<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
	<atom:link href="http://blog.mxlab.eu/tag/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Flickr welcome message leads to Canadian Pharmacy web site</title>
		<link>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/</link>
		<comments>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 16:06:13 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Neighbor Pharmacy]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[Flickr]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=947</guid>
		<description><![CDATA[Various brands have been subject to spam campaigns and today Flickr, the photo sharing web site, is now also being abused by spammers. MX Lab started to intercept messages with the subject &#8220;[Flickr] Welcome!&#8221;, send from a spoofed email address, with an welcome message  from Flickr (see image below). Every link in the message leads [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=947&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Various brands have been subject to spam campaigns and today Flickr, the photo sharing web site, is now also being abused by spammers.</p>
<p>MX Lab started to intercept messages with the subject &#8220;[Flickr] Welcome!&#8221;, send from a spoofed email address, with an welcome message  from Flickr (see image below).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100706_flickr_spam.jpg" alt="" width="450" height="683" /></p>
<p>Every link in the message leads to a different URL, even the links behind Terms of Services or the Privacy Policy.</p>
<p>hxxp://mahimatex.com/sanitation.html<br />
hxxp://electricbrochures.com/custodian.html<br />
hxxp://eventosgs.com.ar/climate.html<br />
hxxp://newcivas.altervista.org/overstatements.html<br />
hxxp://complicat.go.ro/modestly.html<br />
hxxp://kankash-g-s.com/chicagoans.html<br />
hxxp://pliki.open-it.pl/deigned.html<br />
hxxp://turismatica.go.ro/grapefruit.html<br />
hxxp://behsood.ir/schedulable.html<br />
hxxp://jpaquino.com/headlines.html<br />
hxxp://awtchiro.com/consulates.html</p>
<p>The web sites above function as a redirect to hxxp://keptoften.com/</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" alt="" width="450" height="418" /></p>
<p>Each message has different URLs included so these spammers are using a massive amount of domains in this campaign.</p>
<p>I personally do not understand why they are doing this because an Intent Analysis filter, that analyses the included URLs in emails, can blacklist many URLs from these web sites immediatly when investigating one single spam message.</p>
<p>When only using the domain for visiting the sites we get quite often a warning from our browser that the site is known to host malware. In other cases, or when ignoring the warning, we are redirected to hxxp://bestadultsite.ru/run/go.php?sid=3 and afterwards to the web site of Canadian Neighbor Pharmacy hxxp://pharmacymentalhealth.com (see image below).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100706_can_neighb_pharma.jpg" alt="" width="450" height="299" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/947/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/947/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/947/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=947&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/06/flickr-welcome-message-leads-to-canadian-pharmacy-web-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100706_flickr_spam.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100215_canadianpharmacy.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100706_can_neighb_pharma.jpg" medium="image" />
	</item>
		<item>
		<title>Thumbs up for Bit.ly to block shortened URL in &#8220;Coupe du Monde de la FIFA 2010&#8243; spam</title>
		<link>http://blog.mxlab.eu/2010/06/11/thumbs-up-for-bit-ly-to-block-shortened-url-in-coupe-du-monde-de-la-fifa-2010-spam/</link>
		<comments>http://blog.mxlab.eu/2010/06/11/thumbs-up-for-bit-ly-to-block-shortened-url-in-coupe-du-monde-de-la-fifa-2010-spam/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 16:05:18 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[bit.ly]]></category>
		<category><![CDATA[FIFA]]></category>
		<category><![CDATA[FIFA World Cup South Africa]]></category>
		<category><![CDATA[FLVDirect]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=929</guid>
