<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; cnn</title>
	<atom:link href="http://blog.mxlab.eu/tag/cnn/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; cnn</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Conflict in Gaza inspires new CNN campaign from malware authors</title>
		<link>http://blog.mxlab.eu/2009/01/14/conflict_in_gaza_inspires_new_cnn_campaign_from_malware_authors/</link>
		<comments>http://blog.mxlab.eu/2009/01/14/conflict_in_gaza_inspires_new_cnn_campaign_from_malware_authors/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 17:19:58 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[adobe flash malware]]></category>
		<category><![CDATA[cnn]]></category>
		<category><![CDATA[cnn media centre]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.be/?p=327</guid>
		<description><![CDATA[The military campaign from Israël in Gaza has inspired malware distributors. The outbreak appears to be sent from CNN Media Centre (cnn@cnn.com) &#8211; obviously spoofed &#8211; with subject lines such as: israel’s war on hamas: a dozen thoughts hamas goads israel into war israel vows war on hamas in gaza hamas launching rocket war after gaza [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=327&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The military campaign from Israël in Gaza has inspired malware distributors. The outbreak appears to be sent from CNN Media Centre (cnn@cnn.com) &#8211; obviously spoofed &#8211; with subject lines such as:</p>
<blockquote><p>israel’s war on hamas: a dozen thoughts<br />
hamas goads israel into war<br />
israel vows war on hamas in gaza<br />
hamas launching rocket war after gaza evacuation</p></blockquote>
<p>The body of the email contains:</p>
<blockquote><p>Israel offers short respite from strikes.<br />
Israel will halt its bombardment of Gaza for three hours  every day to allow residents of the Hamas-ruled Palestinian territory to obtain much-needed supplies, a military spokesman says.<br />
The images broadcast here where graphic and striking.<br />
The Al Jazeera English report below captures the extent of the devastation caused by the initial strikes.</p>
<p>Proceed to view details:</p>
<p>hxxp://edition.cnn.2009.completeserv.*****-******.israelgazaconflict.com/israel-gaza.htm?/****</p>
<p>2009 Cable News Network. A Time Warner Company. All Rights Reserved.</p></blockquote>
<p>The included URL will lead  visitors to a web site that looks like the CNN site. Download screens promts appear, to update your Adobe Acrobat or Flash player software,  when you click on a link to view the video. Getting out of the loop can only done by closing your browser session. If the download is accepted, a Trojan is installed which opens communication for the download of further malware from a remote location.</p>
<p>A similar campaign has been done in the past with the <a href="http://blog.mxlab.be/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/">CNN Daily top 10</a> and the <a href="http://blog.mxlab.be/2008/08/08/cnn-alerts-my-custom-alert-malware/">CNN Alerts</a>. These previous campaigns caused several new infections because the receivers of these emails thought this was a legit email because of the CNN look-and-feel that was used to mislead readers.</p>
<p>The current campaign isn&#8217;t having a CNN branding at the moment so it should look supsicious right away to anyone. Be carefull.</p>
<p><a href="http://behindthescenes.blogs.cnn.com/2009/01/09/caution-fake-spam-message-alleges-to-be-from-cnn/" target="_blank">CNN&#8217;s Behind the Scenes blog</a> warns their readers not to download any software pertaining to the Gaza conflict.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/327/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/327/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/327/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=327&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/01/14/conflict_in_gaza_inspires_new_cnn_campaign_from_malware_authors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>CNN Alerts: My Custom Alert malware</title>
		<link>http://blog.mxlab.eu/2008/08/08/cnn-alerts-my-custom-alert-malware/</link>
		<comments>http://blog.mxlab.eu/2008/08/08/cnn-alerts-my-custom-alert-malware/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 11:49:15 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[cnn]]></category>
		<category><![CDATA[cnn alerts]]></category>
		<category><![CDATA[cnn custom alert]]></category>
		<category><![CDATA[cnn trojan]]></category>
		<category><![CDATA[cnn virus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=165</guid>
		<description><![CDATA[After a very long outbreak based on the CNN Dailty Top 10 it&#8217;s now time for something different: CNN Alerts: My Custom Alert. This new version brings more of the CNN malware outbreak in a changed lay out but with the same tactics. Again, the email itself is very nice CNN branded but contains a link [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=165&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>After a very long outbreak based on the CNN Dailty Top 10 it&#8217;s now time for something different: CNN Alerts: My Custom Alert. This new version brings more of the CNN malware outbreak in a changed lay out but with the same tactics.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20080808_cnn_alerts.gif" alt="" width="340" height="243" /></p>
