<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Phishing</title>
	<atom:link href="http://blog.mxlab.eu/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Mon, 13 Feb 2012 23:20:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Phishing</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails regarding rejected ACH payment contains security risk</title>
		<link>http://blog.mxlab.eu/2012/01/31/emails-regarding-rejected-ach-payment-contains-security-risk/</link>
		<comments>http://blog.mxlab.eu/2012/01/31/emails-regarding-rejected-ach-payment-contains-security-risk/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 19:08:02 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Email security]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[security risk]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1601</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subjects like: Rejected ACH transaction Rejected ACH payment Your ACH transfer &#8230; The email is send from the spoofed addresses like: &#8220;\&#8221;The Electronic Payments Association\&#8221; risk.manager&#8221;@nacha.org &#8220;\&#8221;The Electronic Payments Association\&#8221; alerts&#8221;@nacha.org &#8220;\&#8221;The Electronic Payments Association\&#8221; risk&#8221;@nacha.org &#8220;\&#8221;The Electronic Payments Association\&#8221; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1601&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subjects like:</p>
<p>Rejected ACH transaction<br />
Rejected ACH payment<br />
Your ACH transfer<br />
&#8230;</p>
<p>The email is send from the spoofed addresses like:</p>
<p>&#8220;\&#8221;The Electronic Payments Association\&#8221; risk.manager&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; alerts&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; risk&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; transfers&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; ach&#8221;@nacha.org<br />
&#8220;\&#8221;The Electronic Payments Association\&#8221; payment&#8221;@nacha.org<br />
&#8230;</p>
<p>The email has the following body:</p>
<blockquote><p>The ACH transaction (ID: 02710822288793), recently sent from your checking account (by you or any other person), was rejected by the Electronic Payments Association.</p>
<p>Canceled transaction<br />
Transaction ID: 02710822288793<br />
Reason for rejection See details in the report below<br />
Transaction Report report_02710822288793.doc (Microsoft Word Document)</p>
<p>13450 Sunrise Valley Drive, Suite 100<br />
Herndon, VA 20171</p>
<p>2011 NACHA &#8211; The Electronic Payments Association</p></blockquote>
<p>A sample of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120131_ACH_risk.jpg" alt="" width="450" height="283" /></p>
<p>The URLs for the transaction report are different and in some cases no longer valid. Some examples:</p>
<p>hxxp://minalimo.com/f9oYYmiY/index.html<br />
hxxp://maerlipinte.ch/LaV4inWa/index.html<br />
hxxp://hotel-sicily.it/aRpcdCjd/index.html<br />
&#8230;</p>
<p>One of the URLs did give us a result: hxxp://ftp.samisalami.com/8KQZuSAy/index.html.</p>
<p>When investigating the HTML code of this web page we got the following:</p>
<blockquote><p>&lt;html&gt;<br />
&lt;h1&gt;WAIT PLEASE&lt;/h1&gt;<br />
&lt;h3&gt;Loading&#8230;&lt;/h3&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://firstnamestore.com/utn08WYD/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://ftp.adamsmarketing.com/VRssE3iH/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://mediapoolstarnberg.de/WrqeCaoy/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://paolomisirochi.com/nqrmZKRC/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://lonnytyler.com/MZF0uXsc/js.js&#8221;&gt;&lt;/script&gt;<br />
&lt;script type=&#8221;text/javascript&#8221; src=&#8221;hxxp://orquestrachapo.com/jAmCDzeM/js.js&#8221;&gt;&lt;/script&gt;</p>
<p>&lt;/html&gt;</p></blockquote>
<p>As you can see, some Javascripts are loaded when opening this web page. Some URLs to the javascripts are also obsolete but some of them returns the code: &#8220;document.location=&#8217;hxxp://sulusate.com/forum/index.php?showtopic=997439&#8242;;&#8221;.</p>
<p>The above URL gives us the web page with the following code:</p>
<blockquote><p>&lt;body&gt;<br />
&lt;applet code=&#8217;Verifa.class&#8217; archive=&#8217;rhi.jar&#8217; width=&#8217;24&#8242; height=&#8217;22&#8242;&gt;<br />
&lt;param name=&#8221;dest&#8221; value=&#8221;lxxt&gt;33wypywexi2gsq3jsvyq3pseh2tltCwls{jsvyqAvlmrs&#8221;&gt;<br />
&lt;/applet&gt;<br />
&lt;/body&gt;&lt;body&gt;<br />
&lt;applet code=&#8217;Ooo.class&#8217; archive=&#8217;Ooo.jar&#8217; width=&#8217;24&#8242; height=&#8217;22&#8242;&gt;<br />
&lt;param name=&#8221;dest&#8221; value=&#8221;lxxt&gt;33wypywexi2gsq3jsvyq3pseh2tltCwls{jsvyqAsfi&#8221;&gt;<br />
&lt;/applet&gt;<br />
&lt;/body&gt;</p></blockquote>
<p>When opening the URLs  in a web browser &#8211; something we do not recommend to even try &#8211; you will get redirected to bing.com or another web site so you won&#8217;t see this code.</p>
<p>It seems that some javascript is obfuscated and that .jar files are involved here inside an applet. The risk is that these applets in java could contain malicious code. Ooo.jar is however related to OpenOffice but in this case it can also be used for phishing.</p>
