e1b20c2083469fbe7e4de4ec9c06689ee105274b1a79c9cadbd23d54ae-1300895171" target="_blank">permalink</a> and MD5: cc040e69121bc19f23ef4a32dbb8a80e.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1296/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1296&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/23/united-parcel-service-notification-from-ups-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>89</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Bredolab trojan variants in DHL and UPS tracking emails</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/</link>
		<comments>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 20:49:51 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[DHL tracking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS tracking]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731</guid>
		<description><![CDATA[MX Lab intercepted several email messages with new Bredolab trojan variants in the traditional style: emails regarding the tracking of a parcel. We noticed new campaigns using the DHL and UPS tracking style. We will cover them both in this article at the same time. The trojan is known as Trojan.Win32.Bredolab, Trojan-Downloader:W32/Bredolab.WI or TrojanDownloader:Win32/Bredolab.AB. UPS [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=731&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted several email messages with new Bredolab trojan variants in the traditional style: emails regarding the tracking of a parcel. We noticed new campaigns using the DHL and UPS tracking style. We will cover them both in this article at the same time.</p>
<p>The trojan is known as Trojan.Win32.Bredolab, Trojan-Downloader:W32/Bredolab.WI or TrojanDownloader:Win32/Bredolab.AB.</p>
<p><strong>UPS Tracking Number</strong></p>
<p>The message comes from the spoofed address UPS Manager *** &lt;services@ups.com&gt; (*** stands for a random firstname lastname format). The subject is UPS Tracking Number 42163829 (number may vary with each email). The body of the email:</p>
<blockquote><p>Dear customer!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
United Parcel Service.</p></blockquote>
<p>The email contains the archive file UPS_invoice _Nr4593.zip, where the number matches the number in the subject. Extracted the executable UPS_invoice _Nr4593.exe is present with a file size of 68kB.</p>
<p>The trojan will create the following files on the system:</p>
<p>%Profiles%\LocalService\Application Data\mvhgkr.dat<br />
%AppData%\avdrn.dat<br />
%DesktopDir%\Internet Security 2010.lnk<br />
%StartMenu%\Internet Security 2010.lnk<br />
%Programs%\Startup\rarype32.exe<br />
%ProgramFiles%\InternetSecurity2010\IS2010.exe<br />
%System%\41.exe<br />
%System%\helper32.dll<br />
%System%\smss32.exe<br />
%System%\winlogon32.exe<br />
%System%\warning.html</p>
<p>There were new processes created in the system:</p>
<p>%System%\smss32.exe<br />
%ProgramFiles%\internetsecurity2010\is2010.exe</p>
<p>Various registry settings will be changed while the port 1054 on TCP is open for the service smss32.exe (%System%\smss32.exe). Connections to remote host are established: 193.104.153.30 on port 80 and to 193.104.94.5 op port 4455.</p>
<p>The data identified by the following URLs was then requested from the remote web server:</p>
<p>* http://downloadavr40.com/loads.php?code=0001384<br />
* http://downloadavr40.com/dfghfghgfj.dll<br />
* http://downloadavr40.com/cgi-bin/download.pl?code=0001384<br />
* http://testavrdown.com/cgi-bin/get.pl?l=0001384</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/a2fc094278b68423a96af25ebff0be17290043762f3a33a262a3edba1589edc6-1263931750" target="_blank">permlink</a> and MD5: 28d798d6021e600101ba68ea87345656. At the time of writing this article, only 10 of the 41 AV engines did detect the trojan variant.</p>
<p><strong>DHL Tracking Number</strong></p>
<p>The email comes from the spoofed address Support *** &lt;services@dhl.com&gt; (*** stands for a random firstname lastname format).</p>
<p>Possible subject formats are:</p>
<p>DHL Delivery Problem NR 98545<br />
DHL International. Get your parcel NR.5269<br />
DHL Customer Services. Get your parcel NR.0961<br />
DHL Express Services. Get your parcel NR.6493<br />
DHL Office. Get your parcel NR.6366<br />
DHL Tracking Number 40834372048</p>
<p>The body of the email:</p>
<blockquote><p>Hello!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Express Services.</p></blockquote>
<p>The email contains the archive file DHL_label_Nr2387.zip. Extracted the executable DHL_label_Nr2387.exe is present with a file size of 68kB. The numbers in the filename may vary.</p>
<p>Following files are created on the system:</p>
<p>%AppData%\avdrn.dat<br />
