<?xml version="1.0" encoding="iso-8859-1"?>

<rdf:RDF 
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns="http://purl.org/rss/1.0/"
>
		
		
		
	<channel rdf:about="../../../../itsecurityblog">
	<title>MX Logic IT Security Blog</title>
	<description>Powered by BlogCFM</description>
	<link>../../../../itsecurityblog</link>
	
	<items>
		<rdf:Seq>
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/07/Announcing-the-July-2008-MX-Logic-Threat-Forecast-and-Report.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/Storm-Wants-to-Make-You-a-Winner.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/Nugache-Worm-Author-Pleads-Guilty.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/Microsoft-Identifies-Tools-to-Address-SQL-Injection-Attacks.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/Cyber-Hitman-of-the-Future.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/PornTube-Malware-and-Spam-Run-in-High-Volumes.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/New-Storm-Variant-Claiming-New-Earthquake-in-China.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/American-in-Heidelberg.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/While-on-the-Topic-of-Google-Spam.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/06/Where-Has-All-of-the-Google-Spam-Gone.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Poorly-Crafted-Fake-CNN-News-Updates.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/New-Kind-of-Phish-Dead-Phish.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/New-Chinese-Earthquake-Relief-Phishing-Scam.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Rootkit-Written-Targeting-Cisco-Routers.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Cell-Phone-Spam-Becoming-More-Invasive.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Whaling-Scam-from-the-US-Tax-Court.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/The-Google-Calendar-Spam-Dilemma.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Google-AdWords-Phishing.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Peter-Gabriels-Web-Server-Stolen.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/05/Happy-Birthday-Spam.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/Telecommuters-Surf-Twice-as-Much-Porn.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/New-Phishing-Scam-Targetting-Economic-Stimulus-Payments.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/Malicious-Google-Spam-Alleging-News-Video-from-Bin-Laden.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/Cyber-Criminals-Go-To-Great-Lengths-To-Establish-Trust.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/Hold-out-on-Spammers-Get-Better-Discounts--Win-the-Spam-Game.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/New-Government-Phish--This-Time-Targeting-the-US-District-Court.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/Rock-on-with-the-Storm-Worm.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/First-Google-now-Hotmail.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/FBI-Releases-2007-Internet-Crime-Report.cfm" />
			
			
			
				
			<rdf:li rdf:resource="../../../../itsecurityblog/1/2008/04/Its-Google-Spam--Its-Video-Spam--Its-Malware.cfm" />
			
			
		</rdf:Seq>
	</items>
	
	</channel>
		
		
		
		
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/07/Announcing-the-July-2008-MX-Logic-Threat-Forecast-and-Report.cfm">
	<title>Announcing the July 2008 MX Logic Threat Forecast and Report</title>
	<description>&lt;br /&gt;
Hot off the presses and posted to the MX Logic web site is the July 2008 edition of our Threat Forecast and Report.&amp;nbsp; &lt;br /&gt;
In this latest edition we look ahead to some of the threats and scams that we see upcoming for the month of July (Teaser:&amp;nbsp; the iPhone will be featured prominently this month!) as well as a lookback to what we saw during the month of June (In our previous report we estimated that spam volume would go up in June after being down in May.&amp;nbsp; Oops!).&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
There is also something about name calling between pots and kettles....&lt;br /&gt;
&lt;br /&gt;
Check out this month&apos;s Threat Forecast and Report &lt;a href=&quot;http://www.mxlogic.com/pdf/forecast/threatforecast0708.pdf&quot;&gt;here&lt;/a&gt;.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/07/Announcing-the-July-2008-MX-Logic-Threat-Forecast-and-Report.cfm</link>
	<dc:date>2008-07-02T10:51:40-06:00</dc:date>
	
	<dc:subject></dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/Storm-Wants-to-Make-You-a-Winner.cfm">
	<title>Storm Wants to Make You a Winner!</title>
	<description>&lt;br /&gt;
Of course it is appropriate that on the same day we write about the author of fast flux &lt;a href=&quot;http://www.mxlogic.com/itsecurityblog/1/2008/06/Nugache-Worm-Author-Pleads-Guilty.cfm&quot;&gt;pleading guilty to a felony&lt;/a&gt; that we see another Storm Worm variant come out.&amp;nbsp; Granted, new Storm Worm variants are nothing new.&amp;nbsp; They come out all the time.&amp;nbsp; I figured I would send out some red flags on this one because as of the time of this writing AV identification of this new variant is less than 10%.&lt;br /&gt;
&lt;br /&gt;
The lure is your typical one-liner type of email which has a love lure in the message body such as &amp;quot;I Want You, I Need You, I Love You&amp;quot; or &amp;quot;You are in my heart&amp;quot; followed by a link to a web site that serves up two executables (both linked to Storm).&lt;br /&gt;
&lt;br /&gt;
This is a screen shot of what the site looks like:&lt;br /&gt;
&lt;br /&gt;
&lt;img alt=&quot;&quot; src=&quot;../../../../itsecurityblog/1/custom/storm_winner.jpg&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
Clicking on the banner at the top of the page attempts to download a file named winner.exe.&amp;nbsp; Clicking the &amp;quot;Click Here&amp;quot; link attempts to download mylove.exe.&lt;br /&gt;
&lt;br /&gt;
Here are the virustotal.com results for winner.exe and mylove.exe:&lt;br /&gt;
&lt;br /&gt;
&lt;table width=&quot;550&quot; cellspacing=&quot;0&quot; cellpadding=&quot;0&quot; border=&quot;0&quot; id=&quot;tablaMotores&quot;&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;th&gt;Antivirus&lt;/th&gt;
            &lt;th&gt;Version&lt;/th&gt;
            &lt;th&gt;Last Update&lt;/th&gt;
            &lt;th&gt;Result&lt;/th&gt;
        &lt;/tr&gt;
        &lt;!-- tablaMotoresContenido --&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;AhnLab-V3&lt;/td&gt;
            &lt;td&gt;2008.7.1.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;AntiVir&lt;/td&gt;
            &lt;td&gt;7.8.0.59&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Authentium&lt;/td&gt;
            &lt;td&gt;5.1.0.4&lt;/td&gt;
            &lt;td&gt;2008.06.29&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Avast&lt;/td&gt;
            &lt;td&gt;4.8.1195.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;AVG&lt;/td&gt;
            &lt;td&gt;7.5.0.516&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;BitDefender&lt;/td&gt;
            &lt;td&gt;7.2&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;CAT-QuickHeal&lt;/td&gt;
            &lt;td&gt;9.50&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;ClamAV&lt;/td&gt;
            &lt;td&gt;0.93.1&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;DrWeb&lt;/td&gt;
