<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
	<atom:link href="http://blog.mxlab.eu/tag/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Sat, 04 Feb 2012 17:44:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Spam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Spam in fake LinkedIn messages</title>
		<link>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/</link>
		<comments>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 16:30:24 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Canadian Family Pharmacy]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1583</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, has noticed a large spam campaign on behalf of the Canadian Family Pharmacy in fake LinkedIn messages. The messages come the spoofed email address &#60;member@linkedin.com&#62; with the authors like: Fenella Macdonald via LinkedIn &#60;member@linkedin.com&#62; Catriona Bailey via LinkedIn &#60;member@linkedin.com&#62; Susan Jones via LinkedIn &#60;member@linkedin.com&#62; .... Subjects in use: Can i place your [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1583&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, has noticed a large spam campaign on behalf of the Canadian Family Pharmacy in fake LinkedIn messages.</p>
<p>The messages come the spoofed email address &lt;member@linkedin.com&gt; with the authors like:</p>
<pre>Fenella  Macdonald via LinkedIn &lt;member@linkedin.com&gt;
Catriona  Bailey via LinkedIn &lt;member@linkedin.com&gt;
Susan  Jones via LinkedIn &lt;member@linkedin.com&gt;
....</pre>
<p>Subjects in use:</p>
<p>Can i place your photo on my site?<br />
Can i place your photo on our facebook page?<br />
Can i place your information on our web page?<br />
Can i place your video on our web site?<br />
Can i place your video on my facebook page?<br />
Can i place your contacts on our twitter page?<br />
&#8230;..</p>
<p>Example of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin.jpg" alt="" width="450" height="263" /></p>
<p>The URL in the message point to different web hosts and pages with an redirect HTML:</p>
<p>&lt;html&gt;&lt;head&gt;&lt;title&gt;Buy Viagra Online &#8211; Online Pharmacy&lt;/title&gt;&lt;style type=&#8221;text/css&#8221;&gt; a { font-size: 24pt; } &lt;/style&gt;&lt;script type=&#8221;text/javascript&#8221;&gt;var a = &#8220;hxxp://viagralevitratestosterone.com&#8221;;window.location = a;&lt;/script&gt;&lt;/head&gt;&lt;body&gt;&lt;center&gt;&lt;h1&gt;#1 Online Pharmacy&lt;/h1&gt;&lt;br&gt;Online DrugStore&lt;br&gt;&lt;a href=&#8221;hxxp://viagralevitratestosterone.com&#8221;&gt;Buy Viagra Online&lt;/a&gt;&lt;/center&gt;&lt;/body&gt;&lt;/html&gt;</p>
<p>In return, the redirect points to hxxp://viagralevitratestosterone.com.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin_2.jpg" alt="" width="450" height="352" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1583/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1583/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1583/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1583&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2012/01/19/spam-in-fake-linkedin-messages/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2012/20120119_spam_linkedin_2.jpg" medium="image" />
	</item>
		<item>
		<title>Increase your security with the MX Lab services at a special promotion price!</title>
		<link>http://blog.mxlab.eu/2011/11/03/increase-your-security-with-the-mx-lab-services-at-a-special-promotion-price/</link>
		<comments>http://blog.mxlab.eu/2011/11/03/increase-your-security-with-the-mx-lab-services-at-a-special-promotion-price/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 23:33:57 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[anti spam]]></category>
		<category><![CDATA[MX Lab]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zero hour antivirus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1499</guid>
		<description><![CDATA[Increase your security with the MX Lab services at a special promotion price until 31 December 2011! MX Lab offers it&#8217;s zero hour anti virus, managed anti spam and email archiving services at a lower price of € 7 per user per year*, a huge € 2 per user discount, and the great news is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1499&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Increase your security with the MX Lab services at a special promotion price until 31 December 2011!</strong></p>
<p><a href="http://www.mxlab.eu" target="_blank">MX Lab</a> offers it&#8217;s zero hour anti virus, managed anti spam and email archiving services at a lower <strong>price of € 7 per user per year*</strong>, a huge € 2 per user discount, and the great news is that you only need to <a href="http://www.mxlab.eu/en/contactus/trial_audit.html" target="_blank">request a 15 day trial</a> and change your MX records to make use of our service.</p>
<p>Our special promotion price also affects our other services like Email Archiving or the Hosted solutions. Visit our web site for a <a href="http://www.mxlab.eu/en/pricing/index.html" target="_blank">full pricing overview</a>.</p>