%Programs%\Startup\rarype32.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/722079cf9293486b565768dc9b961de239302d267c25f259f53052ea30bed10a-1263928285" target="_blank">permlink</a> and MD5: 7c874b52eee7196ef96dc8710b957033.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/731/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=731&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New ZBot trojan detected in UPS tracking emails</title>
		<link>http://blog.mxlab.eu/2009/05/27/new-zbot-trojan-detected-in-ups-tracking-emails/</link>
		<comments>http://blog.mxlab.eu/2009/05/27/new-zbot-trojan-detected-in-ups-tracking-emails/#comments</comments>
		<pubDate>Wed, 27 May 2009 22:40:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Mal/Zbot-I]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=464</guid>
		<description><![CDATA[Email messages coming from UPS with the subject &#8220;Postal Tracking #FDD4Q22514LDU4N&#8221; and the attached file UPS_DOC_986001.zip are part of a new malware distribution by email. MX Lab intercepted the first samples of a new variant that is only detected by 5 of the 40 AV engines of Virus Total. The body of the email: Hello! [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=464&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Email messages coming from UPS with the subject &#8220;Postal Tracking #FDD4Q22514LDU4N&#8221; and the attached file UPS_DOC_986001.zip are part of a new malware distribution by email. MX Lab intercepted the first samples of a new variant that is only detected by 5 of the 40 AV engines of Virus Total.</p>
<p>The body of the email:</p>
<blockquote><p>Hello!</p>
<p>We were not able to deliver postal package you sent on the 14th of March in time<br />
because the recipient’s address is not correct.<br />
Please print out the invoice copy attached and collect the package at our office.</p>
<p>Your United Parcel Service of America</p></blockquote>
<p>The trojan will create the following files:</p>
<blockquote><p>%AppData%\wiaserva.log<br />
%Temp%\WER699f.dir00\appcompat.txt<br />
%Temp%\WER699f.dir00\explorer.exe.hdmp<br />
%Temp%\WER699f.dir00\explorer.exe.mdmp<br />
%Temp%\WER699f.dir00\manifest.txt<br />
%System%\wbem\grpconv.exe</p></blockquote>
<p>%AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.</p>
<p>The following directy is created: %Temp%\WER699f.dir00.<br />
A new process is created in the system: %System%\wbem\grpconv.exe along with some Windows registry modifications.</p>
<p>The following URL is being used: hxxp://dollarpoint.ru/abc/controller.php?action=bot&amp;entity_list=&amp;uid=&amp;first=1&amp;guid=13441600&amp;rnd=8520045</p>
<p>Virus Total <a href="http://www.virustotal.com/reanalisis.html?0834935e7219fe9b598ce7dcf7ade312fd1a87e8ee780541f436f6eecccb4896-1243463193" target="_blank">link</a> and MD5: de90a24f3dfb5c1c8d4a0a3104f3dd4a.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/464/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/464/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/464/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=464&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/27/new-zbot-trojan-detected-in-ups-tracking-emails/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New UPS trojan detected: TrojanSpy.ZBot.DGI</title>
		<link>http://blog.mxlab.eu/2009/03/02/new-ups-trojan-detected/</link>
		<comments>http://blog.mxlab.eu/2009/03/02/new-ups-trojan-detected/#comments</comments>
		<pubDate>Mon, 02 Mar 2009 23:45:22 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.be/?p=370</guid>
		<description><![CDATA[Posting updated on 10 March 2009. Read the new information at the end of this posting. MX Lab intercepted a  few messages, with the zero hour anti virus system, that claim that the delivery of the postal package that is handled by UPS has failed due to an incorrect address. At the time of writing, 03.02.2009 22:55:45 (CET), only [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=370&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Posting updated</strong> on 10 March 2009. Read the new information at the end of this posting.</p>
<p>MX Lab intercepted a  few messages, with the zero hour anti virus system, that claim that the delivery of the postal package that is handled by UPS has failed due to an incorrect address. At the time of writing, 03.02.2009 22:55:45 (CET), only 7 of the 38 anti virus engines detect this new variant.</p>
<p>The trojan is named TrojanSpy.ZBot.DGI (VirusBuster), Trojan-Dropper.Delf (Ikarus) or VirTool:Win32/DelfInject.gen!J (Microsoft).</p>
<p>The from address is spoofed and contains &#8220;United Postal Service &lt;tracking@ups.com&gt;&#8221;.</p>
<p>The message contains the following body content:</p>
<blockquote><p>Hello!</p>
<p>Sorry, we were not able to deliver postal package you sent on February the 23th in time because the recipient’s address is not correct.</p>