		<description><![CDATA[Emails with regarding FIFA World Cup are going around the world now and persons who have less good intentions are on the lookout to create some mayhem. A recent example is the email &#8220;FIFA World Cup South Africa&#8230; bad news&#8221; but the traditional spam messages are also going around on the internet. MX lab intercepted [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=929&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Emails with regarding FIFA World Cup are going around the world now and persons who have less good intentions are on the lookout to create some mayhem. A recent example is the email &#8220;<a href="http://blog.mxlab.eu/2010/06/11/fifa-world-cup-south-africa-bad-news-emails-leads-reader-to-host-with-malware/" target="_blank">FIFA World Cup South Africa&#8230; bad news</a>&#8221; but the traditional spam messages are also going around on the internet.</p>
<p>MX lab intercepted some emails with the subject &#8220;Coupe du Monde de la FIFA 2010&#8243; from World Cup &lt;207peugeot@menara.ma&gt; that are obviously spam and here is the body of the email:</p>
<blockquote><p>bonjour ,</p>
<p>est ce que vous voulez voir les matchs de la coupe gratuitement ?<br />
si oui n&#8217;hesiter pas a telecharger ce logiciel  :</p>
<p>http://bit.ly/worldcupe</p>
<p>cordialement</p>
<p>=========================================</p></blockquote>
<p>The message is in the French language but translated it offers you an option to get software to watch the soccer matches of the World Cup for free.</p>
<p>When using the bit.ly URL shortened link we arrive on the FLV web site http://www.flvpro.com/movies/?aff=4749_movies.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100611_flv_spam.jpg" alt="" width="450" height="326" /></p>
<p>While this is all great, a free download of such a tool, getting your message in this format out to the world is not the way to do it. I refer to the use of bit.ly for the URL, no unsubscribe options and no clear indication who has sent this message. Very bad marketing if you ask me.</p>
<p>MX Lab reprted this to bit.ly, which is something we usually do not do but we thought why not, and bit.ly responded within 10 mintes with a reply that the shortened URL is blocked for further use. Thumbs up for such a fast response.</p>
<p>Now, this is completely off topic, but notice the counter &#8216;Downloaded 2358755 times&#8217; on the web site http://www.flvpro.com/. This is just a Javascript ticker that increases the counter.</p>
<blockquote>
<pre>&lt;script type="text/javascript"&gt;
var num = 2358754;
function IncCounter() {
num = num + 1;   // increment counter by 2
document.getElementById("cntr").innerHTML = num.toLocaleString();
t = setTimeout('IncCounter()', 2000);
// change 1000 to 60000 to update once per minute
}
&lt;/script&gt;</pre>
</blockquote>
<p>When you refresh the page, the counter is back to 2358755.<br />
Very nice marketing! <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/929/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/929/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/929/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=929&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/11/thumbs-up-for-bit-ly-to-block-shortened-url-in-coupe-du-monde-de-la-fifa-2010-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100611_flv_spam.jpg" medium="image" />
	</item>
		<item>
		<title>Web site creator hosts are being abused in spam campaigns</title>
		<link>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/</link>
		<comments>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 11:30:46 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=773</guid>
		<description><![CDATA[Spammers are not afraid to abuse community sites or blog creators like blogspot.com in their spam campaigns. In some cases, the content is published on these site or a redirect is embedded and forwards the visitor to the web site of their choice offering porn, pills and other stuff. MX Lab noticed an increase the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=773&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers are not afraid to abuse community sites or blog creators like blogspot.com in their spam campaigns. In some cases, the content is published on these site or a redirect is embedded and forwards the visitor to the web site of their choice offering porn, pills and other stuff.</p>
<p>MX Lab noticed an increase the last few days of URLs in spam messages that point to (free) web site creater hosts or less well know blog creators. Some of the latest victims are doodlekit.com, sitekreator.com, webs.com, webstarts.com and blogdrive.com.</p>
<p>Some examples of the spam:</p>
<blockquote><p>of necromancer beyond power drill ostensibly wily<br />
dissidents customer<br />
PornstarMikaTanAnalFingering hxxp://trhombic.blogdrive.com<br />
because girls</p></blockquote>
<blockquote><p>dissidents blotched greedily</p>