<p><a href="http://www.mxlab.eu/en/contactus/trial_audit.html" target="_blank">Request your 15 day trial today!</a></p>
<p>Are you active as an IT solutions provider and want to offer the MX Lab services to your clients? Do not hesitate to contact us and join the <a href="http://www.mxlab.eu/en/partners/partner_program.html" target="_blank">MX Lab Partner Program</a> and benefit for the special pricing as well!</p>
<p>* MX Lab offers its services at a special promotion price until 31 December 2011. In order to obtain the promotion you will need to request a 15 day trial and use the trial account by modifying your MX records in order to use the MX Lab service. Each trial that is converted in a subscription at the end of the trial will benefit of the special lower price for one year.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1499/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1499/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1499/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1499&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/11/03/increase-your-security-with-the-mx-lab-services-at-a-special-promotion-price/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Emails &#8220;Sent via Google Maps&#8221; is a redirect to the Canadian Pharmacy</title>
		<link>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/</link>
		<comments>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 09:27:32 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1447</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercepted some spam messages with subjects like: Sent via Google Maps: Brett Lepper sent you: A Maps link Sent via Google Maps: Brenna Eber sent you: A Maps link Sent via Google Maps: Theodora Cavitt sent you: A Maps link &#8230; The subjects start with &#8216;Sent via Google Maps:&#8217; and end with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1447&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercepted some spam messages with subjects like:</p>
<p>Sent via Google Maps: Brett Lepper sent you: A Maps link<br />
Sent via Google Maps: Brenna Eber sent you: A Maps link<br />
Sent via Google Maps: Theodora Cavitt sent you: A Maps link<br />
&#8230;</p>
<p>The subjects start with &#8216;Sent via Google Maps:&#8217; and end with &#8216;A Maps link&#8217;.<br />
The from email address is spoofed but starts with &#8216;admin@&#8217; combined with a subdomain address.</p>
<p>Message body examples:</p>
<blockquote>
<div>
<div lang="x-western">
<div>This email was sent to you by a user on Google Maps:</div>
<div>Hi</div>
<hr noshade="noshade" size="1" />
<div>hxxp://gertie8kthv.blogginc.asia/10/8/gertie-bawa.html</div>
</div>
</div>
</blockquote>
<div lang="x-western">
<blockquote>
<div>This email was sent to you by a user on Google Maps:</div>
<div>Hi</div>
<hr noshade="noshade" size="1" />
<div>hxxp://elmira4221c.blogsun.asia/11/10/elmira-antoniuk.html</div>
</blockquote>
</div>
<p>The URLs in the message will redirect the user to the website of the Canadian Pharmacy at hxxp://www.bestrxs.com/.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1447/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1447/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1447/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1447&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/09/26/emails-sent-via-google-maps-is-a-redirect-to-the-canadian-pharmacy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Receive a bonus of 2000 € &#8211; not everything is what it looks like</title>
		<link>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/</link>
		<comments>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 16:17:41 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[SMS scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1364</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercept a large spam campaign what in fact appears to be an SMS scam system. Email messages are sent from no-reply-xxx@finance-magazine.eu, where the XXX stands for random numbers. The domain finance-magazine.eu is from the The European CFO Magazine. Many different subjects in the French language are being used to get some attraction: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1364&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercept a large spam campaign what in fact appears to be an SMS scam system.</p>
<p>Email messages are sent from no-reply-xxx@finance-magazine.eu, where the XXX stands for random numbers. The domain finance-magazine.eu is from the The European CFO Magazine.</p>
<p>Many different subjects in the French language are being used to get some attraction:</p>
<p>Une offre qou vous ne pouvez pas refuser<br />
Une opportunite unique d&#8217;une vie<br />
Faire de l&#8217;argent n&#8217;a jamais ete aussi facile!<br />
Etes-vous interesse ?<br />
&#8230;</p>
<p>This is the email content:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_1.jpg" alt="" width="450" height="223" /></p>
<p>The embedded URLs directs visitors to hxxp://berborso.com/c/8D1DB23B.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_2.jpg" alt="" width="450" height="362" /></p>