<p>Please print out the invoice copy attached and collect the package at our office.</p>
<p>Your UPS Support Team</p></blockquote>
<p>The trojan hides itself inside the file Invoice_8612112.exe once you have extracted the ZIP archive Invoice_8612112.zip. Names and numbers may vary.</p>
<p>It has the same characteristics as in one of our <a href="http://blog.mxlab.be/2009/01/11/new-ups-trojan-variant_delivery_problems/">previous blog posts</a> with the difference that the connection to the remote host 91.211.65.33 now tries to get /ejik/admin.bin and /ejik/hot.php.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/1f64b69e5fa5e06dd2a539a34ca11ba0" target="_blank">permlink</a> and MD5: a3d1a160e6ce8ca4c2b4421731e549c2.</p>
<p><strong>Update 10 March 2009</strong>: A new variant is being distributed. The attached file is named UPS_ID.zip and contains the trojan UPS_ID.exe.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/e81fd69bc06ea94476a6cedc9b06742c" target="_blank">permlink</a> and MD5: b5e44647bc1f08c4d7f32fc933db1ac6.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/370/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=370&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/03/02/new-ups-trojan-detected/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New UPS trojan variant: Delivery problems</title>
		<link>http://blog.mxlab.eu/2009/01/11/new-ups-trojan-variant_delivery_problems/</link>
		<comments>http://blog.mxlab.eu/2009/01/11/new-ups-trojan-variant_delivery_problems/#comments</comments>
		<pubDate>Sun, 11 Jan 2009 14:02:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.be/?p=318</guid>
		<description><![CDATA[A new UPS trojan variant is being detected called Mal/Zbot-G by Sophos and VirTool:Win32/Obfuscator.CT by Microsoft. MX Lab was the first to send and analyse the file by Total Virus. Only 2 of the 36 AV engines at Virus Total did detect the trojan at the time of writing. So be aware that this email contains malware so [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=318&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A new UPS trojan variant is being detected called Mal/Zbot-G by Sophos and VirTool:Win32/Obfuscator.CT by Microsoft.</p>
<p>MX Lab was the first to send and analyse the file by Total Virus. Only 2 of the 36 AV engines at Virus Total did detect the trojan at the time of writing. So be aware that this email contains malware so don&#8217;t open the attachment.</p>
<p>The senders email addres is: United Postal Service &lt;tracking@ups.com&gt;.</p>
<p>The subject is: Delivery problems</p>
<p>The content of the body:</p>
<blockquote><p>Hello!</p>
<p>Sorry, we were not able to deliver postal package you sent on December the 25th in time because the recipients address is not correct. Please print out the invoice copy attached and collect the package at our office.</p>
<p>Your UPS Support Team</p></blockquote>
<p>The file attached is names UPSInv.zip and the ZIP archive contains UPSInv.exe.</p>
<p>Please note that the senders email address, the subject, body and attached file names can change.</p>
<p>This is the Trojan-Spy.Zbot.YETH, which is a rootkit trojan which steals online banking information and downloads other malware as well. The origin is possibly the Russian Federation.</p>
<p>Local files created:</p>
<p><span> </span>%System%\twain32\local.ds<br />
%System%\twain32\user.ds<br />
%System%\twain32\user.ds.lll <br />
%System%\twex.exe </p>
<p>Several Windows registry changes are being made, one registry change makes ure that twex.exe is run every thime Windows starts, and the trojan makes connection with the host 91.211.65.33 on port 80 and a GET command is executed to ferrari/admin.bin.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/c93fb750b3a412b86441afa4299199fa" target="_blank">permlink</a> and MD5 hash: 61a1617ddb5c5bdb495b29bd1719e965.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/318/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/318/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/318/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=318&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/01/11/new-ups-trojan-variant_delivery_problems/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS Postal Service trojan still active</title>
		<link>http://blog.mxlab.eu/2008/11/25/ups-postal-service-trojan-still-active/</link>
		<comments>http://blog.mxlab.eu/2008/11/25/ups-postal-service-trojan-still-active/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 16:30:29 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=302</guid>