<p>This email is a security risk &#8211; a virus or a phishing attempt &#8211; for sure so do not follow any URLs or open files.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1601/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1601/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1601/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1601&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/31/emails-regarding-rejected-ach-payment-contains-security-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2012/20120131_ACH_risk.jpg" medium="image" />
	</item>
		<item>
		<title>Rabobank phishing emails with attachment</title>
		<link>http://blog.mxlab.eu/2011/11/30/rabobank-phishing-emails-with-attachment/</link>
		<comments>http://blog.mxlab.eu/2011/11/30/rabobank-phishing-emails-with-attachment/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 23:38:38 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rabobank]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1539</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted a phishing campaign with the subject &#8220;ACCOUNT ACTIVEREN&#8221; that targets Rabobank users. The emails are sent from the spoofed emailaddress &#8220;Rabobank &#60;service@aupairconnect.com&#62;&#8221; and have the following body in Dutch: Amsterdam Code : 007498. Geachte Rabobank. klant, Rabobank is niet in staat om uw rekening te verifieren. Uw rekening moet zo snel [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1539&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercepted a phishing campaign with the subject &#8220;ACCOUNT ACTIVEREN&#8221; that targets Rabobank users. The emails are sent from the spoofed emailaddress &#8220;Rabobank &lt;service@aupairconnect.com&gt;&#8221; and have the following body in Dutch:</p>
<blockquote><p>Amsterdam Code :</p>
<p>007498.</p>
<p>Geachte Rabobank. klant,</p>
<p>Rabobank is niet in staat om uw rekening te verifieren.</p>
<p>Uw rekening moet zo snel mogelijk gecontroleerd worden.</p>
<p>Uw kunt dit doen door de onderstaand link te download met ur system.</p>
<p>Opmerking: U zal gecontacteerd worden door een van onze medewerkers van Rabobank voor meer informatie over dit nieuwe systeem.</p>
<p>Hoogachtend,</p>
<p>Customer Service,</p>
<p>Rabobank.</p>
<p>*Belangrijk*</p>
<p>Werk uw administratie op of voor 48 uur, een gebrek aan uw administratie bij te werken zal resulteren in een tijdelijke greep op uw geld.</p>
<p>© 2011 Rabobank. N.V. Nederland? . All rights reserved.</p></blockquote>
<p>The email comes with an attachment named Activeren.html and this HTML files contains a web form that will submit the details to the host hxxp://www.paminklaita.lt/images/go.php.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111130_rabobank_phish.jpg" alt="" width="450" height="604" /></p>
<p>As always, MX Lab advises not to fill in any details when receiving emails from your bank with HTML attachments included.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1539/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1539/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1539/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1539/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1539/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1539/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1539/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1539/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1539&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/11/30/rabobank-phishing-emails-with-attachment/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20111130_rabobank_phish.jpg" medium="image" />
	</item>
		<item>
		<title>Different versions of ABN AMRO phishing email in circulation</title>
		<link>http://blog.mxlab.eu/2011/11/23/different-versions-of-abn-amro-phishing-email-in-circulation/</link>
		<comments>http://blog.mxlab.eu/2011/11/23/different-versions-of-abn-amro-phishing-email-in-circulation/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 14:21:24 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[ABM AMRO phish]]></category>
		<category><![CDATA[ABN AMRO]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1520</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, detected different versions of ABN AMRO phishing emails that are in circulation on a daily base targeting Dutch ABN AMRO bank account users. ABN AMRO Systeembeveiliging The first variant, with a very good lay out and style, comes with the subject &#8220;ABN AMRO Systeembeveiliging&#8221; or &#8220;ABN AMRO Systeembeveiling&#8221; and is sent from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1520&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, detected different versions of ABN AMRO phishing emails that are in circulation on a daily base targeting Dutch ABN AMRO bank account users.</p>
<p><strong>ABN AMRO Systeembeveiliging</strong></p>
<p>The first variant, with a very good lay out and style, comes with the subject &#8220;ABN AMRO Systeembeveiliging&#8221; or &#8220;ABN AMRO Systeembeveiling&#8221; and is sent from the spoofed email address &#8220;ABN AMRO NV &lt;customercare@abnamro.nl&gt;&#8221;.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_1_a.jpg" alt="" width="450" height="376" /></p>
<p>This will redirect you to hxxp://www.clumber.net/abnamro/abn.html.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_1_b.jpg" alt="" width="450" height="430" /></p>
