<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Email security</title>
	<atom:link href="http://blog.mxlab.eu/tag/email-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Email security</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Malware distribution techniques</title>
		<link>http://blog.mxlab.eu/2008/04/21/malware-distribution-techniques/</link>
		<comments>http://blog.mxlab.eu/2008/04/21/malware-distribution-techniques/#comments</comments>
		<pubDate>Mon, 21 Apr 2008 18:14:02 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[root kit]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Trojan-PSW.Win32.Papras]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=66</guid>
		<description><![CDATA[At first I thought of a new phishing email, based on the fact that it comes from a bank, includes a long URL in the body and it is related to your banking account where you need to renew your certificate. Connection-Colonial Bank Renewal Certificate Renewal Personal (Smartcard) e-Cert  Personal e-Cert Certificate owner must renew [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=66&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>At first I thought of a new phishing email, based on the fact that it comes from a bank, includes a long URL in the body and it is related to your banking account where you need to renew your certificate.</p>
<p><em>Connection-Colonial Bank Renewal</em></p>
<p><em>Certificate Renewal<br />
Personal (Smartcard) e-Cert  Personal e-Cert<br />
Certificate owner must renew the certificate before expiry date.<br />
Your certificate expiration date &#8211; 1may 2008.<br />
The system will send email (Certificate Renewal Notice) to the certificate owner ten days and 3 hours before the certificate is due to expire, if it has not been renewed. Upon receiving the renewal notice, certificate owner is required to connect to Colonial Bank Certificate Management System and present the client certificate. Secure Server e-Cert  Developer e-Cert<br />
Certificate owner has the responsibility to renew the certificate before expiry date. Successful renewed application will receive an email notification from Colonial Bank. Applicant can just browse to the URL stated in the email and then download the certificate.</em></p>
<p><em>Download now </em></p>
<p><em>2003 Colonial Bank, N.A.</em></p>
<p>Further investigation show us that it is indeed a technique to distribute malware. The download URL doesn&#8217;t give a login screen but takes you to a web site where you need to download the certificate and this is an .exe.</p>
<p><img src="http://www.mxlab.be/img_news/20080421_malware_s.gif" alt="" width="340" height="460" /></p>
<p>The download gives us an Colonial_CertificateUpdate04192008.exe and is in fact the Trojan-PSW.Win32.Papras. This trojan steals login credentials and other sensitive information on the compromised system. It also drops and uses a rootkit driver to hide itself. The rootkit driver is detected as Rootkit.Win32.Agent.SZ.</p>
<p>As always, take extra attention if you receive these kind of formatted emails.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/66/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/66/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=66&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/04/21/malware-distribution-techniques/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.be/img_news/20080421_malware_s.gif" medium="image" />
	</item>
		<item>
		<title>Phishing levels peak</title>
		<link>http://blog.mxlab.eu/2008/04/14/phishing-levels-peak/</link>
		<comments>http://blog.mxlab.eu/2008/04/14/phishing-levels-peak/#comments</comments>
		<pubDate>Mon, 14 Apr 2008 00:35:00 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Email security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=62</guid>
		<description><![CDATA[MX Lab detects in increase in phishing emails between 09/04/2008 and 13/04/2008, bringing the phishing level up to 0,28% of all blocked messages where in the past this level was 0,03%. These phishing emails are mostly regarding a &#8220;locked bank account&#8221; or &#8220;verify your details&#8221; but we see other phishing attempts targeting Google Adwords customers [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=62&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detects in increase in phishing emails between 09/04/2008 and 13/04/2008, bringing the phishing level up to 0,28% of all blocked messages where in the past this level was 0,03%.</p>
<p>These phishing emails are mostly regarding a &#8220;locked bank account&#8221; or &#8220;verify your details&#8221; but we see other phishing attempts targeting Google Adwords customers stating that their account is locked.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/62/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/62/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/62/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=62&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/04/14/phishing-levels-peak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Very good PayPal phishing email</title>
		<link>http://blog.mxlab.eu/2008/04/02/very-good-paypal-phishing-email/</link>
		<comments>http://blog.mxlab.eu/2008/04/02/very-good-paypal-phishing-email/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 11:12:53 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Email security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[MX Lab]]></category>
		<category><![CDATA[paypal]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=58</guid>
		<description><![CDATA[A certain phishing email from &#8216;PayPal&#8217; caught our attention. When investigating the phishing email we could find that this is a very professional one. The email in fact confirms your payment to a company, in this case Plimus, for an amout of$55,89 USD. The email provides a link to dispute the transaction and this is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=58&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A certain phishing email from &#8216;PayPal&#8217; caught our attention. When investigating the phishing email we could find that this is a very professional one. The email in fact confirms your payment to a company, in this case Plimus, for an amout of$55,89 USD. The email provides a link to dispute the transaction and this is where the phishing starts.
<p><img src="http://www.mxlab.be/img_news/20080402_phishing_paypal_1s.gif" width="340" height="365" /></p>
<p>Following the link to report a dispute results in being directed to http://**-***-**-***.fld-bsr1.chi-fld.il.******.cable.rcn.com:90/www.paypal.com/cgi-bin/ and it brings you to the &#8220;PayPal login screen&#8221;.</p>
<p>Typical to phishing sites is that you can type in whatever you want as login or password, you will always be directed to a webform.</p>
<p>These guys have even included the animated screen &#8216;Logging in&#8217; that you have when logging in to the real PayPal web site. After this screen you get a full webform which will try to get your full details. <img src="http://www.mxlab.be/img_news/20080402_phishing_paypal_3s.gif" width="340" height="347" />  </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/58/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/58/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=58&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/04/02/very-good-paypal-phishing-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.be/img_news/20080402_phishing_paypal_1s.gif" medium="image" />

		<media:content url="http://www.mxlab.be/img_news/20080402_phishing_paypal_3s.gif" medium="image" />
	</item>
		<item>
		<title>MX Lab protects Comap Nordic email communication</title>
		<link>http://blog.mxlab.eu/2007/10/12/comap-extends-the-mx-lab-service/</link>
		<comments>http://blog.mxlab.eu/2007/10/12/comap-extends-the-mx-lab-service/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 15:16:01 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[Email security]]></category>
		<category><![CDATA[managed email security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zero hour virus protection]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/10/12/comap-extends-the-mx-lab-service/</guid>
		<description><![CDATA[After providing email security for Comap Benelux, MX Lab extends its services to protect email communication for the domains comap.se/.no/.fi and .dk.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=50&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>After providing email security for Comap Benelux, MX Lab extends its services to protect email communication for the domains comap.se/.no/.fi and .dk.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/50/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/50/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=50&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/10/12/comap-extends-the-mx-lab-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>