		<description><![CDATA[In the past we&#8217;ve seen many variants of the UPS email containing an attached trojan in a zip file known now as Win32/Kollah.RT, 32/Zbot.GXN!tr.spy or TrojanSpy:Win32/Zbot.gen!C according to the virus engine. Since yesterday we&#8217;ve seen a new variant and it is quite active and being distributed because MX Lab has intercepted quite some samples of this emails. The emails hasn&#8217;t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=302&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In the past we&#8217;ve seen many variants of the <a href="http://blog.mxlab.be/?s=UPS+Tracking" target="_self">UPS email containing an attached trojan in a zip file</a> known now as Win32/Kollah.RT, 32/Zbot.GXN!tr.spy or TrojanSpy:Win32/Zbot.gen!C according to the virus engine. Since yesterday we&#8217;ve seen a new variant and it is quite active and being distributed because MX Lab has intercepted quite some samples of this emails.</p>
<p>The emails hasn&#8217;t changed much, the subject is &#8220;Your Tracking # 877874077711&#8243; (where the number is dyanimc and changes often) and the content of the body:</p>
<blockquote><p>Sorry, we were not able to deliver postal package you sent on November the 1st in time because the recipient’s address is not correct.</p>
<p>Please print out the invoice copy attached and collect the package at our office. If you do not receive package in ten days you will have to pay 36$ per day.</p>
<p>Your UPS</p></blockquote>
<p>The email has the zip file Invoice_UPS.zip attached with the Invoice_UPS.exe inside.</p>
<p>VirusTotal <a href="http://www.virustotal.com/analisis/110e46d088f04bce6f8fa6a5421a451f" target="_blank">Permalink</a> and MD5: 68ab2a6801bbc18e727d8ac093c8087f.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/302/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/302/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/302/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=302&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/11/25/ups-postal-service-trojan-still-active/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>FedEx Tracking number trojan</title>
		<link>http://blog.mxlab.eu/2008/08/09/fedex-tracking-number-trojan/</link>
		<comments>http://blog.mxlab.eu/2008/08/09/fedex-tracking-number-trojan/#comments</comments>
		<pubDate>Sat, 09 Aug 2008 16:48:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[FedEx Tracking Number trojan]]></category>
		<category><![CDATA[FedEx trojan]]></category>
		<category><![CDATA[FedEx virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=170</guid>
		<description><![CDATA[MX Lab has intercepted a few messages with the subject &#8220;[NO-REPLY] FedEx Tracking Number 26901603&#8243; with an attached trojan. After the UPS Tracking trojan campaign it&#8217;s now time to use FedEx. The content of the email has the same characteristics as the UPS trojan: Unfortunately we were not able to deliver postal package you sent [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=170&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab has intercepted a few messages with the subject &#8220;[NO-REPLY] FedEx Tracking Number 26901603&#8243; with an attached trojan. After the UPS Tracking trojan campaign it&#8217;s now time to use FedEx.</p>
<p>The content of the email has the same characteristics as the UPS trojan:</p>
<blockquote><p>Unfortunately we were not able to deliver postal package you sent on July the 31 in time because the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office</p>
<p>Your FedEx</p></blockquote>
<p>The email has attached the zip archive named FedEx_Invoice.zip with the executable FedEx_Invoice_N882874421.exe. The &#8220;tracking number&#8221; in the subject and file can change of course.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/02ad0087b650423dcd989260f5a147c1" target="_blank">results</a> and MD5: da90a0c3000eb90ebc9394e5568c5c9a. 7 of the 36 anti virus engines detect the trojan so be carefull when you receive the message.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/170/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/170/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/170/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=170&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/08/09/fedex-tracking-number-trojan/feed/</wfw:commentRss>
		<slash:comments>29</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS Tracking number trojan &#8211; another variant and Hallmark e-card</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/</link>
		<comments>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 18:59:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[e-card virus]]></category>
		<category><![CDATA[hallmark e-card virus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[UPS virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114</guid>