            &lt;td&gt;4.44.0.09170&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;eSafe&lt;/td&gt;
            &lt;td&gt;7.0.17.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Suspicious File&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;eTrust-Vet&lt;/td&gt;
            &lt;td&gt;31.6.5914&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Ewido&lt;/td&gt;
            &lt;td&gt;4.0&lt;/td&gt;
            &lt;td&gt;2008.06.27&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;F-Prot&lt;/td&gt;
            &lt;td&gt;4.4.4.56&lt;/td&gt;
            &lt;td&gt;2008.06.29&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;F-Secure&lt;/td&gt;
            &lt;td&gt;7.60.13501.0&lt;/td&gt;
            &lt;td&gt;2008.06.26&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Fortinet&lt;/td&gt;
            &lt;td&gt;3.14.0.0&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;GData&lt;/td&gt;
            &lt;td&gt;2.0.7306.1023&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Ikarus&lt;/td&gt;
            &lt;td&gt;T3.1.1.26.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Kaspersky&lt;/td&gt;
            &lt;td&gt;7.0.0.125&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;McAfee&lt;/td&gt;
            &lt;td&gt;5328&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Microsoft&lt;/td&gt;
            &lt;td&gt;1.3704&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;NOD32v2&lt;/td&gt;
            &lt;td&gt;3229&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Norman&lt;/td&gt;
            &lt;td&gt;5.80.02&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Panda&lt;/td&gt;
            &lt;td&gt;9.0.0.4&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Suspicious file&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Prevx1&lt;/td&gt;
            &lt;td&gt;V2&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Rising&lt;/td&gt;
            &lt;td&gt;20.51.02.00&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Sophos&lt;/td&gt;
            &lt;td&gt;4.30.0&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Sunbelt&lt;/td&gt;
            &lt;td&gt;3.1.1509.1&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Symantec&lt;/td&gt;
            &lt;td&gt;10&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;TheHacker&lt;/td&gt;
            &lt;td&gt;6.2.96.365&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;TrendMicro&lt;/td&gt;
            &lt;td&gt;8.700.0.1004&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;VBA32&lt;/td&gt;
            &lt;td&gt;3.12.6.8&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;VirusBuster&lt;/td&gt;
            &lt;td&gt;4.5.11.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Webwasher-Gateway&lt;/td&gt;
            &lt;td&gt;6.6.2&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;table width=&quot;550&quot; cellspacing=&quot;0&quot; cellpadding=&quot;0&quot; border=&quot;0&quot; id=&quot;tablaMotores&quot;&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;th&gt;Antivirus&lt;/th&gt;
            &lt;th&gt;Version&lt;/th&gt;
            &lt;th&gt;Last Update&lt;/th&gt;
            &lt;th&gt;Result&lt;/th&gt;
        &lt;/tr&gt;
        &lt;!-- tablaMotoresContenido --&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;AhnLab-V3&lt;/td&gt;
            &lt;td&gt;2008.7.1.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;AntiVir&lt;/td&gt;
            &lt;td&gt;7.8.0.59&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Authentium&lt;/td&gt;
            &lt;td&gt;5.1.0.4&lt;/td&gt;
            &lt;td&gt;2008.06.29&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Avast&lt;/td&gt;
            &lt;td&gt;4.8.1195.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;AVG&lt;/td&gt;
            &lt;td&gt;7.5.0.516&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;BitDefender&lt;/td&gt;
            &lt;td&gt;7.2&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Trojan.Peed.JLV&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;CAT-QuickHeal&lt;/td&gt;
            &lt;td&gt;9.50&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;ClamAV&lt;/td&gt;
            &lt;td&gt;0.93.1&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;DrWeb&lt;/td&gt;
            &lt;td&gt;4.44.0.09170&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;eSafe&lt;/td&gt;
            &lt;td&gt;7.0.17.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Suspicious File&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;eTrust-Vet&lt;/td&gt;
            &lt;td&gt;31.6.5914&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Ewido&lt;/td&gt;
            &lt;td&gt;4.0&lt;/td&gt;
            &lt;td&gt;2008.06.27&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;F-Prot&lt;/td&gt;
            &lt;td&gt;4.4.4.56&lt;/td&gt;
            &lt;td&gt;2008.06.29&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;F-Secure&lt;/td&gt;
            &lt;td&gt;7.60.13501.0&lt;/td&gt;
            &lt;td&gt;2008.06.26&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Fortinet&lt;/td&gt;
            &lt;td&gt;3.14.0.0&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;GData&lt;/td&gt;
            &lt;td&gt;2.0.7306.1023&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Ikarus&lt;/td&gt;
            &lt;td&gt;T3.1.1.26.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Email-Worm.Win32.Zhelatin.zy&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Kaspersky&lt;/td&gt;
            &lt;td&gt;7.0.0.125&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;McAfee&lt;/td&gt;
            &lt;td&gt;5328&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Microsoft&lt;/td&gt;
            &lt;td&gt;1.3704&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;NOD32v2&lt;/td&gt;
            &lt;td&gt;3229&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Norman&lt;/td&gt;
            &lt;td&gt;5.80.02&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Panda&lt;/td&gt;
            &lt;td&gt;9.0.0.4&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Prevx1&lt;/td&gt;
            &lt;td&gt;V2&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Rising&lt;/td&gt;
            &lt;td&gt;20.51.02.00&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Sophos&lt;/td&gt;
            &lt;td&gt;4.30.0&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Sunbelt&lt;/td&gt;
            &lt;td&gt;3.1.1509.1&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Symantec&lt;/td&gt;
            &lt;td&gt;10&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;TheHacker&lt;/td&gt;
            &lt;td&gt;6.2.96.365&lt;/td&gt;
            &lt;td&gt;2008.07.01&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;TrendMicro&lt;/td&gt;
            &lt;td&gt;8.700.0.1004&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;VBA32&lt;/td&gt;
            &lt;td&gt;3.12.6.8&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;VirusBuster&lt;/td&gt;
            &lt;td&gt;4.5.11.0&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;&quot;&gt;
            &lt;td&gt;Webwasher-Gateway&lt;/td&gt;
            &lt;td&gt;6.6.2&lt;/td&gt;
            &lt;td&gt;2008.06.30&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
