<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Bredolab</title>
	<atom:link href="http://blog.mxlab.eu/tag/bredolab/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Bredolab</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>New trojan variant in mails with &#8220;Look my CV. Thank you!&#8221;</title>
		<link>http://blog.mxlab.eu/2010/06/14/new-trojan-variant-in-mails-with-look-my-cv-thank-you/</link>
		<comments>http://blog.mxlab.eu/2010/06/14/new-trojan-variant-in-mails-with-look-my-cv-thank-you/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 15:44:44 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Eldorado]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=939</guid>
		<description><![CDATA[MX Lab intercepts a new trojan variant in emails with the subject &#8220;Look my CV. Thank you! MyID NR4557547.&#8221;. Possible subject are: Look my CV. Thank you! MyID NR4557547. Please look my CV. Thank you! MyID NR0663460. The number at the end of the subject is choosen randomly and the from email address is spoofed. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=939&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepts a new trojan variant in emails with the subject &#8220;Look my CV. Thank you! MyID NR4557547.&#8221;.</p>
<p>Possible subject are:</p>
<p>Look my CV. Thank you! MyID NR4557547.<br />
Please look my CV. Thank you! MyID NR0663460.</p>
<p>The number at the end of the subject is choosen randomly and the from email address is spoofed.</p>
<p>The body of the email:</p>
<blockquote><p>Good day.</p>
<p>I have figured out that you have an available job.<br />
I am quiet intrested in it. So I send you my resume,</p>
<p>Looking forward to your reply.<br />
Thank you.</p></blockquote>
<p>The email contains the attachment resume098.zip. The extracted file resume.exe is 36 kB large.</p>
<p>The trojan is known as W32/Heuristic-210!Eldorado (Authentium, F-Prot) or Backdoor.Bredolab (PCTools).</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\fjof.sto<br />
%Temp%\2.tmp<br />
%Windir%\atapsrb.dll</p>
<p>The following modules are loaded into the address space of other  processes:</p>
<p>%Windir%\atapsrb.dll:</p>
<p>Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address  space: 0x1E70000 &#8211; 0x1E82000</p>
<p>%Windir%\atapsrb.dll::</p>
<p>Process name: IEXPLORE.EXE<br />
Process filename: %ProgramFiles%\internet  explorer\iexplore.exe<br />
Address space: 0&#215;1940000 &#8211; 0&#215;1952000</p>
<p>%Windir%\atapsrb.dll::</p>
<p>Process name: [generic host process]<br />
Process filename: [generic host  process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10012000</p>
<p>Several Windows registry modifications are created and the trojan attempts to establish a connection with the following IPs on port 80:</p>
<p>195.78.109.6<br />
212.78.71.81<br />
95.211.98.246</p>
<p>Data is downloaded from the following hosts:</p>
<ul>
<li>hxxp://olgashelest.ru/babun/bb.php?v=200&amp;id=603225387&amp;b=6165430227&amp;tm=1</li>
<li>hxxp://olgashelest.ru/babun/bb.php?v=200&amp;id=603225387&amp;tid=4&amp;b=6165430227&amp;r=1&amp;tm=1</li>
<li>hxxp://www.scottishchefs.com/photogallery/Slideshows/SLteam2008/p7hg_img_1/fullsize/sepod.exe</li>
</ul>
<p>At this time of writing, only 6 of the 41 AV engines at Virus Total detect this threat. Virus Total <a href="http://www.virustotal.com/analisis/e35e84cf6f5a044d6b01361995422c1b3640d0c44927b63bedb636d911a11387-1276529610" target="_blank">permlink</a> and MD5: 0ae6a2d53e86b8784d45dd56afc5c6d7.</p>
<p>The downloaded file sepod.exe, which is 60 kB large, is malware known as W32/Hiloti.I.gen!Eldorado (F-Prot),  Trojan.Win32.Hiloti (Ikarus) or Mal/Hiloti-D (Sophos).</p>
<p>The following files are created:</p>
<p>%Windir%\dsmd32.dll</p>
<p>The following modules are loaded into the address space of other processes:</p>
<p>%Windir%\dsmd32.dll:</p>
<p>Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address space: 0x1E70000 &#8211; 0x1E82000</p>
<p>%Windir%\dsmd32.dll:</p>
<p>Process name: [generic host process]<br />
Process filename: [generic host process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10012000</p>
<p>Several Windows registry modifications are created and the trojan attempts to establish a connection with the IP 95.211.98.246 on port 80.</p>
<p>13 of the 41 AV engine at Virus Total detect this threat. Virus Total <a href="http://www.virustotal.com/analisis/f4e10a81dedb5375a33cf1bcb2026e7cd710d11d53f89baf1d5aa761922be564-1276530787" target="_blank">permlink</a> and MD5: 7a10c1118307e7cb4ecf97b40524a89c.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/939/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=939&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/14/new-trojan-variant-in-mails-with-look-my-cv-thank-you/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Emails with the subject &#8220;UPS INVOICE NR9094991&#8243; and &#8220;Delivery Problem NR2204780&#8243; contains trojan</title>