		<description><![CDATA[There is a new variant of the UPS Tracking number trojan on route. The subject is now &#8220;[RE] UPS Tracking Number 7056968807&#8243; but the contents remains the same. The URL that is used by the trojan is slightly different, the host remails the same, the folder structure and the .bin file on the site is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=114&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>There is a new variant of the UPS Tracking number trojan on route. The subject is now &#8220;[RE] UPS Tracking Number 7056968807&#8243; but the contents remains the same. The URL that is used by the trojan is slightly different, the host remails the same, the folder structure and the .bin file on the site is different: http://***********.ru/offshore/denis.bin. The number in the subject and file can be random.</p>
<p>The new variant is detected by 13 of the 35 anti virus engines at <a href="http://www.virustotal.com/analisis/fcf90df882b41b4a33821cca8461e663" target="_blank">Virus Total</a>. The MD5 hash is 488d34cd86e252abca560416413a595d.</p>
<p>Also, if you receive an Hallmark E-Card as attachment it&#8217;s also another <a href="http://www.virustotal.com/analisis/de926ad78b01c9e28f011138a195dd03" target="_blank">variant of a Trojan-Dropper.Win32</a> also known as W32/P2Pworm.E.worm or Trojan.Delf.Inject.F. The chances for infection are much less, 24 of the 35 engines provide protection, so there&#8217;s a good chance that it&#8217;s captured.</p>
<p>When reading the comments on this blog and also on other resources and web site, I am amazed how many people have double clicked the attachment and have indeed infected their computer.</p>
<p>Now, a very simple tip for the future that is also mentioned on some other web sites as well is <strong>don&#8217;t open attachments without checking the content and senders first</strong>. Handle each email with attachments carefully and don&#8217;t start to extract them and click on executables and files with exotic extensions.</p>
<p>Large companies like UPS, Hallmark and others don&#8217;t send you an executable in a zip file. So this is something that you should be aware of. This is the first &#8220;red light&#8221;.</p>
<p>UPS tracking is done online on their web site and after all, think about it, a message stating that a delivery from July the 1st can&#8217;t be delivered while we are in fact July 23 is not a very good UPS service, right?</p>
<p>For Hallmark e-cards you also need to visit their web site to get your lovely e-card.</p>
<p>Following this simple guideline can avoid troubles of getting an infected computer. This applies for everyone. If you work from home, you are an individual, you are in a business environment, it&#8217;s a good tip for everyone.</p>
<p>Now, if you have a business with employees and multiple workstations, servers and computers and you have an infection on your network then you might ask yourself if your anti virus protection is up to the task of providing protection after all. It appears that it is not.</p>
<p>You are missing a good protection on the internet perimeter that is capable of responding faster to email based threats like viruses and trojans.</p>
<p>In that case, let me promote my company for once, contact <a href="http://www.mxlab.eu/en/contactus/index.html" target="_blank">MX Lab</a>, get a <a href="http://www.mxlab.eu/en/contactus/15day_audit.html" target="_blank">15 day trial</a> of our <a href="http://www.mxlab.eu/en/zero_hour_anti_virus.html" target="_blank">zero hour anti virus</a> and <a href="http://www.mxlab.eu/en/managed_anti_spam.html" target="_blank">anti spam</a> security services and notice the difference.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/114/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/114/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/114/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/114/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/114/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=114&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS Tracking number trojan &#8211; new variant</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/</link>
		<comments>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comments</comments>
		<pubDate>Mon, 21 Jul 2008 23:05:55 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[UPS virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99</guid>
		<description><![CDATA[Around 00:02 AM, local Belgian time, MX Lab detected an outbreak of a new UPS tracking number trojan. The email itself remains the same but the attachment name contains now a tracking number like UPS_INVOICE_978172.exe. The .exe is a new variant and when submitting an example to Virus Total only 3 of the 34 anti [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=99&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Around 00:02 AM, local Belgian time, MX Lab detected an outbreak of a new UPS tracking number trojan.</p>