<p>mirror about starlet likeable<br />
WorldOfLustyAmatteurGalsFujckkingOnCameraWithBigCodfckedLadsAndBelovedSelxToys hxxp://sitekreator.com/Dewtty/sdfgty.html</p>
<p>haunchestoward</p></blockquote>
<blockquote><p>for cleavage inside carelessly womanly<br />
bubble baths scythe<br />
AsianSuckingAndFuckingHardcore hxxp://wilfredorz.webs.com<br />
or tea parties</p></blockquote>
<blockquote><p>over and accidentally</p>
<p>tea parties flabby<br />
WorldOfLustyAmatenurGalsFujckkingOnCameraWithBigCobckedLadsAndBelovedSjexToys hxxp://s2.webstarts.com/ssey/q2.html</p>
<p>philosopherssecretly</p></blockquote>
<p>What we also notice is the use of random words in the spam message again. This is a very common technique being used in the past to avoid detected by Bayesian filters and/or to compromise and corrupt the knowledge database of the Bayesian filter when the message is used to train the filter.</p>
<p>This technique is also present in the latest spam campaign of the Canadian Pharmacy:</p>
<blockquote><p>This is a link to our shop http://bc.greatsilent.ru/</p>
<p>gazoive dyojefip eicyla uxamo kajoubemi zitykiboto yejy<br />
irewyumuco izaafoe samin uypoi nyqii asydado<br />
hoxyaogeqa eokinap asiwy yziuboaxoj alomem kawuqyxy<br />
ajitikumoa fiaxe oqoce qiahow yvenouwa bosyebuje ucotaley<br />
yeqa uhybyo nidodyziru logu noboma uuju uedywaby<br />
&#8230;. (cut)&#8230;.</p></blockquote>
<p>New web site creator hosts are being used each day. When I visited a few of those web site creator host I found out that subscription is so easy to do. You can automate account requests quite easily up to a certain point without being blocked by some way of security measure or by clicking on an activation link by email.</p>
<p>On doodlekit.com we found a CAPTCHA security on the subscription web form but I believe that a good CAPTCHA should have letters that are less readable than this one. But, this is a start.</p>
<p>On webs.com I did set up a dummy web site account with the site address http://tryviagra.webs.com without any security measure! This means that anyone can set up an free web site creator account when completing the webforms.</p>
<p>In this particular case, I can even automate every step and let a bot do all the work for you. I could create from 10 to 100 accounts on a day and perhaps the site administrators wouldn&#8217;t even notice this. It is a very efficient way of getting coverage on the internet, getting free hosting for my site or redirect visitors to my site.</p>
<p>To make it worse, I can also place malware on this site and try to infect each visitor on my site with malware, ransomware or other malicious files.</p>
<p>As a spammer, I have the advantage over Intent Anyalisis tools or SURBL, tools that examine and block messages based on the included URLs, by generating mutliple URLs each day and changing URLs in the spam message.</p>
<p>Again, it shows that internet security is a responsability of everyone and everyone should get involved. If we want to stop spammers, we also have to make sure that some of the features that spammers have today &#8211; this is a nice example I think &#8211; can&#8217;t be used tomorrow.</p>
<p>Feel free to comment on this post.</p>
<p>Disclaimer: it is not our intention to attack webs.com on their lack of security &#8211; perhaps in a certain way it is &#8211; but to point out how easy it is to abuse certain online tools.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/773/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/773/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/773/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=773&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/06/web-site-creator-hosts-are-being-abused-in-spam-campaigns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Twitter accounts abused by spammers</title>
		<link>http://blog.mxlab.eu/2009/11/18/twitter-accounts-abused-by-spammers/</link>
		<comments>http://blog.mxlab.eu/2009/11/18/twitter-accounts-abused-by-spammers/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 11:27:18 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[online pharmacy]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Twitter spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=687</guid>
		<description><![CDATA[MX Lab detected a spam campaign where Twitter is being abused by spammers to promote online drug stores. The campaign is sent from random spoofed email addresses and has similar subjects like: 7U1 An amazing selection of brand name medications, all for incredibly low prices! 2F9 Looking for Hytrin? 7N8 6W3 Looking for Abilify? 5Z2 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=687&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a spam campaign where Twitter is being abused by spammers to promote online drug stores.</p>