So, as you can see, AV pickup so far has been non-existent although I am sure it will pick up soon.&amp;nbsp; The IPs that are hosting the infected URLs are being rotated using fast flux.&amp;nbsp; In just the 15 minutes that I have been monitoring some of the sites they have already changed IPs several times.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
This is not likely to be the only time this week that we hear from Storm.&amp;nbsp; Last year during the July 4th holiday is when we started to see the big fake e-card Storm surge.&amp;nbsp; Although most people are used to seeing these by now, they always manage to be popular social engineering lures nonetheless.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Expect to see some revisit of Storm sometime later this week.&amp;nbsp; It might not be e-cards, but in following with Storm&apos;s tradition of releasing new variants on or near holidays, I would be very surprised if a Storm weren&apos;t already brewing.&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/Storm-Wants-to-Make-You-a-Winner.cfm</link>
	<dc:date>2008-06-30T17:21:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/Nugache-Worm-Author-Pleads-Guilty.cfm">
	<title>Nugache Worm Author Pleads Guilty</title>
	<description>&lt;br /&gt;
Jason Michael Milmont, the author of the Nugache worm, and the creator of what came to be known as &amp;quot;Fast Flux&amp;quot; has plead guilty to one count of unlawfully accessing computers, a felony, in a Wyoming federal court.&lt;br /&gt;
&lt;br /&gt;
Fast Flux is an abuse of the domain name system (DNS) by which botnets will continually rotate the IP addresses associated with a malware infected web site to evade detection and forensic analysis.&amp;nbsp; This constant mobility makes the botnet very difficult to shut down. &lt;br /&gt;
&lt;br /&gt;
There is also an evasion tactic called &amp;quot;Double Flux&amp;quot; which is similar to Fast Flux in that it will not only rotate a domain&apos;s responding IP addresses, but also that domain&apos;s authoritative name servers.&amp;nbsp; The reason that it is called &amp;quot;Fast&amp;quot; flux is because these IP addresses will rotate as often as every couple of minutes.&lt;br /&gt;
The Nugache worm was used to launch distributed denial of service (DDoS) attacks as well as steal personal information such as credit card numbers from the computers that were infected with Nugache.&amp;nbsp; It has been estimated that controlled up to as many as 15,000 on his botnet.&lt;br /&gt;
&lt;br /&gt;
Under the terms of his deal Milmont has agreed to pay approximately $74,000 in damages and faces up to five years in federal prison.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
In my opinion, this story is only significant because of Milmont&apos;s contribution to the botnet community with how his Nugache worm used peer-to-peer networking technology and fast flux in order to create a fully redundant, interconnected network to prevent his botnet from easily being shut down.&amp;nbsp; The size of the Nugache botnet (about 15,000 computers) pales in comparison to some of the botnets that we are seeing today, but the work done by Milmont paved the way for worms like Storm which heavily relied on fast flux to stay alive.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/Nugache-Worm-Author-Pleads-Guilty.cfm</link>
	<dc:date>2008-06-30T09:46:29-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/Microsoft-Identifies-Tools-to-Address-SQL-Injection-Attacks.cfm">
	<title>Microsoft Identifies Tools to Address SQL Injection Attacks?</title>
	<description>&lt;br /&gt;
According to &lt;a href=&quot;http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1318731,00.html?track=NL-102&amp;amp;ad=641700USCA&amp;amp;asrc=EM_NLN_3916488&amp;amp;uid=5093170&quot;&gt;this TechTarget article&lt;/a&gt;, Microsoft has a few tools that they recommend people use to address SQL injection attacks.&lt;br /&gt;
&lt;br /&gt;
Don&apos;t be fooled by what is meant by &amp;quot;address&amp;quot; in this context.&amp;nbsp; Let&apos;s be clear on what these tools do and what they don&apos;t do.&lt;br /&gt;
&lt;br /&gt;
They DO:&lt;br /&gt;
&lt;br /&gt;
-- Scan web sites and identify potential SQL injection vulnerabilities.&amp;nbsp; Even Erik Peterson, a senior director of products for HP&apos;s application security center states that Scrawlr (one of the tools identified) falls short the functionality provided many commercial tools.&lt;br /&gt;
-- Analyze source code for potential vulnerabilities, however the source code analyzer that is recommended only supports ASP code written in VBScript.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Seems like we are quickly narrowing down the number of web sites these recommended tools will even function on.&lt;br /&gt;
&lt;br /&gt;
They DON&apos;T:&lt;br /&gt;
&lt;br /&gt;
-- Provide protection against any attacks&lt;br /&gt;
-- Solve the real root of the problem which is ensuring programmers are following safe coding practices to protect the sites that they develop from SQL injection vulnerabilities.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
If you use any of these tools that Microsoft is recommending, don&apos;t be lulled into the false sense of security that they can provide.&amp;nbsp; As we can see, many free scanning tools have all kinds of limitations that will only provide the most basic of testing or only work provided that very specific technology conditions and phases of the moon exist.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
I am glad to see that Robert Westervelt, the author of the article linked at the beginning of this post &lt;a href=&quot;http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1318860,00.html?track=NL-102&amp;amp;ad=641705&amp;amp;asrc=EM_NLN_3931938&amp;amp;uid=5093170&quot;&gt;wrote up this clarification&lt;/a&gt; today.&amp;nbsp; I like Robert and actually did an &lt;a href=&quot;http://securitywireweekly.blogs.techtarget.com/2008/01/&quot;&gt;interview with him&lt;/a&gt; back in January related to PDF spam which posted to his blog, but I think his original article not only missed the mark, but could very well have generated a lot of confusion with junior security researchers and management folks on effective ways to detect SQL injection vulnerabilities.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/Microsoft-Identifies-Tools-to-Address-SQL-Injection-Attacks.cfm</link>
	<dc:date>2008-06-26T12:09:43-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/Cyber-Hitman-of-the-Future.cfm">
	<title>Cyber Hitman of the Future?</title>
	<description>The July 2008 edition of PC Magazine has a short story on page 92 titled &amp;quot;Hacked Through the Heart&amp;quot; which references a &lt;a href=&quot;http://www.secure-medicine.org/icd-study/icd-study.pdf&quot;&gt;paper published at secure-medicine.org&lt;/a&gt; discussing the possibility of hacking the human body through wireless reprogrammable Implantable Medical Devices (IMDs) such as pacemakers.&amp;nbsp; These attacks could lead to effects such as changing the settings on the pacemaker or even disabling it entirely!&amp;nbsp; The paper also goes into detail as to how some of these attacks would take place.&lt;br /&gt;
&lt;br /&gt;