<p>Again, the email itself is very nice CNN branded but contains a link that leads you directly to the malware. The senders address is spoofed and is not coming from cnn.com but this is not guaranteed for the future.</p>
<p>The <strong>link behind Full Story</strong> - so don&#8217;t click on this one &#8211; brings you to a, in this case, Russian web site where you need to download the proper Flash player to view the video. When you accept the malware file adobe_flash.exe is downloaded.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20080808_cnn_alerts_2.gif" alt="" width="340" height="237" /></p>
<p>The trojan has the same specs of the CNN Daily Top 10: Trojan-Downloader.Agent.EL. This trojan will create a new process on an infected machine: %System%\cbevtsvc.exe and creates a new service CbEvtSvc in the system. Quite some registry modifications are being made as well as a direct IP address connection to a remote host on TCP/IP port 443.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/165/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/165/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/165/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=165&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/08/08/cnn-alerts-my-custom-alert-malware/feed/</wfw:commentRss>
		<slash:comments>43</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20080808_cnn_alerts.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20080808_cnn_alerts_2.gif" medium="image" />
	</item>
		<item>
		<title>CNN Daily Top 10 leads users to site hosting malware</title>
		<link>http://blog.mxlab.eu/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/</link>
		<comments>http://blog.mxlab.eu/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/#comments</comments>
		<pubDate>Mon, 04 Aug 2008 21:40:11 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[cnn]]></category>
		<category><![CDATA[cnn daily top 10]]></category>
		<category><![CDATA[cnn daily top 10 malware]]></category>
		<category><![CDATA[cnn malware]]></category>
		<category><![CDATA[flash player malware]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[top 10]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[trojan downloader]]></category>
		<category><![CDATA[video codec malware]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=144</guid>
		<description><![CDATA[Following the links in the CNN.com Daily Top 10 email could lead you to sites that hosts malware. MX Lab detected and intercepted the first messages at around 7:48 PM local Belgian time and is monitoring an outbreak of this type. Malware authors are abusing CNN by using the logo, the lay out and the concept [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=144&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Following the links in the CNN.com Daily Top 10 email could lead you to sites that hosts malware. MX Lab detected and intercepted the first messages at around 7:48 PM local Belgian time and is monitoring an outbreak of this type.</p>
<p>Malware authors are abusing CNN by using the logo, the lay out and the concept of the CNN Daily Top 10 to distribute emails with URLs that point to sites that host malware.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20080804_cnn_01.gif" alt="" width="340" height="338" /></p>
<p>The messages itself is sent from a random generated user email address not on the cnn.com domain. The links behind the top 10 directs you to a web site that should show you the video but instead gives you an error that an incorrect Flash player is installed.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20080804_cnn_02.gif" alt="" width="340" height="443" /></p>
<p>A pop up window will ask you to download the correct video codec, an executable called get_flash_update.exe, but this is in fact the Trojan-Downloader.Agent.EL. This trojan ca an download and installs other malware onto infected machine.</p>
<p>This trojan will in fact create a new process on an infected machine: %System%\cbevtsvc.exe and creates a new service CbEvtSvc in the system. Quite some registry modifications are being made as well as a direct IP address connection to a remote host on TCP/IP port 443.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/327b65afddb3fe28aebd1d4896e25031" target="_blank">permalink</a> and MD5: dabb5a9b431c88c77281bcf1158a9879.</p>
<p>Remark: CNN is not responsible for the CNN Daily Top 10 that contained URLs to sites that host malware in the form of a downloadable Flash codec.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/144/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/144/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/144/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=144&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/feed/</wfw:commentRss>
		<slash:comments>117</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20080804_cnn_01.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20080804_cnn_02.gif" medium="image" />
	</item>
	</channel>
</rss>