<p>The campaign is sent from random spoofed email addresses and has similar subjects like:</p>
<blockquote><p>7U1 An amazing selection of brand name medications, all for incredibly low prices!<br />
2F9 Looking for Hytrin? 7N8<br />
6W3 Looking for Abilify?<br />
5Z2 Looking for Fosamax?<br />
4G5 Do you suffer from male impotence? Order Viagra online today 8I7<br />
5Y5 Do you have a urinary blockage?</p></blockquote>
<p>Some samples of the body:</p>
<blockquote><p>hxxp://twitter.com/oscaresquire/status/5804523982</p>
<p>All Medications are Always 100% Safe  Legal<br />
Our store is Verified, Trusted  Licensed<br />
Guaranteed LowPrices &#8211; up to 85% Off</p>
<p>! G6Y3</p>
<p>* P h 3nt_ er mI.ne 37.5<br />
* S0 .m@<br />
* X@ /\/ a .X<br />
* R1 .T@ L in<br />
* C 0 d1n3<br />
* V /\ L 1Um<br />
* KL 0 N_0.p in<br />
* AMB1en<br />
* Ci..@ _Lis<br />
* V| @ g.R @</p>
<p>www.twitter.com/dweepadvani/status/5790731913<br />
This message was sent to 96190</p></blockquote>
<p>And another one</p>
<blockquote><p>site that pharmacies and big companies don&#8217;t want you to know about!<br />
Vicodin ES Online, Hyrdrocodone, Lortab&#8230;</p>
<p>hxxp://twitter.com/itaiba/status/5803131461</p></blockquote>
<p>They all have the URL in common that points to a Twitter account. The format is  http://twitter.com/***/status/*** where *** stands for random characters.</p>
<p>Some examples of such an Twitter account that directs you to the online pharmacy.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091118_twitter_spam.jpg" alt="" width="450" height="254" /></p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091118_twitter_spam3.jpg" alt="" width="450" height="261" /></p>
<p>The med4udirect.com shop looks like this:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091118_twitter_spam2.jpg" alt="" width="450" height="361" /></p>
<p>The domain appears to registered in China.</p>
<pre> DomainName : MEDS4UDIRECT.COM

RSP: China Springboard Inc.
URL: http://www.namerich.cn      

Name Server :NS3.BERTOSNS.COM
Name Server :NS5.LOVELYSNB34.COM
Name Server :NS1.HDNSSTUFF.COM
Name Server :NS6.LOVELYSNB34.COM
Name Server :NS2.HDNSSTUFF.COM
Name Server :NS4.BERTOSNS.COM
Status :clientTransferProhibited
Status :clientDeleteProhibited
Creation  Date :2009-09-26
Expiration Date :2010-09-26
Last Update  Date :2009-11-11

Registrant ID :V-X-63521-21717
Registrant Name :LU TAO
Registrant Organization :LU TAO
Registrant Address :JIEFANGLU251
Registrant City :ShangHai
Registrant Province/State :ShangHai
Registrant Country Code :CN
Registrant Postal Code :200126
Registrant Phone Number :+86.0217415426
Registrant Fax :+86.0217415426
Registrant Email :djsnhe@163.com

Administrative ID :V-X-63521-21717
Administrative Name :LU TAO
Administrative Organization :LU TAO
Administrative Address :JIEFANGLU251
Administrative City :ShangHai
Administrative Province/State :ShangHai
Administrative Country Code :CN
Administrative Postal Code :200126
Administrative Phone Number :+86.0217415426
Administrative Fax :+86.0217415426
Administrative Email :djsnhe@163.com

Billing ID :V-X-63521-21717
Billing Name :LU TAO
Billing Organization :LU TAO
Billing Address :JIEFANGLU251
Billing City :ShangHai
Billing Province/State :ShangHai
Billing Country Code :CN
Billing Postal Code :200126
Billing Phone Number :+86.0217415426
Billing Fax :+86.0217415426
Billing Email :djsnhe@163.com

Technical ID :V-X-63521-21717
Technical Name :LU TAO
Technical Organization :LU TAO
Technical Address :JIEFANGLU251
Technical City :ShangHai
Technical Province/State :ShangHai
Technical Country Code :CN
Technical Postal Code :200126
Technical Phone Number :+86.0217415426
Technical Fax :+86.0217415426
Technical Email :djsnhe@163.com
</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/687/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/687/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/687/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=687&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/11/18/twitter-accounts-abused-by-spammers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091118_twitter_spam.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20091118_twitter_spam3.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20091118_twitter_spam2.jpg" medium="image" />
	</item>
		<item>
		<title>Can a spammer be creative?</title>
		<link>http://blog.mxlab.eu/2009/10/05/can-a-spammer-be-creative/</link>
		<comments>http://blog.mxlab.eu/2009/10/05/can-a-spammer-be-creative/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 19:31:48 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=555</guid>