		<link>http://blog.mxlab.eu/2010/05/26/emails-with-the-subject-ups-invoice-and-delivery-problem-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/05/26/emails-with-the-subject-ups-invoice-and-delivery-problem-contains-trojan/#comments</comments>
		<pubDate>Wed, 26 May 2010 22:26:33 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[FakeAlert]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[oficla]]></category>
		<category><![CDATA[Sasfis]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=859</guid>
		<description><![CDATA[A combination of the &#8220;Thank you for buying iTunes Gift Certificate!&#8221; and the latest UPS related emails with subjects like &#8220;UPS INVOICE NR9094991&#8243; or  &#8221;Delivery Problem NR2204780&#8243; has made that MX Lab noted the highest virus detection rate since months. The possible subjects are (numbers are random): UPS INVOICE NR9094991 Delivery Problem NR2204780 The body of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=859&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A combination of the <a href="http://blog.mxlab.eu/2010/05/26/new-trojan-variant-in-“thank-you-for-buying-itunes-gift-certificate”-email/" target="_self">&#8220;Thank you for buying iTunes Gift Certificate!&#8221;</a> and the latest UPS related emails with subjects like &#8220;UPS INVOICE NR9094991&#8243; or  &#8221;Delivery Problem NR2204780&#8243; has made that MX Lab noted the highest virus detection rate since months.</p>
<p>The possible subjects are (numbers are random):</p>
<p>UPS INVOICE NR9094991<br />
Delivery Problem NR2204780</p>
<p>The body of the email:</p>
<blockquote><p>Hello!<br />
Unfortunately we were not able to deliver your postal you have sent on the 11th of March in time because the addressee&#8217;s is inexact.<br />
Please print out the invoice copy attached and collect the package at our department.<br />
UPS Global Services.</p></blockquote>
<blockquote><p>Hello!<br />
We failed to deliver the postal you have sent on the 24th of March in time because the addressee&#8217;s is wrong.<br />
Please print out the invoice copy attached and collect the package at our department.<br />
UPS Express Services.</p></blockquote>
<p>The email contains the zip archive upsinvoice3325037.zip, once extracted the 36 kB large file UPSINVOICE.exe is available.</p>
<p>The trojan is known as W32/FakeAlert.NW (F-Prot), Trojan.Win32.VBKrypt.yj (Kaspersky), Win32/Oficla.EU (NOD32), Troj/Bredo-CX (Sophos) or Trojan.Sasfis (Symantec).</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\nnfj.tqo<br />
%Temp%\2.tmp<br />
%Windir%\scindl.dll</p>
<p>The following modules will be loaded into the address space of other process(es):</p>
<p>%Windir%\scindl.dll &#8212;&gt;<br />
Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address space: 0x1E90000 &#8211; 0x1EA1000</p>
<p>%Windir%\scindl.dll &#8212;&gt;<br />
Process name: IEXPLORE.EXE<br />
Process filename: %ProgramFiles%\internet explorer\iexplore.exe<br />
Address space: 0&#215;1940000 &#8211; 0&#215;1951000</p>
<p>%Windir%\scindl.dll &#8212;&gt;<br />
Process name: [generic host process]<br />
Process filename: [generic host process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10011000</p>
<p>The trojan can establish a remote connection with the following hosts on port 80:</p>
<p>85.87.17.230<br />
89.149.202.142<br />
95.211.27.238</p>
<p>Data will be requested fromt he following web sites:</p>
<p>* hxxp://funnylive2010.ru/ms/bb.php?v=200&amp;id=653227819&amp;b=newsp&amp;tm=2<br />
* hxxp://funnylive2010.ru/ms/bb.php?v=200&amp;id=653227819&amp;tid=5&amp;b=newsp&amp;r=1&amp;tm=2<br />
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/<br />
_source/classes/sistempod.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/42763f2bae33449acc3bf441494ea2d35d608d32edc57c5ba366bd5046e6c0ff-1274902157" target="_blank">permlink</a> and MD5: 493c929efe366812cd6fc921c2b549fc.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/859/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=859&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/05/26/emails-with-the-subject-ups-invoice-and-delivery-problem-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New malspam regarding your Amazon order: Your order has been paid! Parcel NR:58588-691</title>
		<link>http://blog.mxlab.eu/2010/05/17/new-malspam-regarding-your-amazon-order-your-order-has-been-paid-parcel-nr58588-691/</link>
		<comments>http://blog.mxlab.eu/2010/05/17/new-malspam-regarding-your-amazon-order-your-order-has-been-paid-parcel-nr58588-691/#comments</comments>