<p>On this landing page you will need to fill in your details including your mobile phone number.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_3.jpg" alt="" width="450" height="468" /></p>
<p>When your details are submitted, you&#8217;ll receive an SMS with an activation code. This code needs to be filled in again on this webform together with some additional details.</p>
<p>I haven&#8217;t filled in my real phone number but I&#8217;m pretty sure that this is a complete SMS scam. I wouldn&#8217;t be suprised if you receive more SMS messages later on that are credited on your phone bill later on.</p>
<p>This domain name is registered in the Ukraine:</p>
<pre>Service Provided By: Center of Ukrainian Internet Names
Website: http://www.ukrnames.com
Contact: +380.577626123

Domain Name: BERBORSO.COM

Creation Date: 28-Mar-2011
Modification Date: 28-Mar-2011
Expiration Date: 28-Mar-2012

Domain servers in listed order:
ns1.hahray.in
ns2.hahray.in

Registrant:
Son Svan hdgi-domains@gmail.com
WATER STREET 45/54
CHRIST CHURCH, BB17056
BARBADOS
+1.24615566596</pre>
<p>Be carefull if you receive offers like this.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1364/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1364&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_3.jpg" medium="image" />
	</item>
		<item>
		<title>Canadian Pharmacy pops up in emails from Facebook with subject &#8220;Welcome to Facebook Goods&#8221;</title>
		<link>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/</link>
		<comments>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 10:06:47 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>
		<category><![CDATA[facebook spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1355</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new spam campaign, since yesterday, by email with the subject &#8220;Welcome to Facebook Goods&#8221;. These messages are sent from the spoofed email addresses in the format that Facebook is using on the domain facebookmail.com. Some examples: update+bscts2qxhedj@facebookmail.com update+6i8mlfxn1svw@facebookmail.com update+6i8mlfxn1svw@facebookmail.com &#8230; This is the body of the email: Notice [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1355&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu/" target="_blank">http://www.mxlab.eu</a>, started to intercept a new spam campaign, since yesterday, by email with the subject &#8220;Welcome to Facebook Goods&#8221;. These messages are sent from the spoofed email addresses in the format that Facebook is using on the domain facebookmail.com. Some examples:</p>
<p>update+bscts2qxhedj@facebookmail.com<br />
update+6i8mlfxn1svw@facebookmail.com<br />
update+6i8mlfxn1svw@facebookmail.com<br />
&#8230;</p>
<p>This is the body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_Facebook_CanPharm.jpg" alt="" width="450" height="363" /></p>
<p>Notice that the Facebook looks are used to disguise the real purpose of the message.</p>
<p>4 different URLs are used in each message with the format: http://www.domainhere.tld/s/h/o/p/ that will redirect you to the Canadian Pharmacy at hxxp://midiclxic.ru/.</p>
<p>&nbsp;</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1355/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1355/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1355/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1355&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/03/canadian-pharmacy-pops-up-in-emails-from-facebook-with-subject-welcome-to-facebook-goods/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_Facebook_CanPharm.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Spam from Canadian pharmacy masked as &#8220;Delivery Notification&#8221;</title>
		<link>http://blog.mxlab.eu/2011/03/23/spam-from-canadian-pharmacy-masked-as-delivery-notification/</link>
		<comments>http://blog.mxlab.eu/2011/03/23/spam-from-canadian-pharmacy-masked-as-delivery-notification/#comments</comments>
		<pubDate>Wed, 23 Mar 2011 18:49:05 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[canadian pharmacy]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1299</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new spam campaign by email with the subject &#8221;Delivery Notification&#8221;. What appears at first as a simple email notification is in fact a spam campaign for the Canadian Pharmacy. The message is sent from a spoofed email addresses like: Notification-15955 &#60;lwnfc@vowyg2kynvx4.veridomlegal.net&#62; Notification-07997 &#60;cwujg@fgoorlgaxle7.veridomlegal.net&#62; &#8230; The body of the email [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1299&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new spam campaign by email with the subject &#8221;Delivery Notification&#8221;. What appears at first as a simple email notification is in fact a spam campaign for the Canadian Pharmacy.</p>
<p>The message is sent from a spoofed email addresses like:</p>
<blockquote><p>Notification-15955 &lt;lwnfc@vowyg2kynvx4.veridomlegal.net&gt;<br />
Notification-07997 &lt;cwujg@fgoorlgaxle7.veridomlegal.net&gt;<br />