<p>When filling in al the details a redirect to the real ABN Amro is executed.</p>
<p><strong>Belangrijk bericht van ABN AMRO Bank</strong></p>
<p>The second variant comes with the subject &#8220;Belangrijk bericht van ABN AMRO Bank&#8221; and is sent from the spoofed email address &#8220;ABN AMRO Bank &lt;klant.services@abnamro.nl&gt;&#8221;.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_2_a.jpg" alt="" width="450" height="197" /></p>
<p><strong>Beveiliging Message Alert van ABN AMRO Bank</strong></p>
<p>Another variant comes with the subject &#8220;Beveiliging Message Alert van ABN AMRO Bank&#8221; and is sent from the spoofed email address &#8220;ABN AMRO BANK &lt;customer.services@abnamro.nl&gt;&#8221;.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_3_a.jpg" alt="" width="450" height="187" /></p>
<p><strong>Installatie mijn ABN AMRO Bank</strong></p>
<p>This one comes with the subject &#8220;Installatie mijn ABN AMRO Bank&#8221; and is sent from a random spoofed email address.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_4_a.jpg" alt="" width="450" height="131" /></p>
<p>This one will redirect you to hxxp://70.38.120.162/~abnsecbk/secure/.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_4_b.jpg" alt="" width="450" height="421" /></p>
<p><strong>ABN-AMRO BANK</strong></p>
<p>This last one comes with the subject &#8220;Belangrijk Nieuws Mijn ABN-AMRO Bank&#8221; and is sent from a random spoofed email address.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_5_a.jpg" alt="" width="450" height="140" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1520/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1520/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1520/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1520&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/11/23/different-versions-of-abn-amro-phishing-email-in-circulation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_1_a.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_1_b.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_2_a.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_3_a.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_4_a.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_4_b.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111123_abnamro_phish_5_a.jpg" medium="image" />
	</item>
		<item>
		<title>Increase your security with the MX Lab services at a special promotion price!</title>
		<link>http://blog.mxlab.eu/2011/11/03/increase-your-security-with-the-mx-lab-services-at-a-special-promotion-price/</link>
		<comments>http://blog.mxlab.eu/2011/11/03/increase-your-security-with-the-mx-lab-services-at-a-special-promotion-price/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 23:33:57 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[MX Lab]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zero hour antivirus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1499</guid>
		<description><![CDATA[Increase your security with the MX Lab services at a special promotion price until 31 December 2011! MX Lab offers it&#8217;s zero hour anti virus, managed anti spam and email archiving services at a lower price of € 7 per user per year*, a huge € 2 per user discount, and the great news is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1499&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Increase your security with the MX Lab services at a special promotion price until 31 December 2011!</strong></p>
<p><a href="http://www.mxlab.eu" target="_blank">MX Lab</a> offers it&#8217;s zero hour anti virus, managed anti spam and email archiving services at a lower <strong>price of € 7 per user per year*</strong>, a huge € 2 per user discount, and the great news is that you only need to <a href="http://www.mxlab.eu/en/contactus/trial_audit.html" target="_blank">request a 15 day trial</a> and change your MX records to make use of our service.</p>
<p>Our special promotion price also affects our other services like Email Archiving or the Hosted solutions. Visit our web site for a <a href="http://www.mxlab.eu/en/pricing/index.html" target="_blank">full pricing overview</a>.</p>
<p><a href="http://www.mxlab.eu/en/contactus/trial_audit.html" target="_blank">Request your 15 day trial today!</a></p>
<p>Are you active as an IT solutions provider and want to offer the MX Lab services to your clients? Do not hesitate to contact us and join the <a href="http://www.mxlab.eu/en/partners/partner_program.html" target="_blank">MX Lab Partner Program</a> and benefit for the special pricing as well!</p>
<p>* MX Lab offers its services at a special promotion price until 31 December 2011. In order to obtain the promotion you will need to request a 15 day trial and use the trial account by modifying your MX records in order to use the MX Lab service. Each trial that is converted in a subscription at the end of the trial will benefit of the special lower price for one year.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1499/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1499&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/11/03/increase-your-security-with-the-mx-lab-services-at-a-special-promotion-price/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>SNS Bank subject in phishing campaign by email with attached web form</title>
		<link>http://blog.mxlab.eu/2011/10/07/sns-bank-subject-in-phishing-campaign-by-email-with-attached-web-form/</link>