		<pubDate>Mon, 17 May 2010 08:22:45 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=849</guid>
		<description><![CDATA[MX Lab detected a new malware spam outbreak with the subject &#8220;Your order has been paid! Parcel NR:58588-691&#8243;regarding a payment towards Amazon. The malware is sent from a spoofed email address in the form of Amazon Manager Vaughn Montes &#60;refrigeratorser22@rokulabs.com&#62;. The trojan is known as Trojan.Generic.Bredolab.3232 (ClamAV), W32/VBcrypt.E.gen!Eldorado (Eldorado), W32/VBcrypt.E.gen!Eldorado (F-Prot) or Heuristic.BehavesLike.Win32.Downloader.H (McAfee-GW-Edition). The body of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=849&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a new malware spam outbreak with the subject &#8220;Your order has been paid! Parcel NR:58588-691&#8243;regarding a payment towards Amazon. The malware is sent from a spoofed email address in the form of Amazon Manager Vaughn Montes &lt;refrigeratorser22@rokulabs.com&gt;.</p>
<p>The trojan is known as Trojan.Generic.Bredolab.3232 (ClamAV), W32/VBcrypt.E.gen!Eldorado (Eldorado), W32/VBcrypt.E.gen!Eldorado (F-Prot) or Heuristic.BehavesLike.Win32.Downloader.H (McAfee-GW-Edition).</p>
<p>The body of the email:</p>
<blockquote><p>Dear Sirs,</p>
<p>Thank you for shopping at Amazon.com!</p>
<p>We have successfully received your payment.</p>
<p>Your order has been shipped to your billing address.</p>
<p>You have ordered ” Sony Bravia  S1452 ”</p>
<p>You can find your tracking number in attached to the e-mail  document.</p>
<p>Print the postal label to get your package.</p>
<p>We hope you enjoy your order!</p>
<p>Vaughn Montes, Amazon</p></blockquote>
<p>The email has the ZIP archive Amazon_label_N-322-552.zip attached and contains the 36 kB large file Amazon_label_N-322-552.DOC.exe.</p>
<p>The following files are created:</p>
<p>C:\Documents and Settings\User\Local Settings\Temp\1.tmp<br />
C:\WINDOWS\system32\thxr.wgo</p>
<p>An HTTP request will be done to:</p>
<p>hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=636608811&amp;b=build_9&amp;tm=1<br />
hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=636608811&amp;b=build_9&amp;tm=2<br />
hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=636608811&amp;b=build_9&amp;tm=3</p>
<p>At the time of writing, only 5 of the 41 AV engines at Virus Total did detect the threat. Virus Total <a href="http://www.virustotal.com/analisis/7cf41d0feea39c27f0671e7be8683c6ae7a807900108e77c85636baa7cfb3bf1-1274083361" target="_blank">permlink</a> and MD5: b31628758d2557315403f59cc65bc33d.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/849/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=849&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/05/17/new-malspam-regarding-your-amazon-order-your-order-has-been-paid-parcel-nr58588-691/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Thank you for buying iTunes Gift Certificate!&#8221; email contains trojan</title>
		<link>http://blog.mxlab.eu/2010/05/07/thank-you-for-buying-itunes-gift-certificate-email-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/05/07/thank-you-for-buying-itunes-gift-certificate-email-contains-trojan/#comments</comments>
		<pubDate>Fri, 07 May 2010 08:56:17 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[iTunes Gift Certificate]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[oficla]]></category>
		<category><![CDATA[Sasfis]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=838</guid>
		<description><![CDATA[[UPDATE] A new article regarding a new trojan variant has been posted on the MX Lab blog on 26 May 2010: New trojan variant in “Thank you for buying iTunes Gift Certificate!” email. Read article here. MX Lab started to intercept emails with the subject &#8220;Thank you for buying iTunes Gift Certificate!&#8221; with the trojan Gen:Variant.Bredo.4 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=838&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>[UPDATE]</strong> A new article regarding a new trojan variant has been posted on the MX Lab blog on 26 May 2010: New trojan variant in “Thank you for buying iTunes Gift Certificate!” email. <a href="http://blog.mxlab.eu/2010/05/26/new-trojan-variant-in-“thank-you-for-buying-itunes-gift-certificate”-email/" target="_self">Read article here</a>.</p>
<hr />
<p>MX Lab started to intercept emails with the subject &#8220;Thank you for buying iTunes Gift Certificate!&#8221; with the trojan Gen:Variant.Bredo.4 (Bitdefender, F-Secure), Win32/Oficla.GQ (NDO32), Trojan.Sasfis (Symantec) or Mal/EncPk-NS (Sophos).</p>
<p>It is clear that with this campaign, the virus authors are using a subtle way to lure potential victims. Getting a $50 iTunes Gift Certificate is more tempting than anything else.</p>