<p>The email itself remains the same but the attachment name contains now a tracking number like UPS_INVOICE_978172.exe.</p>
<p>The .exe is a new variant and when submitting an example to Virus Total only <strong>3 of the 34 anti virus engines detected this new variant</strong>. More details below in the table.</p>
<blockquote>
<table id="tablaMotores" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<th>Antivirus</th>
<th>Version</th>
<th>Last Update</th>
<th>Result</th>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>2008.7.21.1</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>AntiVir</td>
<td>7.8.1.11</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Authentium</td>
<td>5.1.0.4</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Avast</td>
<td>4.8.1195.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>AVG</td>
<td>8.0.0.130</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>BitDefender</td>
<td>7.2</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>9.50</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>ClamAV</td>
<td>0.93.1</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.44.0.09170</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>eSafe</td>
<td>7.0.17.0</td>
<td>2008.07.21</td>
<td class="positivo">Suspicious File</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>31.6.5971</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Ewido</td>
<td>4.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>F-Prot</td>
<td>4.4.4.56</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>F-Secure</td>
<td>7.60.13501.0</td>
<td>2008.07.21</td>
<td class="positivo">Suspicious:W32/Malware!Gemini</td>
</tr>
<tr>
<td>Fortinet</td>
<td>3.14.0.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>GData</td>
<td>2.0.7306.1023</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Ikarus</td>
<td>T3.1.1.34.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Kaspersky</td>
<td>7.0.0.125</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>McAfee</td>
<td>5343</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Microsoft</td>
<td>1.3704</td>
<td>2008.07.22</td>
<td>-</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>3284</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Norman</td>
<td>5.80.02</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>PCTools</td>
<td>4.4.2.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Prevx1</td>
<td>V2</td>
<td>2008.07.22</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Rising</td>
<td>20.54.02.00</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.31.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Sunbelt</td>
<td>3.1.1536.1</td>
<td>2008.07.18</td>
<td>-</td>
</tr>
<tr>
<td>Symantec</td>
<td>10</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>TheHacker</td>
<td>6.2.96.385</td>
<td>2008.07.20</td>
<td>-</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.700.0.1004</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>VBA32</td>
<td>3.12.8.1</td>
<td>2008.07.21</td>
<td class="positivo">suspected of Malware-Cryptor.Win32.General.2</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.5.11.0</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
<tr class="odd">
<td>Webwasher-Gateway</td>
<td>6.6.2</td>
<td>2008.07.21</td>
<td>-</td>
</tr>
</tbody>
</table>
</blockquote>
<p>The file contains threat characteristics of ZBot &#8211; a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system. It opens backdoors on infected computer to allow malicious attacker unauthorized access.</p>
<p>On an infected computer the trojan will create a new files like %System%\ntos.exe, %System%\wsnpoem\audio.dll, %System%\wsnpoem\video.dll and creates a new directory %System%\wsnpoem.</p>
<p>It also adds and modifies entries in the Windows registry and make connection with a server for http://*********.ru/******/odessa.bin. It opens random TCP ports in order to provide backdoor capabilities.</p>
<p><strong>Update 10:00 AM Belgian time:</strong></p>
<p>The MD5 on Virus Total is da4b7ef93c588ad799f1a1c5afb6cfad and the trojan is now detectedby 12 virus engines. Permalink: <a href="http://www.virustotal.com/analisis/69a8553eb41687126314099d97f7dcdf" target="_blank">http://www.virustotal.com/</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/99/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/99/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/99/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/99/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/99/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=99&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/feed/</wfw:commentRss>
		<slash:comments>37</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>