		<comments>http://blog.mxlab.eu/2011/10/07/sns-bank-subject-in-phishing-campaign-by-email-with-attached-web-form/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 10:57:14 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[SNS Bank]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1483</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a phishing campaign by email with the subject &#8220;SNSBANK : Rekening Activeren&#8221;  sent form the spoofed email address &#8220;SNS Bank &#60;admin@72.29.75.183.com&#62;&#8221;. The email is  has the following body (including the SNS Bank logo on top): Geachte klant, SNS is niet in staat om uw rekening te verifiлren. Uw rekening [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1483&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a phishing campaign by email with the subject &#8220;SNSBANK : Rekening Activeren&#8221;  sent form the spoofed email address &#8220;SNS Bank &lt;admin@72.29.75.183.com&gt;&#8221;.</p>
<p>The email is  has the following body (including the SNS Bank logo on top):</p>
<blockquote><p>Geachte klant,</p>
<p>SNS is niet in staat om uw rekening te verifiлren. Uw rekening dient zo snel mogelijk geverifieerd te worden.</p>
<p>U kunt uw rekening simpel weg verifiлren door op de volgende link te klikken.</p>
<p>Om de procedure te starten download en klik op de onderstaande link.</p>
<p>Lukt dit proces? Dan word u doorverwezen naar het Klantenservice van sns.nl</p>
<p>SNS bedankt u voor uw medewerking</p>
<p>Hoogachtend,<br />
Klantenservice,</p>
<p>Ga snel naar:</p>
<p>© 2011 SNS Bank<br />
SNS Bank<br />
Inloggen<br />
Disclaimer<br />
Privacy- en cookiereglement<br />
Over SNS Bank<br />
Klantenservice</p></blockquote>
<p>The email has the attachment SNS_RekeningActiveren. Once downloaded and openen we found the following web form to fill in:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111007_SNSBank_1.jpg" alt="" width="450" height="411" /></p>
<p>The web form will submit the filled in details to hxxp://www.couvreurrivesud.ca/images/go.php and redirect you to the official and real SNS Bank web site.</p>
<p>Phishing attempts with attachments are not new. It is one of the techniques we&#8217;ve seen emerging last year in order to avoid interception by URL filters when emails are scanned. Even today we see several different campaigns based on this technique.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1483/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1483/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1483/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1483/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1483/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1483/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1483/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1483/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1483&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/10/07/sns-bank-subject-in-phishing-campaign-by-email-with-attached-web-form/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20111007_SNSBank_1.jpg" medium="image" />
	</item>
		<item>
		<title>Paypal phishing emails with very nice campaign template</title>
		<link>http://blog.mxlab.eu/2011/10/03/paypal-phishing-emails-with-very-nice-campaign-template/</link>
		<comments>http://blog.mxlab.eu/2011/10/03/paypal-phishing-emails-with-very-nice-campaign-template/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 09:02:50 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[paypal]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1473</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted a series of Paypal phishing emails with the subject &#8220;Your PayPal account has been limited&#8221; sent from the spoofed email address &#8220;Paypal &#60;service@paypal.com&#62;&#8221;. The phish looks very good and is well designed. The spoofed emailaddress, the logo, layout and even the footer matches. Images are taken from the web server http://pics.ebaystatic.com/. One small [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1473&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu/" target="_blank">http://www.mxlab.eu</a>, intercepted a series of Paypal phishing emails with the subject &#8220;Your PayPal account has been limited&#8221; sent from the spoofed email address &#8220;Paypal &lt;service@paypal.com&gt;&#8221;.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111003_paypal_phish_1.jpg" alt="" width="450" height="551" /></p>
<p>The phish looks very good and is well designed. The spoofed emailaddress, the logo, layout and even the footer matches. Images are taken from the web server http://pics.ebaystatic.com/. One small thing to notice is that in the footer the word &#8220;Unsubscribe&#8221; doesn&#8217;t have an unsubscribe option but apart from that, this phish scores.</p>
<p>The URL points to hxxp://www.mittemaedchen.de/twg176/admin/www.paypal.co.uk/details.php?cmd=_login-done&amp;login_access=1193476743.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111003_paypal_phish_2.jpg" alt="" width="450" height="364" /></p>
<p>At this form, the phishers will take over the filled in details and redirect you to a new screen.</p>
<p>The form does warn you when some fields are not filled in but doesn&#8217;t check if the VISA card number matches with the verification number to validate the card number.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111003_paypal_phish_3.jpg" alt="" width="450" height="345" /></p>