		<description><![CDATA[Yes, that is the answer we have today. MX Lab detected a nice piece of spam and we didn&#8217;t wanted to hold this one back for you. It&#8217;s not image based, no ASCII art but the text is constructed and formatted by the character &#8220;#&#8221;. It didn&#8217;t render well in Entourage on Mac so it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=555&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Yes, that is the answer we have today. MX Lab detected a nice piece of spam and we didn&#8217;t wanted to hold this one back for you.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091005_spam_art.jpg" alt="" width="450" height="195" /></p>
<p>It&#8217;s not image based, no ASCII art but the text is constructed and formatted by the character &#8220;#&#8221;. It didn&#8217;t render well in Entourage on Mac so it needs a little work. <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/555/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/555/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/555/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=555&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/10/05/can-a-spammer-be-creative/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091005_spam_art.jpg" medium="image" />
	</item>
		<item>
		<title>Death of Michael Jackson inspires spammers and malware distributors</title>
		<link>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/</link>
		<comments>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/#comments</comments>
		<pubDate>Sat, 27 Jun 2009 20:48:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Michael Jackson]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=492</guid>
		<description><![CDATA[Spammers and malware distributors are trying to take advantage of the death of Michael Jackson by sending out email campaigns with subject and/or body related to Michael Jackson while malware distributors try to infect computers by offering a URL to a site that offers a video of the death of the &#8220;King of pop&#8221;. Here [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=492&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers and malware distributors are trying to take advantage of the death of Michael Jackson by sending out email campaigns with subject and/or body related to Michael Jackson while malware distributors try to infect computers by offering a URL to a site that offers a video of the death of the &#8220;King of pop&#8221;. Here is a brief overview.</p>
<p><strong>Canadian Pharmacy spam</strong></p>
<p>One of the campaigns contains the subject &#8220;Michael Jackson dead? NO!!!&#8221; and the body content:</p>
<blockquote><p>Michael Jackson dead? NO!!!<br />
Open attached file and read!!!</p></blockquote>
<p>The attachment itself appears to be harmless and contains the HTML refresh tag</p>
<blockquote><p>&lt;meta http-equiv=&#8217;Refresh&#8217; content=&#8217;0; url=hxxp://addfamous.com/&#8217; /&gt;</p></blockquote>
<p>This will redirect your browser to the Canadian Pharmacy web site.</p>
<p><strong>Email harvesting</strong></p>
<p>Another campaign has the intention to harvest email addresses and is coming from a bogus email account but the reply to is a ***@live.com account. The email claims to have special and confidential information regarding the death of Michael Jackson. A sample of the content:</p>
<blockquote><p>Confidential<br />
Vital informations after the death of Michael Jackson’s I really need some one trusted &amp; secretive to speak with with informations i have in my possession before its too late Kindly reply me and i will immediately respond back,Its for just secret between both of us</p></blockquote>
<p>The call-to-action is to reply to this message. When doing so you will confirm the spammer that the email has been received and read and therefore is active.</p>
<p><strong>Malicious spam</strong></p>
<p>This spam email offers a link to a YouTube video but actually sends the recipient to a Trojan Downloader hosted on a compromised web site. The file is Michael.Jackson.videos.scr. When downloaded and executed 3 information-stealing components are downloaded and installed by the malware. One of the files has the name michael.gif and has a very low <a href="http://www.virustotal.com/analisis/67cba7b9d91e1cbcac0f22b5f4bcf12f4b07a1a62d7d3018e28ccd5ee93e0ce4-1246012313" target="_blank">AV detection rate</a>.</p>
<p>The malware then installs a malicious BHO that is registered with this file %windir%\Dynamic.dll. Another component is bound to startup at %windir%\system32\kproces.exe. Another malicious file installed by the malware is %windir%\system32\fotos.exe.</p>