<p>This distribution is sent from the spoofed email address iTunes Products &lt;customer.service@itunes.com&gt;.</p>
<p>The body of the email:</p>
<blockquote><p>Hello!</p>
<p>You have received an iTunes Gift Certificate in the amount of $50.00<br />
You can find your certificate code in attachment  below.</p>
<p>Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video  right away.</p>
<p>iTunes Store.</p></blockquote>
<p>The email contains the file ZIP archive iTunes_certificate_247.zip containing the 52 kB large executable iTunes_certificate_247.exe.</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\pgsb.lto</p>
<p>The registry key “HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid” is created.<br />
The registry key “[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]” will be modified.</p>
<p>The trojan can establish a remote connection with the IP 195.78.108.201 on port 80 and retrieve data from:</p>
<p>* hxxp://davidopolko.ru/migel/bb.php?v=200&amp;id=743908139&amp;b=6may&amp;tm=2</p>
<p>At the time of writing, 15 of the 41 AV engines did detect the trojan. Virus Total <a href="http://www.virustotal.com/analisis/0b0b24ca0593723075ef8b103a229b17b86d5b01d624c9ef82c0c74c16ae69ea-1273221418" target="_blank">permlink</a> and MD5: 0e50c0085bc6d75226a5c06ac1637df1</p>
<p>MX Lab customers are protected against this email based threat.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/838/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/838/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/838/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/838/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/838/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/838/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/838/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/838/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/838/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/838/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=838&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/05/07/thank-you-for-buying-itunes-gift-certificate-email-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>31</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Email regarding Conflicker.B Infection Alert contains a trojan</title>
		<link>http://blog.mxlab.eu/2010/02/17/email-regarding-conflicker-b-infection-alert-contains-a-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/02/17/email-regarding-conflicker-b-infection-alert-contains-a-trojan/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 13:56:42 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Conflicker]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=769</guid>
		<description><![CDATA[MX Lab started to intercept emails with the subject &#8220;Conflicker.B Infection Alert&#8221;. The trojan is names Win32:Bredolab-CC (Avast), Generic Dropper.lr (McAfee) or Trojan.Win32.Bredolab.Gen.2 (Sunbelt). The from address is spoofed and can contain &#8220;Microsoft Team&#8221;. The emails is signed by &#8220;Microsoft Windows Computer Safety Division&#8221; to make it appears that it is from Microsoft itself. The email [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=769&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept emails with the subject &#8220;Conflicker.B Infection Alert&#8221;. The trojan is names Win32:Bredolab-CC (Avast), Generic Dropper.lr (McAfee) or Trojan.Win32.Bredolab.Gen.2 (Sunbelt).</p>
<p>The from address is spoofed and can contain &#8220;Microsoft Team&#8221;. The emails is signed by &#8220;Microsoft Windows Computer Safety Division&#8221; to make it appears that it is from Microsoft itself.</p>
<p>The email has the attachment open.zip and inside the ZIP archive the executable open.exe (16 kB).</p>
<p>As you can read, the email contains instructions to use the attached file to scan your network after an detected virus infection by the Conflicker worm.</p>
<blockquote><p>Dear Microsoft Customer,</p>
<p>Starting 12/11/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.</p>
<p>To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.</p>
<p>Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.</p>
<p>Regards,<br />
Microsoft Windows Agent #2 (Hollis)<br />
Microsoft Windows Computer Safety Division</p></blockquote>
<p>At the time of writing, 21 of the 40 AV engines at Virus Total did detect the threat correctly. Our recommendation is that you never following instructions, send by email, like this one. Microsoft, or any other company, will spread security tools by email.</p>
<p>This trojan is a serious security risk because it will display fake alerts regarding a virus infection in order to lead you to buy rogue anti virus/anti spyware products. The trojan also has the capabilities to send out emails with a build-in SMTP engine.</p>