Although the paper mentions that as of right now these are theoretical scenarios, the more important point to remember is that these IMDs are driven by software and &amp;quot;where there is software, there are vulnerabilities&amp;quot; and &amp;quot;where there are vulnerabilities, there will be exploits.&amp;quot;&amp;nbsp; I could easily envision a scenario where this creates a Cyber Hitman of the Future where hits are carried out in such a way that they would be virtually untraceable and if executed correctly could have an elapsed time effect where the full damage of the attack may not materialize for days, weeks, or even months after it initially occurred.&lt;br /&gt;
&lt;br /&gt;
On a lighter note, this certainly gives new meaning to the term &amp;quot;Insider Threat&amp;quot; (I&apos;m funny on a Friday :) )&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/Cyber-Hitman-of-the-Future.cfm</link>
	<dc:date>2008-06-20T14:28:35-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/PornTube-Malware-and-Spam-Run-in-High-Volumes.cfm">
	<title>PornTube Malware and Spam Run in High Volumes</title>
	<description>&lt;br /&gt;
Worm Alert!&lt;br /&gt;
&lt;br /&gt;
We are currently seeing high volumes of a new spam run that contains a link to an pornographic web site that contains an ActiveX malware component.&amp;nbsp; Our Threat Operations Center started seeing these messages at about 6am today and thus far we have received over 8 million of them (accounting for over 85% of our worm traffic over the past 24 hours).&amp;nbsp; From what we can tell thus far the malware appears to be related to the Srizbi botnet.&lt;br /&gt;
&lt;br /&gt;
There is no specific lure here as the subject lines to these messages are fairly random, but are trying to generate interest based on fake news stories.&amp;nbsp; Here are some example subject lines that we have seen so far:&lt;br /&gt;
&lt;br /&gt;
&lt;pre&gt;Batman latest movie bombs at box office&lt;br /&gt;Britney found hanged in locker room&lt;br /&gt;Celtics disqualified from NBA title&lt;br /&gt;China Earthquake claims 1 million lives&lt;br /&gt;Dan Brown&apos;s latest novel&lt;br /&gt;David Cook American Idol - latest NEW single&lt;br /&gt;Donald Trump missing, feared kidnapped&lt;br /&gt;Egypt Giza pyramids rocked by massive earthquake&lt;br /&gt;Eiffel Tower damaged by massive earthquake&lt;br /&gt;Eiffel Tower suffers structural damage, collapse possible&lt;br /&gt;Find out about Harry Potter&apos;s last novel&lt;br /&gt;Ford unveils latest 2 door design hatch&lt;br /&gt;Get Smart -- movie premiere&lt;br /&gt;Get star wars photos&lt;br /&gt;Get the latest discount plan from Ford Cars&lt;br /&gt;Great Wall of China damaged by earthquake&lt;br /&gt;Hiliary admits past failures&lt;br /&gt;Hillary Clinton reveals husband&apos;s scandal secrets&lt;br /&gt;Italy knocked out of Euro 2008&lt;br /&gt;Las Vegas Hotel caught in fire&lt;br /&gt;Lastest! Obama quits presidential race&lt;br /&gt;London rocked by gas attack, army on high alert&lt;br /&gt;Love Guru sneak previews here&lt;br /&gt;Man wakes up from 40 year coma&lt;br /&gt;Nokia unveils revolutionary new phone design&lt;br /&gt;Obama suffers setback in polls due to sex secrets&lt;br /&gt;Obama withdraws from elections&lt;br /&gt;Oprah found sleeping the streets&lt;br /&gt;Osama Bin Laden caught finally&lt;br /&gt;Paris Hilton found to be gay&lt;br /&gt;Saddam Hussein found dead&lt;br /&gt;Star Trek star dies at age 79&lt;br /&gt;Statue of Liberty struck by lightning, catches fire&lt;br /&gt;Stonehenge damaged by massive earthquake&lt;br /&gt;Top 10 movies of all time&lt;br /&gt;Top comedy downloads&lt;br /&gt;Top film from the Cannes&lt;br /&gt;Turner Empire poised for bankruptcy file&lt;br /&gt;Usher and Rihanna making out&lt;br /&gt;Watch movie premieres now&lt;br /&gt;White House hit by lightning, catches fire&lt;br /&gt;Windows Vista URGENT upgrade installation&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;
&lt;p&gt;The messages themselves are one liners followed by a link to a YouTube look alike site called PornTube where the user is prompted to install a malicious Active X control.&amp;nbsp; Most of the links that we have seen thus far point to a file named r.html at the end if the URL such as (obfuscated since most are still hosting active malware at the time of this posting):&lt;/p&gt;
&lt;p&gt;hxxp://envol-restaurant.com/r.html&lt;/p&gt;
&lt;p&gt;hxxp://spizarnia.nazwa.pl/r.html&lt;/p&gt;
&lt;p&gt;hxxp://wandea1.wandea.org.pl/r.html&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Upon visiting these sites you will see the PornTube site in the background and you get the following popup window:&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;&quot; src=&quot;../../../../itsecurityblog/1/custom/porn_tube.jpg&quot; /&gt;&lt;/p&gt;
&lt;br /&gt;
&lt;p&gt;If you click OK, the ActiveX control is installed and your PC is infected, however clicking the Cancel button displays this popup:&lt;/p&gt;
&lt;p&gt;&lt;img alt=&quot;&quot; src=&quot;../../../../itsecurityblog/1/custom/porn_tube2.jpg&quot; /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;At this point you can get yourself into an endless loop of clicking the OK button on this window and the Cancel button on the previous window.&amp;nbsp; The only way out of this (in Windows) is to kill your browser window via the Task Manager (or infect yourself, but let&apos;s assume that you don&apos;t really want to do that :) ).&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Keep on the lookout for these as they are currently being distributed in fairly high volumes.&amp;nbsp; &lt;/p&gt;
&lt;pre&gt;&lt;br /&gt;&lt;/pre&gt;
&lt;p&gt;*** UPDATE 6/20/2008 12:00pm MDT *** After volumes peaking at about one million instances of this worm being seen per hour, as of early this morning it has dropped off to only about 5 thousand per hour.&amp;nbsp; Looks like this one hit quick and is now tailing off.&lt;br /&gt;
&lt;/p&gt;
&lt;pre&gt;&amp;nbsp;&lt;/pre&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/PornTube-Malware-and-Spam-Run-in-High-Volumes.cfm</link>
	<dc:date>2008-06-19T18:01:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/New-Storm-Variant-Claiming-New-Earthquake-in-China.cfm">
	<title>New Storm Variant Claiming New Earthquake in China</title>
	<description>&lt;br /&gt;
Starting yesterday (June 18th) we began seeing evidence of a new Storm Worm variant claiming news of a new Earthquake in China.&amp;nbsp; &lt;br /&gt;
Some of the subject lines associated with these messages include:&lt;br /&gt;
&lt;br /&gt;
2008 Olympic Games are under the threat&lt;br /&gt;
A new powerful disaster in China&lt;br /&gt;
A new deadly catastrophe in China&lt;br /&gt;
China is paralyzed by new earthquake&lt;br /&gt;
China&apos;s most deadly earthquake&lt;br /&gt;
Chinese people are horrified by new earthquake&lt;br /&gt;
Countless victims of earthquake in China&lt;br /&gt;
Deadly catastrophe in Chinese capital&lt;br /&gt;
Death toll in China exceeds 1000000&lt;br /&gt;
Death toll in China is growing&lt;br /&gt;
Earth tremors in China is going on&lt;br /&gt;
Recent earthquake in china took a heavy toll&lt;br /&gt;
Recent china earthquake kills million&lt;br /&gt;
Terrible earthquake devastated Beijing&lt;br /&gt;
The capital of China were collapsed by earthquake&lt;br /&gt;
The most powerful quake hits China&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;
Toll mounts in China earthquake&lt;br /&gt;
Unprecedented earthquake in China&lt;br /&gt;
&lt;br /&gt;