<p>After this screen you are redirected to the official PayPal web sites at the login screen.</p>
<p>Note: at the time of writing Firefox did not issue a warning regarding this phishing site.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1473/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1473/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1473/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1473/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1473/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1473/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1473/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1473/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1473&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/10/03/paypal-phishing-emails-with-very-nice-campaign-template/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20111003_paypal_phish_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111003_paypal_phish_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20111003_paypal_phish_3.jpg" medium="image" />
	</item>
		<item>
		<title>ING phishing email with a twist</title>
		<link>http://blog.mxlab.eu/2011/10/03/ing-phishing-email-with-a-twist/</link>
		<comments>http://blog.mxlab.eu/2011/10/03/ing-phishing-email-with-a-twist/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 08:35:46 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[ING]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1471</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted a series of ING phishing emails in Dutch with the subject &#8220;Controleer nu uw gegevens&#8221; from the spoofed email address &#8220;ING BANK N.V. &#60;security@ing.nl&#62;&#8221;. The email caught our attention because the Dutch version is quite good. This is the body text: Het is u ongetwijfeld niet ontgaan dat wij de laatste [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1471&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercepted a series of ING phishing emails in Dutch with the subject &#8220;Controleer nu uw gegevens&#8221; from the spoofed email address &#8220;ING BANK N.V. &lt;security@ing.nl&gt;&#8221;.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20111003_ing_phish_1.jpg" alt="" width="450" height="334" /></p>
<p>The email caught our attention because the Dutch version is quite good. This is the body text:</p>
<blockquote><p>Het is u ongetwijfeld niet ontgaan dat wij de laatste tijd doelwit zijn van internetcriminaliteit. Om te voorkomen dat deze internetcriminelen misbruik van uw rekening kunnen maken hebben wij onlangs een waarschuwing gepubliceerd. Ondanks deze waarschuwingen komt het helaas nog te vaak voor dat er internetcriminelen misbruik maken van ons beveiligingssysteem. Wij verzoeken u daarom direct te controleren of uw saldo en gegevens nog correct zijn.Tevens verzoeken wij u om uw telefoonnummer bij ons te registreren zodat wij u kunnen bereiken in geval van fraude. verifieren door op de volgende link te klikken..</p>
<p>Controleer nu uw gegevens</p>
<p>Wij willen u er nogmaals op attenderen dat een link naar onze website altijd begint het https://mijn.ing.nl dit is namelijk een beveiligde link met 128 bits encryptie. Bedankt voor uw aandacht en medewerking.,</p>
<p>Customer Service,<br />
2011 ING BANK Nederland</p></blockquote>
<p>However, let&#8217;s analyze the email. At the end of the first paragraph we noticed that the sentence &#8220;verifieren door op de volgende link te klikken..&#8221; is not complete.</p>
<p>And then, the text below the URL mentions &#8220;een link naar onze website altijd begint het https://mijn.ing.nl dit is namelijk een beveiligde link met 128 bits encryptie&#8221;. Translated to English it says &#8220;a link to our site always starts https://mijn.ing.nl because this is a secure link with 128-bit encryption&#8221;. When hovering over the URL under &#8220;Controleer nu uw gegevens&#8221; we have the URL hxxp://www.apartamentainaglis.com/en/includes/Cache/includes/default.html which is clearly not an https or secured connection as they mentioned in the standard copied text.</p>
<p>So, if you ever receive such a phishing email, take a look at the fine details. In most cases, you can identify a phish by such poorly formatted emails.</p>
<p>Firefox warns about this phishing attempt and the account is already disabled at the hosting company.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1471/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1471/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1471/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1471/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1471/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1471/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1471/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1471/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1471&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/10/03/ing-phishing-email-with-a-twist/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20111003_ing_phish_1.jpg" medium="image" />
	</item>
		<item>
		<title>Google AdWords phishing campaign</title>
		<link>http://blog.mxlab.eu/2011/09/26/google-adwords-phishing-campaign/</link>