<p>A new windows will be created after executing the file open.exe:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100217_rogueAV_1.gif" alt="" width="248" height="130" /></p>
<p>The following files are created:</p>
<p>%CommonAppData%\28701826\28701826.exe<br />
%DesktopDir%\Security Tool.lnk<br />
%Programs%\Security Tool.lnk<br />
%Windir%\Temp\_ex-08.exe</p>
<p>The following directory is created:</p>
<p>%CommonAppData%\28701826</p>
<p>New processes are created:</p>
<p>_ex-08.exe in %Windir%\temp\_ex-08.exe<br />
28701826.exe in C:\DOCUME~1\ALLUSE~1\APPLIC~1\28701826\28701826.exe</p>
<p>The Windows registry will be modified and the malware can open the TCP ports 1066 and 1067 ports on an infected system.</p>
<p>Connection to remote hosts (port 80):</p>
<p>221.150.130.37<br />
94.102.50.131<br />
95.143.192.40</p>
<p>Remote downloands:</p>
<p>    * hxxp://221.150.130.37/qmbzxqbitqs.htm<br />
    * hxxp://221.150.130.37/gyxk.htm<br />
    * hxxp://221.150.130.37/xwxwkg.htm<br />
    * hxxp://94.102.50.131/in.php?affid=43400&amp;url=5&amp;win=Windows%20XP+2.0&amp;sts=<br />
    * hxxp://95.143.192.40/pr/pic/sys.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/22b4d35e6310d11ceebb046d7eede09a83c8489121dbb492fbd7702d6eb2fe8d-1266412310" target="_blank">permlink</a> and MD5: 76cf8a523c11f4d2ab86a7b99c89c9e0.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/769/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/769/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/769/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=769&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/17/email-regarding-conflicker-b-infection-alert-contains-a-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100217_rogueAV_1.gif" medium="image" />
	</item>
		<item>
		<title>&#8220;updated account agreement&#8221; email contains Bredolab trojan</title>
		<link>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 22:26:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=751</guid>
		<description><![CDATA[MX Lab started to intercept emails with the subject &#8220;updated account agreement&#8221; that contains the Bredolab trojan. The campaign is designed for Facebook users because of the content. The email comes from the spoofed email address and contains &#8220;Facebook Team&#8221;. The body of the email: Dear Facebook user, Due to Facebook policy changes, all Facebook [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=751&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept emails with the subject &#8220;updated account agreement&#8221; that contains the Bredolab trojan. The campaign is designed for Facebook users because of the content. The email comes from the spoofed email address and contains &#8220;Facebook Team&#8221;.</p>
<p>The body of the email:</p>
<blockquote><p>Dear Facebook user,</p>
<p>Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date.</p>
<p>Accounts that do not submit the updated account agreement by the deadline will have restricted.</p>
<p>Please unzip the attached file and run “agreement.exe” by double-clicking it.</p>
<p>Thanks,<br />
The Facebook Team</p></blockquote>
<p>The email has the ZIP archive agreement.zip attached, once unpacked the file 28 kB big file agreement.exe is available.</p>
<p>Facebook, or any other company, will never distribute agreements,  software updates and patches or anything else in emails. Our recommendation is to delete the email immediatly because a lot of AV engines do not detect this variant very well at the moment.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/3eea167a650a747dad1ec304cf2f46ffaa9be273152d723aeda6d908cf8023d8-1265839538" target="_blank">permlink</a> and MD5: cc632e1dad8775e2bb558a6cd247b94b.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/751/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=751&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Bredolab trojan on the move</title>
		<link>http://blog.mxlab.eu/2010/02/04/bredolab-trojan-on-the-move/</link>
		<comments>http://blog.mxlab.eu/2010/02/04/bredolab-trojan-on-the-move/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 16:52:50 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=747</guid>
		<description><![CDATA[MX Lab noticed an increase in intercepted Bredolab trojan variants that are spread by email. The Bredolab variants are distributed by different campaigns. Do you like to find a girlfriend like me ? One campaign has the subject &#8220;Do you like to find a girlfriend like me ?&#8221; and targets female singles in a certain [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=747&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab noticed an increase in intercepted Bredolab trojan variants that are spread by email. The Bredolab variants are distributed by different campaigns.</p>