This is a pretty typical tactic for Storm: ride on the wave of current events as a social engineering lure to get users to click on links in emails.&amp;nbsp; This variant is primarily targeting the Chinese earthquakes, but there is also a mention of the Beijing Olympics as well stating that the Olympics will be &amp;quot;under the threat.&amp;quot;&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
If a user clicks the link within one of these emails, they are not immediately infected with Storm.&amp;nbsp; They will be directed to a web site (all of the ones that we have seen so far have a .cn TLD) that looks like this:&lt;br /&gt;
&lt;br /&gt;
&lt;img src=&quot;../../../../itsecurityblog/1/custom/storm_china.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
It is important to note that this is not a real video player, but clicking the player will launch a file named beijing.exe which will infect your PC.&lt;br /&gt;
&lt;br /&gt;
Volume of this variant is pretty low.&amp;nbsp; We are currently seeing on the order of about 900 per hour in our Threat Operations Center.&amp;nbsp; Expect to see similar stories of this nature threatening the safety of the Olympics as well as its participants and visitors as the event gets closer.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/New-Storm-Variant-Claiming-New-Earthquake-in-China.cfm</link>
	<dc:date>2008-06-19T13:41:42-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/American-in-Heidelberg.cfm">
	<title>American in Heidelberg</title>
	<description>&lt;br /&gt;
Last week I had the privilege of attending the 13th General MAAWG Meeting in Heidelberg, Germany (I serve as the co-chair of the Zombie/Botnet Subcommittee with my friend Ken Simpson from Mailchannels).&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
The MAAWG conferences are a great opportunity to meet and talk with some of the best minds in the anti-spam industry, discuss anti-spam tactics, operational best practices (what works and what doesn&apos;t), how to be a responsible ESP, and many other topics.&amp;nbsp;&amp;nbsp; Although MAAWG is largely run by ISPs, its mission is to also bring together both email senders as well as email receivers in a collaborative environment where both sides can attempt to work out best practice solutions so that senders can achieve better deliverability rates at the large mailbox providers, a constant struggle for ESPs.&lt;br /&gt;
&lt;br /&gt;
If you are a messaging vendor or provider (and this includes both email filtering vendors as well as email senders) or an ISP, you are doing yourself a disservice by not becoming a member of an organization like MAAWG where ideas, practices and upcoming threats are shared that it is very likely you will not hear anywhere else.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
This has been an unpaid advertisement :)&lt;br /&gt;
&lt;br /&gt;
Before I close, I&apos;d be remiss if I didn&apos;t bring up something security related in this post.&amp;nbsp; So, I am standing in the security line at Denver International Airport about to go through the metal detector when the guy who was working behind the conveyor belt asks me and the woman behind me the standard &amp;quot;Any liquids, gels, or aerosols in your bag?&amp;quot; before our bags went into the X-Ray machine.&amp;nbsp; I just look at him and say &amp;quot;No&amp;quot;, but the woman behind me responds with &amp;quot;Not that I know of.&amp;quot;&amp;nbsp; Apparently this set off the ire of the TSA worker who immediately responded with &amp;quot;Not that you know of?!&amp;nbsp; Don&apos;t you know what is packed in your bags, ma&apos;am?&amp;quot;&amp;nbsp; I&apos;d never seen a TSA worker move so fast, but her bags were immediately yanked off of the conveyor, she was pulled out of line, and then was escorted by 2 TSA workers to wherever they take you likely to inspect every minute crevice of her bag.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
For all of the flack that the TSA gets for either bad procedures or lack of attention to detail, you would think that as a traveler it is also our responsibility to know the basic responses to the simple questions security officers may ask you.&amp;nbsp; The questions are neither tricky nor confusing.&amp;nbsp; I guess this woman had to learn the hard way...&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/American-in-Heidelberg.cfm</link>
	<dc:date>2008-06-18T10:44:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/While-on-the-Topic-of-Google-Spam.cfm">
	<title>While on the Topic of Google Spam...</title>
	<description>&lt;br /&gt;
I wonder if the folks over at Google got the message that service providers had finally had enough of dealing with the backscatter that was coming out of their mail servers because it has also significantly dropped off since we &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/04/First-Google-now-Hotmail.cfm&quot;&gt;first started talking about it&lt;/a&gt; back in April.&amp;nbsp; Backscatter (bounce messages attempting to be delivered to users that do not exist) rates from Google were over 50% on some days.&amp;nbsp; This means that over 50% of the total mail that we were receiving from Google were these invalid bounces.&amp;nbsp; The backscatter rate has dropped now to about 2% of the total mail from Google.&amp;nbsp; That is still higher than what most would call acceptable, but when you are comparing over 500k messages per day to about 10-15k, I would say that is a significant improvement no matter how you slice it.&lt;br /&gt;
&lt;br /&gt;
Unfortunately, though the problem has shifted from backscatter to 419 phishing scams.&amp;nbsp; A 419 phishing scam is the advance fee fraud type of scam where for a small amount of money you can be promised to receive much more in return.&amp;nbsp; 419 scams are also typically called Nigerian Scams.&amp;nbsp; The term 419 comes from the Nigerian Criminal Code that deals with fraud.&lt;br /&gt;
&lt;br /&gt;
Although still about 25% of the email that we get from Google&apos;s network is spam, the traffic has shifted from about 50% backscatter to about 50% phishing, in particular from IP addresses that start with 72.14.204, 72.14.214, and 72.14.246.&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
This is certainly not intended to single out Google either as they are not the only free webmail provider that we see enormous amounts of spam from.&amp;nbsp; We see plenty from Yahoo and Hotmail as well.&amp;nbsp; Google is the main provider on everyone&apos;s radar right now because of the quickly changing nature of attacks against their system and the rapidly changing view across many different industries of the viability of using Google as their business mail host.&amp;nbsp; More and more legitimate businesses are having trouble sending email from their hosted GMail accounts to service providers because Google&apos;s mail servers are ending up on block lists with increasing regularity, a trend that is only gaining momentum amongst industry insiders.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/While-on-the-Topic-of-Google-Spam.cfm</link>
	<dc:date>2008-06-05T13:54:19-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/06/Where-Has-All-of-the-Google-Spam-Gone.cfm">
	<title>Where Has All of the Google Spam Gone?</title>
	<description>&lt;br /&gt;
