<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; Western Union</title>
	<atom:link href="http://blog.mxlab.eu/tag/western-union/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; Western Union</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Emails Western Union Service contains Bredolab</title>
		<link>http://blog.mxlab.eu/2009/11/30/emails-western-union-service-contains-bredolab/</link>
		<comments>http://blog.mxlab.eu/2009/11/30/emails-western-union-service-contains-bredolab/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 23:17:50 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Western Union]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=699</guid>
		<description><![CDATA[After a relative low virus detection for more than a week, MX Lab started to intercepted a new virus outbreak of Bredolab in emails regarding a Western Union money transfer. The malware is named Bredolab.gen.a (McAfee), TrojanDownloader:Win32/Bredolab.X (Microsoft),  Mal/Krap-B (Sophos) or Trojan.Bredolab!gen3 (Symantec). The spoofed from address is in the form of Manager Ginger Patrick &#60;customer@westernunion.com&#62; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=699&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>After a relative low virus detection for more than a week, MX Lab started to intercepted a new virus outbreak of Bredolab in emails regarding a Western Union money transfer. The malware is named Bredolab.gen.a (McAfee), TrojanDownloader:Win32/Bredolab.X (Microsoft),  Mal/Krap-B (Sophos) or Trojan.Bredolab!gen3 (Symantec).</p>
<p>The spoofed from address is in the form of Manager Ginger Patrick &lt;customer@westernunion.com&gt; where the name of the person is random.</p>
<p>The email has the subject:</p>
<blockquote><p>Western Union Service. Please get your money. Order NR.4560<br />
Western Union Service. You can receive money transfer. Order NR.5606<br />
Western Union Service. You should receive money transfer. Order NR.0743<br />
Western Union Service. Your money transfer details!. Order NR.4560<br />
Western Union Service. You need to get money! Order NR.5606<br />
Western Union Service. MTCN Details. Order NR.3365</p></blockquote>
<p>The order numbers will change with each email and are choosen randomly.</p>
<p>The body of the email:</p>
<blockquote><p>Dear customer.</p>
<p>The amount of money transfer: 4675 USD.<br />
Money is available to withdrawl.</p>
<p>You may find the Money Transfer Control Number and receiver&#8217;s details in document attached to this email.</p>
<p>Western Union.<br />
Financial Services.</p></blockquote>
<p>The email contains the attachment WU_Details_db6ec.zip with the executable WU_Details_db6ec.exe in the archive.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/4fbb996e1396c7b0ae3a9e1170863f4258bd411f7dcbaae477a2eb09a6fca324-1259620109" target="_blank">permlink</a> and MD5: 0307d603cef4c524c3b05417387dfdec</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/699/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/699/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/699/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/699/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/699/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/699/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/699/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/699/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/699/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/699/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=699&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/11/30/emails-western-union-service-contains-bredolab/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Western Union MTCN trojan</title>
		<link>http://blog.mxlab.eu/2009/05/26/new-western-union-mtcn-trojan/</link>
		<comments>http://blog.mxlab.eu/2009/05/26/new-western-union-mtcn-trojan/#comments</comments>
		<pubDate>Tue, 26 May 2009 21:46:11 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Mal/Zbot-I]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Western Union]]></category>
		<category><![CDATA[zbot]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=460</guid>
		<description><![CDATA[MX Lab intercepted a new ZBot trojan today that is being distributed in the famous &#8220;Western Union MTCN&#8221; format. The message subject is &#8220;Western Union Transfer MTCN: 5815328212&#8243;. The attached file is a compresses zip archive WesternUnion_SPL90710021.zip containing the malware WesternUnion_SPL90710021.exe. Please note that the numbers in the subject line and/or attachment and executable can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=460&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted a new ZBot trojan today that is being distributed in the famous &#8220;Western Union MTCN&#8221; format. The message subject is &#8220;Western Union Transfer MTCN: 5815328212&#8243;. The attached file is a compresses zip archive WesternUnion_SPL90710021.zip containing the malware WesternUnion_SPL90710021.exe. Please note that the numbers in the subject line and/or attachment and executable can change.</p>