<p>Upon executing the file, a legitimate Web site at http://musica.uol.com.br/ultnot/2009/06/25/michael-jackson.jhtm is opened by the default browser in order to distract the user by presenting a news article for them to read.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/d602b5cbc6386e9ba4b7d910ff0eb04fefba5ce06ef6f703e37f76ab88ad2ff9-1246130240" target="_blank">permlink</a> and MD5: 664cb28ef710e35dc5b7539eb633abca.</p>
<p><strong>Student Loans</strong></p>
<p>A spam with the subject and the body content &#8220;Micheal Jackson History&#8221;, notice the wrong spelling of his firstname, leads to hxxp://loansofworld.blogspot.com/. This message was sent through Google Groups.</p>
<p><strong>Contact databases</strong></p>
<p>An email with the subject &#8220;Michael Jackson: last farewell from DataForYou&#8221; is attracting readers with a subject related to Michael Jackson but instead offers contact databases.</p>
<p>Notice the TinyURL inside the email content to hide a direct link to the web site. TinyURL has already removed the URL but  this example shows that you need to be carefull with URLs in emails where a service like TinyURL is shortening the full URL. Try to use a preview feature first when you don&#8217;t trust the source is our recommendation.</p>
<blockquote><p>Dear Sirs,<br />
in our site you have access, through the cheapest prices you have ever seen,<br />
to a vast database of international Companies,  divided by region, province, city or area of activity.</p>
<p>The databases are divided into two broad categories.</p>
<p>Archives of International Companies with E-mai only</p>
<p>The archives are divided by country and include a list of e-mail only.<br />
The archives are in TXT format and they are easy to be used  because<br />
this format is the  typical one used for data import. You can also find<br />
more than one email, relferring to different people working in the same<br />
structure, for the Companies which have provided them.</p>
<p>International Archives of active domains with MX record only</p>
<p>The archives are divided by size and include a list of  domains only.<br />
The archives are in TXT format and they are easy to use because this<br />
format is the typical one used for data iimport. All the domains have<br />
an active MX record; this means that each domain is directly linked<br />
with working  email accounts.</p>
<p>Visit our site at<br />
hxxp://tinyurl.com/infinitemail</p>
<p>Don&#8217;t lose this incredible opportunity for increment your business.</p>
<p>InfiniteMail</p>
<p>Customer Care</p>
<p>If you no longer want to receive our email reply here:<br />
mailto:remove@mediasch0pping.com</p></blockquote>
<p><strong>National Survey Panel&#8217;s Gift Program</strong></p>
<blockquote><p>What killed Michael Jackson?</p>
<p>Press here:<br />
hxxp://totjebiok.com/tr.php?72928+*****@*****.com</p>
<p>Tell us. Then complete the program requirements for a FREE 7 album collection of MJ&#8217;s solo career.</p></blockquote>
<p>These guys are using the death of Michael Jackson to attract some people to fill in some information and in return you can receive his albums for free.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090627_MJackson_1.jpg" alt="" width="450" height="293" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/492/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=492&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090627_MJackson_1.jpg" medium="image" />
	</item>
		<item>
		<title>Health.com branding used in spam</title>
		<link>http://blog.mxlab.eu/2009/05/19/health-com-branding-used-in-spam/</link>
		<comments>http://blog.mxlab.eu/2009/05/19/health-com-branding-used-in-spam/#comments</comments>
		<pubDate>Tue, 19 May 2009 01:00:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Health.com]]></category>
		<category><![CDATA[branding]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=458</guid>
		<description><![CDATA[A few days earlier we reported that the branding of Auslogics Software was being used in a spam campaign. We now noticed that Health.com has been subject of such abuse. MX Lab intercepted spam messages with a Health.com branding. The image below shows us a mailing template with the Health logo, an image for viagra [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=458&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A few days earlier we reported that the branding of <a href="http://blog.mxlab.eu/2009/05/14/auslogics-software-logo-used-in-spam/">Auslogics Software was being used in a spam campaign</a>. We now noticed that Health.com has been subject of such abuse.</p>