		<comments>http://blog.mxlab.eu/2011/09/26/google-adwords-phishing-campaign/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 15:51:00 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Adwords]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Google Adwords]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1453</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new phishing campaign with the subject &#8220;Account has stopped running&#8221; and comes from the spoofed email address &#8220;Google Adword &#60;adwords-noreply@google.com&#62;&#8221;. This campaign targets AdWords users. The recipient is informed that his Adwords campaigns stopped running as of this morning Monday, September 26, 2011. This is the full content: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1453&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new phishing campaign with the subject &#8220;Account has stopped running&#8221; and comes from the spoofed email address &#8220;Google Adword &lt;adwords-noreply@google.com&gt;&#8221;. This campaign targets AdWords users.</p>
<p>The recipient is informed that his Adwords campaigns stopped running as of this morning Monday, September 26, 2011.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110926_AdWords_phishing.jpg" alt="" width="450" height="220" /></p>
<p>This is the full content:</p>
<blockquote><p>We stopped running your Google ads this morning (Monday, September 26, 2011).</p>
<p>Dear AdWords Advertiser,</p>
<p>We had encountered a number of issues when reviewing your ads this morning and we stopped running them. We will review them again and make the necessary changes that will allow to run your ads without any problems.</p>
<p>lightbulbClick here to review your ads and let us know if we made a mistake.</p>
<p>We&#8217;ll often stop running your ads until we are able to make the necessary updates. As soon as we made and saved the changes, your ads are automatically resubmitted to us for review.</p>
<p>Please note: If you do not verify the status of your Adwords account and notify us if your ads do not appear online we can not help you and your ads will stay offline for the next few days.</p>
<p>2011 Google is a trademark of Google Inc. All other company and product names may be trademarks of the respective companies with which they are associated. 1600 Amphitheatre Parkway Mountain View, CA 94043</p></blockquote>
<p>The included URL leads to hxxp://www.google-ars.com/accounts/?ServiceLogin?service=adwords and brings the visitor to the following login webpage.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110926_AdWords_phishing_2.jpg" alt="" width="450" height="477" /></p>
<p>The login page will request the page login.php and redirect the visitor to an official Google AdWords page http://adwords.google.com/support/aw/bin/answer.py?hl=en&amp;answer=142731.</p>
<p>Now, when I was looking at the above page it made me wonder if this version of the login page is still up to date. I surfed to the Google Adwords page and got the following</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110926_AdWords_phishing_3.jpg" alt="" width="450" height="384" /></p>
<p>It seems to me that the authors of this campaign didn&#8217;t take the effort to check the design and layout of the phishing login page and modify it to the changed design that is online at Google. Never mind, it&#8217;s even better for us to see the difference between an real site from Google and an phishing attempt.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1453/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1453/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1453/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1453&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/09/26/google-adwords-phishing-campaign/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110926_AdWords_phishing.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110926_AdWords_phishing_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110926_AdWords_phishing_3.jpg" medium="image" />
	</item>
		<item>
		<title>Google AdWords phishing attempt</title>
		<link>http://blog.mxlab.eu/2011/07/25/google-adwords-phishing-attempt/</link>
		<comments>http://blog.mxlab.eu/2011/07/25/google-adwords-phishing-attempt/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 20:53:19 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Google Adwords]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1427</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted a phishing campaign, targetting Google AdWords. The phishing emails comes from the spoofed email address &#8220;adwords-noreply@google.com&#8221; and has the subject &#8220;Account has stopped running this morning&#8221;. The body of the email: The URL points to hxxp://www.google-hs.com/accounts/?ServiceLogin?service=adwords&#38;hl=en_US and this will redirect visitors to hxxp://adwords.google-oa.net/adwords/?ServiceLogin?service=adwords&#38;hl=en_US<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1427&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercepted a phishing campaign, targetting Google AdWords. The phishing emails comes from the spoofed email address &#8220;adwords-noreply@google.com&#8221; and has the subject &#8220;Account has stopped running this morning&#8221;.</p>
<p>The body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110725_googleadwords_1.jpg" alt="" width="450" height="187" /></p>
<div></div>