&#8230;</p></blockquote>
<p>The body of the email only contains a link to a web site:</p>
<blockquote><p>http://www-48023.outdomnovolume.net</p>
<p>http://www-35051.outdomnovolume.net</p>
<p>&#8230;.</p></blockquote>
<p>The 5 numbers inside the web site address change with every email but always shows the web site of the Canadian Pharmacy:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" alt="" width="450" height="346" /></p>
<p>The domain outdomnovolume.net is registered a few days ago according to a WHOIS is with the following details:</p>
<pre>Domain name: outdomnovolume.net

Registrant Contact:
   Xicheng
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

Administrative Contact:
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

Technical Contact:
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

Billing Contact:
   Zhongguancun Si Zhongguancun@yahoo.com
   01066569226 fax: 01066569226
   Huixindongjie
   Beijing Chaoyang 101400
   cn

DNS:
ns1.dnsfopiq.com
ns2.dnstow.ru

Created: 2011-03-19
Expires: 2012-03-19</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1299/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1299&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/23/spam-from-canadian-pharmacy-masked-as-delivery-notification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110323_canpharmacy.gif" medium="image" />
	</item>
		<item>
		<title>Large spam campaign &#8220;Unread messages&#8221; from Twitter leads to pharmacy sites</title>
		<link>http://blog.mxlab.eu/2011/03/18/large-spam-campaign-unread-messages-from-twitter-leads-to-pharmacy-sites/</link>
		<comments>http://blog.mxlab.eu/2011/03/18/large-spam-campaign-unread-messages-from-twitter-leads-to-pharmacy-sites/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 23:28:03 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Twitter spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1293</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a large spam campaign with the subject &#8220;Twitter &#8211; You have X unread message(s)&#8221;, where the X is a number from 1 to 3,  that leads to the U.S. Drugs web site. This campaign is slightly different from the previous campaign at the end of February 2011 but leads [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1293&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a large spam campaign with the subject &#8220;Twitter &#8211; You have X unread message(s)&#8221;, where the X is a number from 1 to 3,  that leads to the U.S. Drugs web site. This campaign is slightly different from the previous campaign at the end of February 2011 but leads to the same pharmacy site.</p>
<p>The campaigns is send from the spoofed email address &#8220;Twitter &lt;twitter-message-RECIPIENT=DOMAIN@postmaster.twitter.com&gt;&#8221; where the recipients email address is included in the from address.</p>
<p>An example of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110317_twitter_spam.gif" alt="" width="450" height="227" /></p>
<p>The final destination of the URL:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110225_twitter_drug_spam2.jpg" alt="" width="450" height="352" /></p>
<p>More information regarding this site can be found at <a href="http://spamtrackers.eu/wiki/index.php/US_Drugs" target="_blank">http://spamtrackers.eu/wiki/index.php/US_Drugs</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1293/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1293/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1293/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1293&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/18/large-spam-campaign-unread-messages-from-twitter-leads-to-pharmacy-sites/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110317_twitter_spam.gif" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110225_twitter_drug_spam2.jpg" medium="image" />
	</item>
		<item>
		<title>&#8220;Twitter Notifications&#8221; spam emails leads to US Drugs web site</title>
		<link>http://blog.mxlab.eu/2011/02/25/twitter-notifications-spam-emails-leads-to-us-drugs-web-site/</link>
		<comments>http://blog.mxlab.eu/2011/02/25/twitter-notifications-spam-emails-leads-to-us-drugs-web-site/#comments</comments>
		<pubDate>Thu, 24 Feb 2011 23:43:27 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[U.S. Drugs]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1248</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a spam campaign with the subject &#8220;Twitter Notifications&#8221;, send from  randomly spoofed email addresses, that leads to U.S. Drugs web site. An example of the email: The email contains the Twitter logo and a basic lay out. The included URL appears to be leading to the twitter.com site, along [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1248&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a spam campaign with the subject &#8220;Twitter Notifications&#8221;, send from  randomly spoofed email addresses, that leads to U.S. Drugs web site.</p>
<p>An example of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110225_twitter_drug_spam.jpg" alt="" width="450" height="235" /></p>