<p>The body of the email contains:</p>
<blockquote><p>Dear customer!</p>
<p>The money transfer you have sent on the 20th of April wasn&#8217;t received by the recipient.<br />
According to the Western Union contract the transfers which are not collected in 15 days are to be returned to sender.<br />
To collect funds you need to print the invoice attached to this e-mail and visit the nearest Western Union branch.</p>
<p>Thank you!</p></blockquote>
<p>When we submitted the virus sample to Virus Total, on 26/05/2009 at 21:27:10 (UTC), we only had 6 of the 40 AV engines detecting the malware. When looking at the details and virus naming we assume that they are being detected by some heuristic features that the AV engines have: Gen:Trojan.Heur.3004FB9EBC (BitDefender, GData), Suspicious file (Panda), (Suspicious) &#8211; DNAScan (CAT-QuickHeal). A-Squared and Microsoft have a real virus name: Gen.Trojan!IK and TrojanDownloader:Win32/Bredolab.G.</p>
<p>The trojan will create the following files:</p>
<blockquote><p>%AppData%\wiaserva.log <br />
 %Temp%\WER699f.dir00\appcompat.txt <br />
%Temp%\WER699f.dir00\explorer.exe.hdmp<br />
%Temp%\WER699f.dir00\explorer.exe.mdmp <br />
%Temp%\WER699f.dir00\manifest.txt <br />
%System%\wbem\grpconv.exe </p></blockquote>
<p>%AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.</p>
<p>The following directy is created: %Temp%\WER699f.dir00.<br />
A new process is created in the system: %System%\wbem\grpconv.exe along with some Windows registry modifications.</p>
<p>The following URL is being used: hxxp://dollarpoint.ru/abc/controller.php?action=bot&amp;entity_list=&amp;uid=&amp;first=1&amp;guid=13441600&amp;rnd=8520045</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/8a45f57a2d32ee905c653bcd69aac18441602a82bc1a10690c38c9fa81c9ffde-1243373550" target="_blank">permalink</a> and MD5 hash: 53d15dc652a2534572981bab1e2eddf3.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/460/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/460/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/460/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=460&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/26/new-western-union-mtcn-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Western Union MTCN trojan variant</title>
		<link>http://blog.mxlab.eu/2009/05/13/western-union-mtcn-trojan-variant/</link>
		<comments>http://blog.mxlab.eu/2009/05/13/western-union-mtcn-trojan-variant/#comments</comments>
		<pubDate>Wed, 13 May 2009 17:41:12 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[Western Union]]></category>
		<category><![CDATA[Western Union trojan]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=442</guid>
		<description><![CDATA[MX Lab intercepted emails with attached malware Trojan-Spy.Win32.Zbot.tnt regarding a failed money transfer that is handled by Western Union. The email subject is &#8220;Western Union Transfer MTCN: 9439449215&#8243; &#8211; note that the number is random and will change with each message &#8211; and is coming from support@westernunion.com &#8211; is obviously spoofed. The body of the email: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=442&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted emails with attached malware Trojan-Spy.Win32.Zbot.tnt regarding a failed money transfer that is handled by Western Union. The email subject is &#8220;Western Union Transfer MTCN: 9439449215&#8243; &#8211; note that the number is random and will change with each message &#8211; and is coming from support@westernunion.com &#8211; is obviously spoofed.</p>
<p>The body of the email:</p>
<blockquote>
<p style="font:10px Verdana;margin:0;">Dear Client!</p>
<p style="font:10px Verdana;min-height:12px;margin:0;"> </p>
<p style="font:10px Verdana;margin:0;">The money transfer you have sent on the 9th of March has not been received by the recipient.</p>
<p style="font:10px Verdana;margin:0;">According to the Western Union contract the transfers which are not collected in 15 business days are to be returned to sender.</p>
<p style="font:10px Verdana;margin:0;">To collect funds you need to print the invoice attached to this e-mail and visit the nearest Western Union agency.</p>
<p style="font:10px Verdana;min-height:12px;margin:0;"> </p>
<p style="font:10px Verdana;margin:0;">Thank you!</p>
</blockquote>
<p>The email has a Zip file attached with the name Invoice_8773.zip which contains the executable Invoice_8773.exe. The malware has the same characteristics as our <a href="http://blog.mxlab.eu/2008/08/27/western-union-mtcn-troja/" target="_self">previous malware detection</a> in the past.</p>
<p>VirusTotal <a href="http://www.virustotal.com/analisis/c7d36fb4de9cca3707b37a2a64c0df1b" target="_blank">permalink</a> and MD5:fa491105bd5c3baedad78f28586ff91e.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/442/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/442/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/442/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=442&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/13/western-union-mtcn-trojan-variant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>