<p><strong>Do you like to find a girlfriend like me ?</strong></p>
<p>One campaign has the subject &#8220;Do you like to find a girlfriend like me ?&#8221; and targets female singles in a certain way:</p>
<blockquote><p>Wish to have a boyfriend<br />
Be able to protect me, take care of me<br />
Intolerable lonely night and would like to have your care.<br />
do you Willing ?</p>
<p>This is my photos.</p></blockquote>
<p>The email includes a ZIP archive named myphotos.zip which indicated that you will see some pictures. Instead the archive includes the file myphoto.exe which is the Bredolab trojan.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/c95c3fb721abf1255f82e851b18c94716c7e675a7bc51b9cc21ef36a2b2afa1e-1265281447" target="_blank">permlink</a> and MD5: 63936bfd3c1207ef3d2cce7b52d508da.</p>
<p><strong>DHL Office. Please get your parcel NR.6161</strong></p>
<p>The second campaign is the tradional failed package delivery style, in this case DHL coming from the spoofed email address &lt;support@dhl.com&gt;. Following subject are used:</p>
<p>DHL Office. Please get your parcel NR.6161<br />
DHL Express. Please get your parcel NR.6161<br />
DHL Express Services. You need to get a parcel NR. 3050<br />
DHL International. You need to get a parcel NR. 3050<br />
DHL Services. Please get your parcel NR. 1608<br />
DHL Customer Services.  Please get your parcel NR. 3528</p>
<p>Body of the email:</p>
<blockquote><p>Hello!</p>
<p>The courier service was not able to deliver your parcel at your address.</p>
<p>Cause: Mistake in address</p>
<p>You may pickup the parcel at our post office personally.</p>
<p>The delivery advice is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Services.</p></blockquote>
<p>There is also a Spanish version of the campaign with the spoofed email address &lt;support@dhl.es&gt; with the subject &#8220;DHL servicios. Recibir parcela NR.82140&#8243; and the email body:</p>
<blockquote><p>Estimado Cliente</p>
<p>El mensajero de nuestra Compañía no pudo entregarle el envío en su domicilio.<br />
Causa: Error en la indicación del domicilio de entrega.<br />
Puede recibir su envío personalmente en la oficina de correos cercana a su domicilio.</p>
<p>Atención!<br />
A esta carta se le adjunta una etiqueta postal. Usted debe imprimir la etiqueta para poder recibir el envío en la oficina de correos.</p>
<p>Gracias.<br />
DHL servicios.</p></blockquote>
<p><strong>UPS Delivery Problem NR 66466.</strong></p>
<p>The third campaign in also failed package delivery style but with UPS &#8216;branding&#8217; from the spoofed from address &lt;service@ups.com&gt;. Subject is UPS Delivery Problem NR 66466 and and example of the body of the email:</p>
<blockquote><p>Dear customer!</p>
<p>Unfortunately we were not able to deliver the package sent on the 24th of January in time<br />
because the addressee&#8217;s address is not correct.<br />
Please print out the invoice copy attached and collect the package at our office.</p>
<p>United Parcel Service of America.</p></blockquote>
<p>The UPS and DHL trojans have the same MD5 are are the same variant. At the time of writting this article only 14 of the 40 AV engines pick up the trojan well.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/efece73178abfe2335c088cf9d1145d24ac0ee7828d6b1b368b77e944f51b110-1265283514" target="_blank">permlink</a> and MD5:574f07d83aeae631834ff8279af8c1ed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/747/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/747/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/747/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=747&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/04/bredolab-trojan-on-the-move/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Bredolab trojan variants in DHL and UPS tracking emails</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/</link>
		<comments>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 20:49:51 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[DHL tracking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS tracking]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731</guid>
		<description><![CDATA[MX Lab intercepted several email messages with new Bredolab trojan variants in the traditional style: emails regarding the tracking of a parcel. We noticed new campaigns using the DHL and UPS tracking style. We will cover them both in this article at the same time. The trojan is known as Trojan.Win32.Bredolab, Trojan-Downloader:W32/Bredolab.WI or TrojanDownloader:Win32/Bredolab.AB. UPS [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=731&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted several email messages with new Bredolab trojan variants in the traditional style: emails regarding the tracking of a parcel. We noticed new campaigns using the DHL and UPS tracking style. We will cover them both in this article at the same time.</p>