<p>MX Lab intercepted spam messages with a Health.com branding. The image below shows us a mailing template with the Health logo, an image for viagra and other pills, along withlinks to Twitter, Facebook and YouTube, opt-out links, privacy policy and the address of Health.com.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090519_spam_health_com.jpg" alt="" width="450" height="637" /></p>
<p>Spammer have replaced each of the links with hxxp://www.blackaringo.ru in this campaign that redirects to hxxp://newpharmshappy.com/. This site is from our best friends, who else, the Canadian Pharmacy.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/458/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=458&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/19/health-com-branding-used-in-spam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090519_spam_health_com.jpg" medium="image" />
	</item>
		<item>
		<title>Belgian court condemns 18 persons regarding Nigerean spam</title>
		<link>http://blog.mxlab.eu/2009/05/18/belgian-court-condemns-18-persons-regarding-nigerean-spam/</link>
		<comments>http://blog.mxlab.eu/2009/05/18/belgian-court-condemns-18-persons-regarding-nigerean-spam/#comments</comments>
		<pubDate>Mon, 18 May 2009 21:46:15 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[nigerean spam]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=455</guid>
		<description><![CDATA[The correctional court of Brugges, Belgium, condems 18 persons with prison sentences from 2 to 6 years for sending out fraudulent spam between Februay 2007 and November 2008. In the Nigerian spam emails they claimed to have a fund in Ghana where a substantional amount of money was blocked after a woman died in a car accident. The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=455&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>The correctional court of Brugges, Belgium, condems 18 persons with prison sentences from 2 to 6 years for sending out fraudulent spam between Februay 2007 and November 2008.</p>
<p>In the Nigerian spam emails they claimed to have a fund in Ghana where a substantional amount of money was blocked after a woman died in a car accident. The small fortune of 35 million Euro could be released with the help and a contribution of the addressee.</p>
<p>The police could arrest the gang after a tip and a thorough investigation of mobile phone conversations.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/455/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=455&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/18/belgian-court-condemns-18-persons-regarding-nigerean-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Auslogics Software logo used in spam</title>
		<link>http://blog.mxlab.eu/2009/05/14/auslogics-software-logo-used-in-spam/</link>
		<comments>http://blog.mxlab.eu/2009/05/14/auslogics-software-logo-used-in-spam/#comments</comments>
		<pubDate>Thu, 14 May 2009 19:13:28 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Auslogics Software]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=450</guid>
		<description><![CDATA[When spammers send their messages they try to hide their tracks by spoofing the From address in each message. Sometimes using valid domains or even real email addresses. In some cases they also try to gain credibility by using a brand, a logo or any other style of a real company. In this case, the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=450&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>When spammers send their messages they try to hide their tracks by spoofing the From address in each message. Sometimes using valid domains or even real email addresses. In some cases they also try to gain credibility by using a brand, a logo or any other style of a real company.</p>
<p>In this case, the victim is the company Auslogics Software (http://www.auslogics.com/).</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090514_auslogics_software.jpg" alt="" width="450" height="783" /></p>
<p>When looking at the spam it seems that they offer a whole branch of software products. But in fact this company offers software to speed up your computer, recovery and disc-and registry defrag tools.</p>
<p>The Auslogics logo is embedded with a complete URL directing to the Auslogics Software web site. The other images are taken from the Amazon web site.</p>