<p>The email contains the Twitter logo and a basic lay out. The included URL appears to be leading to the twitter.com site, along with some userid variables to make it appear genuine, but behind the URL we can notice different web site addresses with each email.</p>
<p>The URL leads to the web site of U.S. Drugs where you can buy&#8230;. viagra and others. What else?</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110225_twitter_drug_spam2.jpg" alt="" width="450" height="352" /></p>
<p>More information regarding this site can be found at <a href="http://spamtrackers.eu/wiki/index.php/US_Drugs" target="_blank">http://spamtrackers.eu/wiki/index.php/US_Drugs</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1248/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1248&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/02/25/twitter-notifications-spam-emails-leads-to-us-drugs-web-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110225_twitter_drug_spam.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110225_twitter_drug_spam2.jpg" medium="image" />
	</item>
		<item>
		<title>URL shortening service durl.me is being used large spam campaigns</title>
		<link>http://blog.mxlab.eu/2011/01/27/url-shortening-service-durl-me-is-being-used-large-spam-campaigns/</link>
		<comments>http://blog.mxlab.eu/2011/01/27/url-shortening-service-durl-me-is-being-used-large-spam-campaigns/#comments</comments>
		<pubDate>Thu, 27 Jan 2011 17:51:13 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[durl.me]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1238</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, reported earlier on the dangers of URL shortening services and the increased usage of URL shorteners in spam campaigns. Since a few weeks now we notice that the URL shortening service is being used a large spam campaigns for replica watches,&#8230; and today penis enlargment spam. Very short messages like below are [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1238&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, reported earlier on <a href="http://blog.mxlab.eu/2009/07/17/shortened-urls-the-real-dangers-behind-and-how-to-avoid-troubles/">the dangers of URL shortening services</a> and <a href="http://blog.mxlab.eu/2011/01/04/increase-in-usage-of-url-shorteners-in-spam-campaigns/">the increased usage of URL shorteners in spam campaigns</a>. Since a few weeks now we notice that the URL shortening service is being used a large spam campaigns for replica watches,&#8230; and today penis enlargment spam.</p>
<p>Very short messages like below are intercepted on our systems:</p>
<blockquote><p><span style="font-family:Verdana, Helvetica, Arial;">Avoir la meilleure sexe de votre vie avec ces pilules me demande &lt;<span style="color:#0000ff;"><span style="text-decoration:underline;">hxxp://durl.me/5cogd</span></span>&gt;</span></p></blockquote>
<blockquote><p><span style="font-family:Verdana, Helvetica, Arial;"><!--StartFragment--><span style="font-family:Verdana, Helvetica, Arial;">Boostez votre ego et de la longueur de votre facilement avec nous &lt;<span style="color:#0000ff;"><span style="text-decoration:underline;">hxxp://durl.me/5cqkx</span></span>&gt;</span></span></p></blockquote>
<blockquote><p><span style="font-family:Verdana, Helvetica, Arial;">Apprenez à être un mari aimant à votre femme. &lt;<span style="color:#0000ff;"><span style="text-decoration:underline;">hxxp://durl.me/5cmx8</span></span>&gt;</span></p></blockquote>
<blockquote><p><span style="font-family:Verdana, Helvetica, Arial;"><!--StartFragment--><span style="font-family:Verdana, Helvetica, Arial;">Juste ce qu&#8217;il faut pour augmenter votre taille de tracas d&#8217;orgue gratuit &lt;<span style="color:#0000ff;"><span style="text-decoration:underline;">hxxp://durl.me/5ckzd</span></span>&gt;</span></span></p></blockquote>
<p>Each spam message is having a different shortened URL to avoid detection by intent anaylis. durl.me does offer an API so we are quite sure that the creation of new durl.me URLs is fully automated at the system of the spammer. The site of durl.me is lacking ways to contact the owners or report any abuses and this is a benefit for a spammer.</p>
<p>When following the durl.me URLs we where directed to the web site hxxp://www.entermix.ru/en/</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110127_durlme_spam.jpg" alt="" width="450" height="230" /></p>
<p>If you can&#8217;t stand the offer&#8230; Enjoy it!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1238/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1238/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1238/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1238&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/01/27/url-shortening-service-durl-me-is-being-used-large-spam-campaigns/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110127_durlme_spam.jpg" medium="image" />
	</item>
		<item>
		<title>Increase in usage of URL shorteners in spam campaigns</title>
		<link>http://blog.mxlab.eu/2011/01/04/increase-in-usage-of-url-shorteners-in-spam-campaigns/</link>
