<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; trojans</title>
	<atom:link href="http://blog.mxlab.eu/tag/trojans/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; trojans</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Death of Michael Jackson inspires spammers and malware distributors</title>
		<link>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/</link>
		<comments>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/#comments</comments>
		<pubDate>Sat, 27 Jun 2009 20:48:25 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Michael Jackson]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=492</guid>
		<description><![CDATA[Spammers and malware distributors are trying to take advantage of the death of Michael Jackson by sending out email campaigns with subject and/or body related to Michael Jackson while malware distributors try to infect computers by offering a URL to a site that offers a video of the death of the &#8220;King of pop&#8221;. Here [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=492&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Spammers and malware distributors are trying to take advantage of the death of Michael Jackson by sending out email campaigns with subject and/or body related to Michael Jackson while malware distributors try to infect computers by offering a URL to a site that offers a video of the death of the &#8220;King of pop&#8221;. Here is a brief overview.</p>
<p><strong>Canadian Pharmacy spam</strong></p>
<p>One of the campaigns contains the subject &#8220;Michael Jackson dead? NO!!!&#8221; and the body content:</p>
<blockquote><p>Michael Jackson dead? NO!!!<br />
Open attached file and read!!!</p></blockquote>
<p>The attachment itself appears to be harmless and contains the HTML refresh tag</p>
<blockquote><p>&lt;meta http-equiv=&#8217;Refresh&#8217; content=&#8217;0; url=hxxp://addfamous.com/&#8217; /&gt;</p></blockquote>
<p>This will redirect your browser to the Canadian Pharmacy web site.</p>
<p><strong>Email harvesting</strong></p>
<p>Another campaign has the intention to harvest email addresses and is coming from a bogus email account but the reply to is a ***@live.com account. The email claims to have special and confidential information regarding the death of Michael Jackson. A sample of the content:</p>
<blockquote><p>Confidential<br />
Vital informations after the death of Michael Jackson’s I really need some one trusted &amp; secretive to speak with with informations i have in my possession before its too late Kindly reply me and i will immediately respond back,Its for just secret between both of us</p></blockquote>
<p>The call-to-action is to reply to this message. When doing so you will confirm the spammer that the email has been received and read and therefore is active.</p>
<p><strong>Malicious spam</strong></p>
<p>This spam email offers a link to a YouTube video but actually sends the recipient to a Trojan Downloader hosted on a compromised web site. The file is Michael.Jackson.videos.scr. When downloaded and executed 3 information-stealing components are downloaded and installed by the malware. One of the files has the name michael.gif and has a very low <a href="http://www.virustotal.com/analisis/67cba7b9d91e1cbcac0f22b5f4bcf12f4b07a1a62d7d3018e28ccd5ee93e0ce4-1246012313" target="_blank">AV detection rate</a>.</p>
<p>The malware then installs a malicious BHO that is registered with this file %windir%\Dynamic.dll. Another component is bound to startup at %windir%\system32\kproces.exe. Another malicious file installed by the malware is %windir%\system32\fotos.exe.</p>
<p>Upon executing the file, a legitimate Web site at http://musica.uol.com.br/ultnot/2009/06/25/michael-jackson.jhtm is opened by the default browser in order to distract the user by presenting a news article for them to read.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/d602b5cbc6386e9ba4b7d910ff0eb04fefba5ce06ef6f703e37f76ab88ad2ff9-1246130240" target="_blank">permlink</a> and MD5: 664cb28ef710e35dc5b7539eb633abca.</p>
<p><strong>Student Loans</strong></p>
<p>A spam with the subject and the body content &#8220;Micheal Jackson History&#8221;, notice the wrong spelling of his firstname, leads to hxxp://loansofworld.blogspot.com/. This message was sent through Google Groups.</p>
<p><strong>Contact databases</strong></p>
<p>An email with the subject &#8220;Michael Jackson: last farewell from DataForYou&#8221; is attracting readers with a subject related to Michael Jackson but instead offers contact databases.</p>
<p>Notice the TinyURL inside the email content to hide a direct link to the web site. TinyURL has already removed the URL but  this example shows that you need to be carefull with URLs in emails where a service like TinyURL is shortening the full URL. Try to use a preview feature first when you don&#8217;t trust the source is our recommendation.</p>
<blockquote><p>Dear Sirs,<br />
in our site you have access, through the cheapest prices you have ever seen,<br />
to a vast database of international Companies,  divided by region, province, city or area of activity.</p>
<p>The databases are divided into two broad categories.</p>
<p>Archives of International Companies with E-mai only</p>
<p>The archives are divided by country and include a list of e-mail only.<br />
The archives are in TXT format and they are easy to be used  because<br />
this format is the  typical one used for data import. You can also find<br />
more than one email, relferring to different people working in the same<br />
structure, for the Companies which have provided them.</p>
<p>International Archives of active domains with MX record only</p>
<p>The archives are divided by size and include a list of  domains only.<br />
The archives are in TXT format and they are easy to use because this<br />
format is the typical one used for data iimport. All the domains have<br />
an active MX record; this means that each domain is directly linked<br />
with working  email accounts.</p>
<p>Visit our site at<br />
hxxp://tinyurl.com/infinitemail</p>
<p>Don&#8217;t lose this incredible opportunity for increment your business.</p>
<p>InfiniteMail</p>
<p>Customer Care</p>
<p>If you no longer want to receive our email reply here:<br />
mailto:remove@mediasch0pping.com</p></blockquote>
<p><strong>National Survey Panel&#8217;s Gift Program</strong></p>
<blockquote><p>What killed Michael Jackson?</p>
<p>Press here:<br />
hxxp://totjebiok.com/tr.php?72928+*****@*****.com</p>
<p>Tell us. Then complete the program requirements for a FREE 7 album collection of MJ&#8217;s solo career.</p></blockquote>
<p>These guys are using the death of Michael Jackson to attract some people to fill in some information and in return you can receive his albums for free.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090627_MJackson_1.jpg" alt="" width="450" height="293" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/492/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/492/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/492/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=492&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/06/27/death-of-michael-jackson-inspires-spammers-and-malware-distributors/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090627_MJackson_1.jpg" medium="image" />
	</item>
		<item>
		<title>Managed Anti Virus powered by Trend Mirco</title>
		<link>http://blog.mxlab.eu/2007/10/12/managed-anti-virus-powered-by-trend-mirco/</link>
		<comments>http://blog.mxlab.eu/2007/10/12/managed-anti-virus-powered-by-trend-mirco/#comments</comments>
		<pubDate>Fri, 12 Oct 2007 15:13:58 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[MX Lab News]]></category>
		<category><![CDATA[anti virus]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/2007/10/12/49/</guid>
		<description><![CDATA[MX Lab offers a fully managed antivirus and comprehensive security protection against today’s complex, blended threats and web-based attacks using the Trend Micro™ OfficeScan™ technology. Visit MX Lab for more information.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=49&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab offers a fully managed antivirus and comprehensive security protection against today’s complex, blended threats and web-based attacks using the Trend Micro™ OfficeScan™ technology. Visit <a href="http://www.mxlab.be/en/services/managed_antivirus_officescan.html" target="_blank">MX Lab</a> for more information.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/49/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/49/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=49&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2007/10/12/managed-anti-virus-powered-by-trend-mirco/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>