<p>The URL points to hxxp://www.google-hs.com/accounts/?ServiceLogin?service=adwords&amp;hl=en_US and this will redirect visitors to hxxp://adwords.google-oa.net/adwords/?ServiceLogin?service=adwords&amp;hl=en_US</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110725_googleadwords_2.jpg" alt="" width="450" height="475" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1427/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1427/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1427/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1427/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1427/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1427/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1427/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1427/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1427&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/07/25/google-adwords-phishing-attempt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110725_googleadwords_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110725_googleadwords_2.jpg" medium="image" />
	</item>
		<item>
		<title>HM Revenue &amp; Customs phishing emails &#8211; continued</title>
		<link>http://blog.mxlab.eu/2011/04/01/hm-revenue-customs-phishing-emails-continued/</link>
		<comments>http://blog.mxlab.eu/2011/04/01/hm-revenue-customs-phishing-emails-continued/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 05:06:56 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[HM Revenue & Customs]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1346</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, is intercepting tax refund phishing emails with the subject “Please Submit Your Payment Refund″ and an attached HTML webpage. We have reported this earlier on on January 27th, 2011, and this campaign is still running in a modified version. The emails is send from the spoofed email address srvcs@hmrc.gov.uk, and possible other [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1346&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu/" target="_blank">http://www.mxlab.eu</a>, is intercepting tax refund phishing emails with the subject “Please Submit Your Payment Refund″ and an attached HTML webpage. We have reported this <a href="http://blog.mxlab.eu/2011/01/27/hm-revenue-customs-phishing-emails/">earlier on on January 27th, 2011</a>, and this campaign is still running in a modified version.</p>
<p>The emails is send from the spoofed email address srvcs@hmrc.gov.uk, and possible other combinations, and has the following body:</p>
<blockquote><p>Dear Applicant:</p>
<p>Following an upgrade of our computer systems and review of our records we have investigated your payments and latest tax returns over the last seven years  our calculations show that you have made over payments of GBP 178.25</p>
<p>Due to the high volume of refunds due you must complete the online application, the telephone help line is unable to assist with this application. In oder to process your refund you will need to complete the application form attached to this email.Your refund may take up to 6 weeks to process please make sure you complete the form correctly.</p>
<p>NOTE: If you&#8217;ve received an Income Tax ‘repayment’ it will either be following a claim you&#8217;ve made or because HM Revenue &amp; Customs (HMRC) has received new information about your taxable income or entitlement to allowances. The refund may come through your tax code or as a payment and could relate to the current tax year or earlier years.</p>
<p>An Income Tax repayment is a refund of tax that you&#8217;ve overpaid. So, if you&#8217;ve paid too much tax for example through your job or pension this year or in previous years HMRC will send you a repayment. You&#8217;ll get the repayment by bank transfer directly to your credit or debit card.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Copyright 2011, HM Revenue Customs UK All rights reserved.</p></blockquote>
<p>Attached to the email is an HTML page with the name Refund_Form.htm. Once opened you will have a webform to submit your personal details together with your credit card details.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_HMRevenueCust.jpg" alt="" width="450" height="378" /></p>
<p>When looking into the HTML source code we can find that the layout and  images are directly taken from the http://www.hmrc.gov.uk/ web site. The  form data itself will be directed  to hxxp://www.hotel-bergara.com/cgi-bin/mailform.cgi. When  submitting data you will be redirected to the HM Revenue &amp; Customs  web site. The forms hidden values shows us that the data is sent to govukgov@yahoo.com.</p>
<p>We also have a second example where the email contains an URL to the phishing web site instead of an embedded attachment in the message.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_HMRevenueCust2.jpg" alt="" width="450" height="387" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1346/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1346/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1346/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1346&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/01/hm-revenue-customs-phishing-emails-continued/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_HMRevenueCust.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_HMRevenueCust2.jpg" medium="image" />
	</item>
	</channel>
</rss>