<p>The trojan is known as Trojan.Win32.Bredolab, Trojan-Downloader:W32/Bredolab.WI or TrojanDownloader:Win32/Bredolab.AB.</p>
<p><strong>UPS Tracking Number</strong></p>
<p>The message comes from the spoofed address UPS Manager *** &lt;services@ups.com&gt; (*** stands for a random firstname lastname format). The subject is UPS Tracking Number 42163829 (number may vary with each email). The body of the email:</p>
<blockquote><p>Dear customer!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
United Parcel Service.</p></blockquote>
<p>The email contains the archive file UPS_invoice _Nr4593.zip, where the number matches the number in the subject. Extracted the executable UPS_invoice _Nr4593.exe is present with a file size of 68kB.</p>
<p>The trojan will create the following files on the system:</p>
<p>%Profiles%\LocalService\Application Data\mvhgkr.dat<br />
%AppData%\avdrn.dat<br />
%DesktopDir%\Internet Security 2010.lnk<br />
%StartMenu%\Internet Security 2010.lnk<br />
%Programs%\Startup\rarype32.exe<br />
%ProgramFiles%\InternetSecurity2010\IS2010.exe<br />
%System%\41.exe<br />
%System%\helper32.dll<br />
%System%\smss32.exe<br />
%System%\winlogon32.exe<br />
%System%\warning.html</p>
<p>There were new processes created in the system:</p>
<p>%System%\smss32.exe<br />
%ProgramFiles%\internetsecurity2010\is2010.exe</p>
<p>Various registry settings will be changed while the port 1054 on TCP is open for the service smss32.exe (%System%\smss32.exe). Connections to remote host are established: 193.104.153.30 on port 80 and to 193.104.94.5 op port 4455.</p>
<p>The data identified by the following URLs was then requested from the remote web server:</p>
<p>* http://downloadavr40.com/loads.php?code=0001384<br />
* http://downloadavr40.com/dfghfghgfj.dll<br />
* http://downloadavr40.com/cgi-bin/download.pl?code=0001384<br />
* http://testavrdown.com/cgi-bin/get.pl?l=0001384</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/a2fc094278b68423a96af25ebff0be17290043762f3a33a262a3edba1589edc6-1263931750" target="_blank">permlink</a> and MD5: 28d798d6021e600101ba68ea87345656. At the time of writing this article, only 10 of the 41 AV engines did detect the trojan variant.</p>
<p><strong>DHL Tracking Number</strong></p>
<p>The email comes from the spoofed address Support *** &lt;services@dhl.com&gt; (*** stands for a random firstname lastname format).</p>
<p>Possible subject formats are:</p>
<p>DHL Delivery Problem NR 98545<br />
DHL International. Get your parcel NR.5269<br />
DHL Customer Services. Get your parcel NR.0961<br />
DHL Express Services. Get your parcel NR.6493<br />
DHL Office. Get your parcel NR.6366<br />
DHL Tracking Number 40834372048</p>
<p>The body of the email:</p>
<blockquote><p>Hello!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Express Services.</p></blockquote>
<p>The email contains the archive file DHL_label_Nr2387.zip. Extracted the executable DHL_label_Nr2387.exe is present with a file size of 68kB. The numbers in the filename may vary.</p>
<p>Following files are created on the system:</p>
<p>%AppData%\avdrn.dat<br />
%Programs%\Startup\rarype32.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/722079cf9293486b565768dc9b961de239302d267c25f259f53052ea30bed10a-1263928285" target="_blank">permlink</a> and MD5: 7c874b52eee7196ef96dc8710b957033.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/731/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/731/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/731/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=731&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Bredolab variant targets MySpace users with MySpace Password Reset email</title>
		<link>http://blog.mxlab.eu/2010/01/08/new-bredolab-variant-targets-myspace-users-with-myspace-password-reset-email/</link>
		<comments>http://blog.mxlab.eu/2010/01/08/new-bredolab-variant-targets-myspace-users-with-myspace-password-reset-email/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 09:13:05 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[MySpace virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=728</guid>