Since February we have made several mentions of Google Spam and its migration from benign redirects to Canadian Pharmacy sites to malware distribution &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/04/Malicious-Google-Spam-Alleging-News-Video-from-Bin-Laden.cfm&quot;&gt;fake Osama bin Laden videos&lt;/a&gt;.&amp;nbsp; We also saw a &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/04/Rock-on-with-the-Storm-Worm.cfm&quot;&gt;Storm Worm campaign&lt;/a&gt; which alleged to be a video codec that used this same technique.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Since February Google spam had accounted for anywhere between 1-5% of total spam volume, but over the past couple of weeks has all but completely disappeared.&lt;br /&gt;
&lt;br /&gt;
Where did it go?&lt;br /&gt;
&lt;br /&gt;
It seems to have migrated over to &lt;a href=&quot;http://skydrive.live.com/&quot;&gt;Microsoft&apos;s Live SkyDrive&lt;/a&gt; service.&amp;nbsp; If you are not familiar with SkyDrive, it is a document hosting service being launched by Microsoft, similar to &lt;a href=&quot;http://docs.google.com/&quot;&gt;Google Docs&lt;/a&gt;.&amp;nbsp; &lt;br /&gt;
Here is the basic premise on how this tactic works:&lt;br /&gt;
&lt;br /&gt;
-- Email is received with a link to a document hosted on the SkyDrive service with some sort of social engineering lure as bait.&amp;nbsp; The format of the URL is http://hostname.bay.livefilestore.com/..$very_long_hash_value&amp;hellip;/$filename.html (where the hash is some calculated value and $file.html is the name of the hosted file)&lt;br /&gt;
&lt;br /&gt;
-- User clicks the link to file hosted on SkyDrive, which in this case is an HTML file that contains a JavaScript redirect to a pharmacy website&lt;br /&gt;
&lt;br /&gt;
-- Redirected web site is displayed in the user&apos;s browser and any background code executed which could include the drive-by injection of malware just as we saw with Google Spam.&lt;br /&gt;
&lt;br /&gt;
The HTML file being hosted on SkyDrive is a simple, one line script :&lt;br /&gt;
&lt;br /&gt;
&amp;lt;html&amp;gt;&amp;lt;script language=JavaScript&amp;gt;window.location.replace(&amp;quot;hxxp://songkhlong.com&amp;quot;)&amp;lt;/script&amp;gt;&amp;lt;/html&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Currently, SkyDrive Spam is accounting for a little over 1% of the total spam that we are seeing in our Threat Operations Center which means that it is currently as prevalent as both phishing and gambling spam.&amp;nbsp; I don&apos;t believe that we have seen the last of Google spam, but focus definitely appears to have moved toward Microsoft for the time being.&lt;br /&gt;
&lt;br /&gt;
As a side note, &lt;a href=&quot;http://www.avertlabs.com/research/blog/index.php/2008/01/08/microsofts-skydrive-beta-abused-by-spammers/&quot;&gt;McAfee originally reported&lt;/a&gt; seeing large influxes of SkyDrive Spam back in January so SkyDrive spam isn&apos;t a new tactic, however it has dramatically increased in prevalence since the dropoff of Google Spam about 2 weeks ago.&lt;br /&gt;
&lt;br /&gt;
*** UPDATE 6/5/2008 4:50pm MDT *** - It appears that Google Docs is also being targeted by this tactic.&amp;nbsp; I just came across the below message (note the link at the bottom) from one of our spamtraps which hit our system yesterday (the hosted doc appears to have been taken offline by the time of this update):&lt;br /&gt;
&lt;br /&gt;
Hi fellow&lt;br /&gt;
&lt;br /&gt;
Is the Rising Cost of Prescrlption Drugsare cause of concern?&lt;br /&gt;
&lt;br /&gt;
The rising cost of Prescrlption drugs may be costing you your health.&lt;br /&gt;
In particular, living on a fixedincome.&lt;br /&gt;
&lt;br /&gt;
You can cut your Medicalbilling.&lt;br /&gt;
&lt;br /&gt;
Simple Way to Cut Your Prescrlption Costs optfor Generic.&lt;br /&gt;
&lt;br /&gt;
Genericpharmacy: A Cheaper Effective Alternative&lt;br /&gt;
&lt;br /&gt;
Forget about huge spendings You can save upto 8O%&lt;br /&gt;
&lt;br /&gt;
Hugesaving because the solutions is directly from manufacturer.&lt;br /&gt;
&lt;br /&gt;
hxxp://docs.google.com/View?docid=3Dddsz3hdh_0wwwmrbm3&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/06/Where-Has-All-of-the-Google-Spam-Gone.cfm</link>
	<dc:date>2008-06-05T11:15:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Poorly-Crafted-Fake-CNN-News-Updates.cfm">
	<title>Poorly Crafted Fake CNN News Updates</title>
	<description>&lt;br /&gt;
As I was going through one of our spamtraps a few minutes ago I saw a brand new message come in which claimed to be a CNN News Update.&amp;nbsp; This was especially interesting to me because none of our spamtraps subscribe to any updates from CNN (or any other news organization for that matter).&lt;br /&gt;
&lt;br /&gt;
&lt;img src=&quot;../../../../itsecurityblog/1/custom/cnn.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
So I started to do a little digging....&lt;br /&gt;
&lt;br /&gt;
Below are the (somewhat elided) headers:&lt;br /&gt;
&lt;br /&gt;
Received: from unknown [219.87.137.170] (EHLO mail.tfmi.com.tw)&amp;nbsp;&amp;nbsp;&amp;nbsp; by&lt;br /&gt;
&amp;nbsp;XXXXXXXXXXXXX (XXXXXXXXXX) over TLS secured channel&amp;nbsp;&amp;nbsp;&amp;nbsp; with ESMTP&lt;br /&gt;
&amp;nbsp;id XXXXXXXXXXXXXXXXXXXXXXXXXX (envelope-from&lt;br /&gt;
&amp;nbsp;&amp;lt;news@cnn.com&amp;gt;);&amp;nbsp;&amp;nbsp;&amp;nbsp; Wed, 28 May 2008 11:32:13 -0600 (MDT)&lt;br /&gt;
&lt;br /&gt;
Received: from User (dsl-KK-static-static-237.201.95.61.airtelbroadband.in&lt;br /&gt;
&amp;nbsp;[61.95.201.237] (may be forged))&amp;nbsp;&amp;nbsp;&amp;nbsp; (authenticated bits=0)&amp;nbsp;&amp;nbsp;&amp;nbsp; by mail.tfmi.com.tw&lt;br /&gt;
&amp;nbsp;(8.12.5/8.12.8) with ESMTP id m4SHTkxC005178;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thu, 29 May 2008 01:29:49 +0800&lt;br /&gt;
&lt;br /&gt;
If you are not sure how to read email message headers, here is basically how this message breaks down:&amp;nbsp; It originated from a static DSL customer in India (dsl-KK-static-static-237.201.95.61.airtelbroadband.in) and routed through Taiwan (mail.tfmi.com.tw), then sent to our spamtrap.&lt;br /&gt;
&lt;br /&gt;
Whoever is sending these spam messages either doesn&apos;t know what they are doing or is testing the waters for an upcoming spam/malware run.&amp;nbsp; Here&apos;s why:&lt;br /&gt;
&lt;br /&gt;
When I opened this message in an email client, the HTML within the message never attempted to render.&amp;nbsp; Why?&amp;nbsp; Because the content type of the message was set in the message header as plain text.&amp;nbsp; This means that the email client should not attempt to render the HTML (show it as it would appear on a web page) rather display the raw HTML text to the user.&amp;nbsp; Only the truly geeky, like me, would take the time to actually analyze this gibberish.&lt;br /&gt;
&lt;br /&gt;
Also, the email had every link within the message (including the help text at the bottom of the message which is supposed to link to the CNN web site) pointed to a web site hosted in Italy.&amp;nbsp; Here is an example taken directly from the email:&lt;br /&gt;
&lt;br /&gt;