<p>Unfourtunatly, or luckely &#8211; depends how you look at it, the spammers didn&#8217;t complete their homework very well. A small mistake happened and the provided links contain http://{oemurl}/. It seems that the spammers have forgotten to include a real URL or that a content merge failed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/450/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/450/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/450/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=450&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/14/auslogics-software-logo-used-in-spam/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090514_auslogics_software.jpg" medium="image" />
	</item>
		<item>
		<title>The latest spam campaigns on the net</title>
		<link>http://blog.mxlab.eu/2009/01/19/the-latest-spam-campaigns-on-the-net/</link>
		<comments>http://blog.mxlab.eu/2009/01/19/the-latest-spam-campaigns-on-the-net/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 23:11:42 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[CBS News spam]]></category>
		<category><![CDATA[Google Groups spam]]></category>
		<category><![CDATA[Pizza Hut spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.be/?p=331</guid>
		<description><![CDATA[Spam regarding meds and pills are still taking a serious part of all the spam messages worldwide. The latest spam messages are some fine examples. Google Groups spam The following spam message is using Google Groups again to get the visitor attracted. Hi! Feel Better Now!! hxxp://groups.google.com/xxxxx/robertomrlg860/web/mariana We&#8217;re always here for you! the past is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=331&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spam regarding meds and pills are still taking a serious part of all the spam messages worldwide. The latest spam messages are some fine examples.</p>
<p><strong>Google Groups spam</strong></p>
<p>The following spam message is using Google Groups again to get the visitor attracted.</p>
<blockquote><p>Hi!</p>
<p>Feel Better Now!!</p>
<p>hxxp://groups.google.com/xxxxx/robertomrlg860/web/mariana</p>
<p>We&#8217;re always here for you!<br />
the past is immutable: forget it, sheep dismantler</p></blockquote>
<p>This is the Google Groups page:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090119_spam_01.jpg" alt="" width="340" height="233" /></p>
<p>Following the URL to the Google Groups brings us to a site called Pharmacy Express under the domain hxxp://esmnyx.sg/.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090119_spam_02.jpg" alt="" width="340" height="358" /></p>
<p><strong>CBS News spam</strong></p>
<p>Another example included a “News Summary” in the header. That image is actually hosted on the CBS News site.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090119_spam_03.jpg" alt="" width="340" height="314" /></p>
<p>What is remarkable with this spam is that when you look in the message source you&#8217;ll find up to 5 different URLs in use, below the Help, Advertise, Terms of Service and other links, that redirect all to the same Canadia Pharmacy web site.</p>
<p><strong>Pizza Hut</strong></p>
<p>Another &#8220;victim&#8221; in the spam campaigns is Pizza Hut. The “Order Now” button and the “Click for more deals” tab are both images hosted on the Pizza Hut site.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090119_spam_04.jpg" alt="" width="340" height="323" /></p>
<p>The message source even contains an URL from Pizza Hut going to their special landing page: hxxp://getmore.emailpizzahut.com/****. The URLs also lead to the Canadian Pharmacy.</p>
<p><strong>Power Gain spam</strong></p>
<p>Besides viagra and other pills, techniques and products to increase your manhood are also very popular. This example shows you the latest one.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090119_spam_05.jpg" alt="" width="340" height="263" /></p>
<p>Do notice that with these campaigns the spam messages contain some footers with unsubscribe links, click your email preferences and so on. With these techniques spammers try to make their messages appear as a valid mailing trying to mislead the readers.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/331/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/331/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/331/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=331&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/01/19/the-latest-spam-campaigns-on-the-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090119_spam_01.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20090119_spam_02.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20090119_spam_03.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20090119_spam_04.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20090119_spam_05.jpg" medium="image" />
	</item>
	</channel>
</rss>