		<description><![CDATA[MX Lab detected a new virus campaign containing a new Bredolab variant. The campaign has the same characteristics as the Facebook Password Reset email campaign. The trojan listens to the name Win32:Bredolab-BL (Avast) or W32/Bredolab!Generic2 (F-Prot). The email is send from the spoofed address &#60;confirmation@myspace.com&#62; and has the subjects: MySpace Password Reset Confirmation! MySpace Password Reset Confirmation! [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=728&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a new virus campaign containing a new Bredolab variant. The campaign has the same characteristics as the <a href="http://blog.mxlab.eu/2009/10/27/bredolab-masked-as-facebook-password-reset-confirmation/">Facebook Password Reset email</a> campaign. The trojan listens to the name Win32:Bredolab-BL (Avast) or W32/Bredolab!Generic2 (F-Prot).</p>
<p>The email is send from the spoofed address &lt;confirmation@myspace.com&gt; and has the subjects:</p>
<p>MySpace Password Reset Confirmation!<br />
MySpace Password Reset Confirmation! Order NR.4648.</p>
<p>The number at the end of the subject is choosen randomly and can change in case the subject contains an Order NR.</p>
<p>Body of the email:</p>
<blockquote><p>Hey a ,</p>
<p>Because of the measures taken to provide safety to our clients, your password has been changed.<br />
You can find your new password in attached document.</p>
<p>Thanks,<br />
Your MySpace.</p></blockquote>
<p>The attached document is named MySpace_document_10081.zip and contains the 36 kB big MySpace_document_10081.exe executable.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/8abb167902465903cfc857b521cbdee2f01c020abe5653c2bcaf63a9ff8c59a6-1262936252" target="_blank">permlink</a> and MD5: cfd05a493ccab7d5928ba9bf7dec3d16.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/728/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/728/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/728/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/728/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/728/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/728/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/728/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/728/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/728/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/728/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=728&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/01/08/new-bredolab-variant-targets-myspace-users-with-myspace-password-reset-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Bredolab variant in email regarding DHL parcel delivery problems</title>
		<link>http://blog.mxlab.eu/2009/12/07/new-bredolab-variant-in-email-regarding-dhl-parcel-delivery-problems/</link>
		<comments>http://blog.mxlab.eu/2009/12/07/new-bredolab-variant-in-email-regarding-dhl-parcel-delivery-problems/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 22:12:06 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[DHL tracking trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=702</guid>
		<description><![CDATA[MX Lab started to intercept new variants of Bredolab in emails regarding DHL parcel delivery problems. The emails comes from the spoofed address Manager Youg Steward &#60;parcel@dhl-usa.com&#62; (name is choosen randomly). The body of the email: Dear customer! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=702&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept new variants of Bredolab in emails regarding DHL parcel delivery problems. The emails comes from the spoofed address Manager Youg Steward &lt;parcel@dhl-usa.com&gt; (name is choosen randomly).</p>
<p>The body of the email:</p>
<blockquote><p>Dear customer!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Delivery Services.</p></blockquote>
<p>The email has the ZIP attachment named DHL_Label_da882.zip (charachters after DHL_Label_ are choosen randomly) that contains 32 kB big file DHL_Label_da882.exe.</p>
<p>At the time of writing only 14 of the 40 AV engines detect the virus at Virus Total. Virus Total <a href="http://www.virustotal.com/analisis/7203206bf2500d600b737524d1ebd9f3d4ec2ca932d37a3598f11fe9f54cc848-1260216166" target="_blank">permlink</a> and MD5: 2ddd08612873d8217555f6c40ae32f51.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/702/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/702/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/702/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/702/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/702/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/702/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/702/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/702/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/702/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/702/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=702&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/12/07/new-bredolab-variant-in-email-regarding-dhl-parcel-delivery-problems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>