For assistance, go to &amp;lt;a href=&amp;quot;hxxp://www.colectionarul.com/existenz1.html&amp;quot;&amp;gt;CNN web page&amp;lt;/a&amp;gt; and choose the &amp;quot;Help&amp;quot; link on any page.&amp;lt;br&amp;gt;&amp;nbsp; If you do not want to recive any more news from CNN &amp;lt;a href=&amp;quot;hxxp://www.colectionarul.com/existenz1.html&amp;quot;&amp;gt;click here&amp;lt;/a&amp;gt;!&amp;lt;/span&amp;gt;&amp;lt;/font&amp;gt; &amp;lt;font color=&amp;quot;#808080&amp;quot; face=&amp;quot;Arial&amp;quot;&amp;gt;&amp;lt;/font&amp;gt;&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There doesn&apos;t appear to be anything malicious on the page being linked to at colectionarul.com (at least right now), which leads me to believe that this was either someone who didn&apos;t know what they were doing and thus sent out a horribly broken spam message or someone who was doing a test run and that this was a prelude to more current event based social engineering tactics similar to what started the huge Storm Worm outbreaks in January 2007.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Poorly-Crafted-Fake-CNN-News-Updates.cfm</link>
	<dc:date>2008-05-28T12:06:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/New-Kind-of-Phish-Dead-Phish.cfm">
	<title>New Kind of Phish: Dead Phish!</title>
	<description>&lt;br /&gt;
Thanks to James in our Threat Operations Center for forwarding me a sample of one of the funnier phishing tactics that I have come across.&amp;nbsp; I thought an appropriate name for this type of scam would be &amp;quot;Dead Phish.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Here is a copy of the email (in all it unedited glory filled with spelling and grammatical errors):&lt;br /&gt;
&lt;br /&gt;
Dear Sir,&lt;br /&gt;
&lt;br /&gt;
We are in receipt of a Death Certificate certifying you dead and seeking the transfer of your over due contract funds to an Account in London.&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
All the local financial contractural obligations have been met and the funds is ready for transfer to the London account.&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
Please understand that if we do not hear from you in the next 7 days we shall treat you as dead and the funds shall be duly transferred.&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
You have been notified.&lt;br /&gt;
&lt;br /&gt;
If this is false please write and let us have an affidevid to counter &lt;br /&gt;
this claims. &lt;br /&gt;
&lt;br /&gt;
Yours faithfullly,&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
Mrs.callister Ibe&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
Chairman of Contract Review Panel&lt;br /&gt;
&lt;br /&gt;
Phone:234-805-6135520.&lt;br /&gt;
&lt;br /&gt;
This is another phish by phone tactic similar to what I have &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/03/New-IRS-Refund-Scam-with-a-Vishing-Twist.cfm&quot;&gt;blogged about previously&lt;/a&gt; where the scammers are avoiding using web site links within their messages in an attempt to get by URL filters and built-in browser phishing detection.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
My favorite part is where it says &amp;quot;You have been notified.&amp;quot;&amp;nbsp; What if I were actually dead?&amp;nbsp; It&apos;s true that you can get your email just about anywhere nowadays, but I never knew that also extended to beyond the grave!&amp;nbsp; This was a good way to start the post-holiday work week.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/New-Kind-of-Phish-Dead-Phish.cfm</link>
	<dc:date>2008-05-27T10:18:56-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/New-Chinese-Earthquake-Relief-Phishing-Scam.cfm">
	<title>New Chinese Earthquake Relief Phishing Scam</title>
	<description>&lt;br /&gt;
Sometimes the depths to which spammers will stoop really sickens me.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Even in today&apos;s criminally infested internet I sometimes naively hope that there is still some kind of Code of Conduct where trying to capitalize off of certain catastrophic events was considered taboo.&amp;nbsp; As we&apos;ve seen before, such as with the devastation caused by Hurricane Katrina back in 2005, the Indian tsunami in 2004, and now with the earthquake and aftershocks that have already killed over 28,000 people in southwest China&apos;s Sichuan province (with estimates that the death toll will be over 50,000 before the final counts are tallied) over the past week and a half, scams looking to tug at both your heart strings and purse strings have started popping up.&lt;br /&gt;
I&apos;ll abbreviate the message that we received for the sake of brevity (it&apos;s about the longest phish I have ever seen) as it gives a fairly detailed account of the plight of the person allegedly sending the message:&lt;br /&gt;
&lt;br /&gt;
&lt;font size=&quot;2&quot; face=&quot;Arial&quot;&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;Dear  friend,&lt;br /&gt;
&lt;br /&gt;
I don&apos;t know your exact name. I can only guess.&lt;br /&gt;
&lt;br /&gt;
I ask you  to read my letter up to the end. After that you will be in the right to send my  letter in a garbage basket or.......&lt;br /&gt;
&lt;br /&gt;
My letter is caused by despair. I  don&apos;t know to whom to address. I am compelled to ask for help any person. Namely  you. I hope that mine letter has got to the person which has sympathy and  compassion. I wish to trust in it.&lt;br /&gt;
&lt;br /&gt;
My name is Arnulfo. My situation  plunges me into depression and despair.&lt;br /&gt;
&lt;br /&gt;
I will tell you shortly. I do not  even know how to express correctly my thoughts. How to write you about it. I can  tell with confidence that my hands shiver when I press on the buttons of the  keyboard. Several days ago I could not think that I shall address to the  stranger with such situation. Probably it&apos;s stupid or incorrectly. But it&apos;s the  only thing that is left to do. I just ask to understand me. I even must&amp;nbsp; say  that it is a shame to do it.&lt;br /&gt;
&lt;br /&gt;
I will continue. I don&apos;t know where you are.  And I do not know what news you watched on TV or listened by Radio. I think that  you could hear about Earthquake in &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt;. My God, it&apos;s  awful...&lt;br /&gt;
&lt;br /&gt;
Me and my wife have flied to the country of &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Philippines&lt;/st1:place&gt;&lt;/st1:country-region&gt; two  weeks ago. We wanted to search for a new place in this world, where we could  create our new world. There where we&lt;br /&gt;
could live and create good family. We  have got married a year ago. The matter is that my wife is a chinese woman, and  I was born on &lt;st1:country-region w:st=&quot;on&quot;&gt;Philippines&lt;/st1:country-region&gt;,  but has grown in &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Spain&lt;/st1:place&gt;&lt;/st1:country-region&gt;. My father is Spaniard, and my  mum is Philippine. My parents have died several years ago. I have left to study  in the university to another country. I studied Chinese&lt;br /&gt;
language and culture.  There I also have got acquainted with Jin It&apos;s my wife. We have got married. And  yes, we were happy. I will tell - We are happy together. But parents of Jin were  against our marriage. And we have decided to search a place which will make us  happy. We thought of &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Philippines&lt;/st1:place&gt;&lt;/st1:country-region&gt;.&lt;br /&gt;