		<comments>http://blog.mxlab.eu/2011/01/04/increase-in-usage-of-url-shorteners-in-spam-campaigns/#comments</comments>
		<pubDate>Tue, 04 Jan 2011 22:51:05 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[shortened URl]]></category>
		<category><![CDATA[URL shorteners]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1217</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, is noticing an increase in the usage of URL shorteners like bit.ly and others. This technique is being used to avoid detecting of the URL by intent analysing techniques. Some examples of the latest spam campaign for replica watches: Vervollständigen Sie Ihre Garderobe mit Markennamen Luxus-Accessoires http://durl.me/4krma Kommen Sie in unser One-Stop-Shopping-Erlebnis [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1217&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, http://www.mxlab.eu, is noticing an increase in the usage of URL shorteners like bit.ly and others. This technique is being used to avoid detecting of the URL by intent analysing techniques.</p>
<p>Some examples of the latest spam campaign for replica watches:</p>
<blockquote><p>Vervollständigen Sie Ihre Garderobe mit Markennamen Luxus-Accessoires</p>
<p>http://durl.me/4krma</p></blockquote>
<blockquote><p>Kommen Sie in unser One-Stop-Shopping-Erlebnis wunderbar, nur einen Klick entfernt.</p>
<p>http://durl.me/4kohn</p></blockquote>
<blockquote><p>Obtenez le Tag Heuer SLR Mercedes regarder ici</p>
<p>http://durl.me/4iii7</p></blockquote>
<blockquote><p>Obtenez tous vos besoins de luxe sous un même toit, et à 60% de réduction!</p>
<p>http://durl.me/4kpjy</p></blockquote>
<blockquote><p>Email not displaying correctly? View in your browser.<br />
Great prices on all watch brands http://redir.ec/39qj</p>
<p>Our web-store of Watch-lones welcomes you!<br />
We have copies of famous chronometer brands for more than affordable prices!<br />
Respect and style will be easier to get!</p>
<p>If you wish to unsubscribe from our mailing list, click here</p></blockquote>
<blockquote><p>Assurez-il se passer maintenant avec les prix réelle et exacte des produits de luxe à la recherche.</p>
<p>http://durl.me/4kon6</p></blockquote>
<p>The URLs in this spam campaign lead to the web site Ultimate Replica</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110103_ultreplica.jpg" alt="" width="450" height="423" /></p>
<p>We have seen the usage of URL shorteners emerge at the end of 2010 so  it seems that this technique is becoming more popular among spammers.  Each spam message has a different shortened URL,  sometimes even  processed by different URL shortening services.</p>
<p>While in the first  campaigns we noticed some popular URL shorteners like bit.ly being  used, the trend is now that other less known URL shortening services are  being used. In some cases, the URL shorteners also do not even have a  way to report abuses through their web site and I think that the spammers are aware of this.</p>
<p>In the past, we have submitted some shortened URLs to the abuse department of bit.ly for example and we could notice that the URLs where disabled quite fast.</p>
<p>Most of the URL shorteners also have an API available. The API makes it even more easier to integrate an URL shortener service into a botnet or spam campaign. For example, the URL shortener wa.la has a <a href="http://www.wa.la/api.html" target="_blank">very simple PHP API</a>:</p>
<p>$shortenedurl = file_get_contents(&#8216;http://wa.la/shorten.php?longurl=&#8217; . urlencode(&#8216;http://theurl.to.shorten.com/&#8217;));</p>
<p>With a single line, the URL is shortened and usable in a spam campaign. In this case, no account has to be created so the creation of the URL is also anonymous.</p>
<p>Some URL shorteners also have the ability to gather some statistics about the usage of the shortened URL. Spammers can measure certain aspects of the spam campaign they manage.</p>
<p>In  the past, MX Lab warned about <a href="http://blog.mxlab.eu/2009/07/17/shortened-urls-the-real-dangers-behind-and-how-to-avoid-troubles/" target="_blank">URL shorteners</a> and the possible threats you may encounter with them. One major disadvantage is that you are no longer to see the full URL before you click on it with certain URL shortening services. The URL shorteners that spammers use do not have a preview mode like  for example bit.ly. So, the recipient will only see the full URL when  following the shortened URL.</p>
<p>At this time it is a spam campaign for replica watches, one day it can be a malicious payload, designed to infect your computer.</p>
<p>MX Lab was already pro-actively scanning emails for shortened URLs since a few weeks when we noticed the first campaigns with shortened URLs. When a shortened URL is detected we take this into account when we determine wether the message is spam or not.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1217/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1217&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/01/04/increase-in-usage-of-url-shorteners-in-spam-campaigns/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110103_ultreplica.jpg" medium="image" />
	</item>
	</channel>
</rss>