&lt;br /&gt;
All. Everything  was good. Yes, everything was simply magnificent. Until the first impact has  happened. We have heardabout it in the news. I do not want to describe that  occured with Jin when she has heard about that her native city was completely  destroyed. Her native city has been destroyed. Me and Jin were in panic. We have  decided at once to come back to &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; to my wife&apos;s parents. Jin was  in despair.&lt;br /&gt;
&lt;br /&gt;
But the destiny has made a new turn. We had no money for air  flight to &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; for two. We had money. We have  made money transfer to the bank account in &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Philippines&lt;/st1:place&gt;&lt;/st1:country-region&gt; for  purchase of a small house. But I can receive this money only on the 1st of June.  Not earlier. Bank bureaucracy exists all over the world. We did not know what to  do. Then we have found only one output. We have received all money which were on  our ATM-cart. Me collected the sum of money for air flight only for my wife. It  was a hard moment in our life. But then I did not know that the worst will be  ahead. We have solved that my wife will go to &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; alone. It  was a difficult decisions for me. But I could not stop Jin. And I could not fly  together with her. Jin has quickly gathered and has departed. When she left  tears flew on our cheeks . I do not know how to explain that I felt during this  moment. But I understood that my wife felt. Mine Jin. Her parents were in  trouble. I have remained alone not having money. My hotel accommodation has been  paid for some days.&lt;br /&gt;
&lt;/span&gt;&lt;/font&gt;&lt;font face=&quot;Arial&quot;&gt;&lt;br /&gt;
[ SEVERAL UNIMPORTANT PARAGRAPHS REMOVED ]&lt;br /&gt;
&lt;br /&gt;
Also some kind people which know about my situation have helped me. I shall have  the small sum of money. But a greater sum of money is required . I am lack of  1500$. I have no opportunity to find such sum of money. I tried all ways to find  th&amp;oacute; money. I do not wish to think that money solve everything in this world. I  believe that the main thing is people and love. And I want to believe that I  will be able to be beside my Jin soon . We are sure will be happy  together.&lt;br /&gt;
&lt;br /&gt;
Only despair has compelled me to write you this letter.  Probably it sounds silly. You have a right to think about me all that you want.  I shall understand you.I I address to you for a help. Your help is required to  me. I will tell directly that I ask you to help me with money. I will return you  money&lt;br /&gt;
later, right after as soon as I receive my money which are in the bank.  I can return to you money on the first of June. I shall see the wife. I shall be  with her. I can take care of her. After that I will return on  &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Philippines&lt;/st1:place&gt;&lt;/st1:country-region&gt; to take back money. And I  will return to you even more Money. I only ask to help me now.I have been  explained that I will be able to receive money in &lt;st1:place w:st=&quot;on&quot;&gt;Western  Union&lt;/st1:place&gt;. And I shall return the money to you in the same way. I am  ready to return you more.&lt;br /&gt;
&lt;br /&gt;
I will hope that my letter will not offend you  because we are unfamiliar. I do not even know your name. I have taken yours  e-mail from Internet. And I have hope that e-mail to which I write is of a good  person.&lt;br /&gt;
&lt;br /&gt;
I will understand you in any case. Iask to excuse me . I only  want you to understood me. Only despair and love have compelled me to write this  letter to you. I wish to use all variants To be near to my love.&lt;br /&gt;
&lt;br /&gt;
And  still, if you will be able to help me I shall consider you to be the best man in  this world. You will save a life of mine Jin. I shall write the data on which I  will be able to receive cashes in &lt;st1:country-region w:st=&quot;on&quot;&gt;Philippines&lt;/st1:country-region&gt; through &lt;st1:place w:st=&quot;on&quot;&gt;Western  Union&lt;/st1:place&gt;.&lt;br /&gt;
&lt;br /&gt;
I don&apos;t know what to tell you more . I believe in love  and destiny. I ask you to answer me to this  e-mail:&lt;br /&gt;
&lt;br /&gt;
arnulfoqramos@yahoo.com.ph&lt;br /&gt;
&lt;br /&gt;
I have registered it right now.  I shall wait fo your answer to this e-mail. If you want to answer  me&lt;br /&gt;
&lt;br /&gt;
Yours faithfully Arnulfo&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The words that I want to use to describe people who would try to capitalize on an event that has affected hundreds of thousands of people aren&apos;t appropriate for corporate blog nor for any other conversation for that matter.&amp;nbsp; Every time I see these types of things, it further lowers my faith in humanity.&lt;br /&gt;
&lt;br /&gt;
Please be on the lookout for this and other related scams over the coming weeks as we are sure to see more of them, likely alleging to be from relief organizations and/or companies who claim to be affiliated with them.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
If you wish to make a donation to your favorite relief organization to help them to provide assistance to people around the world being affected by these horrific natural disasters please contact them directly.&amp;nbsp; Do not respond to solicitations via email, even if they look legitimate or come from an email address that potentially looks legitimate.&lt;br /&gt;
&lt;/font&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*** UPDATE 5/21/2008 11:20am MDT ***&amp;nbsp; Here are some of the subject lines that we are seeing associated with this scam:&lt;br /&gt;
&lt;br /&gt;
-- Help me&lt;br /&gt;
-- Help me please. Read through the letter&lt;br /&gt;
-- Last hope. Help me please&lt;br /&gt;
-- I ask to help. Please&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;font size=&quot;2&quot;&gt;&lt;font face=&quot;Tahoma&quot;&gt;&lt;/font&gt;&lt;/font&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/New-Chinese-Earthquake-Relief-Phishing-Scam.cfm</link>
	<dc:date>2008-05-21T11:13:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Rootkit-Written-Targeting-Cisco-Routers.cfm">
	<title>Rootkit Written Targeting Cisco Routers</title>
	<description>&lt;br /&gt;
According to &lt;a href=&quot;http://csoonline.com/article/357963?source=nlt_csonewswatch&quot;&gt;this article&lt;/a&gt; posted on CSO Online, a security researcher named Sebastian Muniz has created a rootkit that will work on &amp;quot;several different versions of IOS.&amp;quot;&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
One of the concepts that I have been throwing out there since we originally started &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/02/2008-Off-to-a-Fast-Start.cfm&quot;&gt;talking about drive-by pharming&lt;/a&gt; (aka DNS Rebinding attack) is the potential of similar vulnerabilities being exploited in an effort to move malware infections out closer to the network edge and create a &amp;quot;router bot&amp;quot; whereby a compromised router could potentially be used for the distribution of spam, viruses, and malware similar to how PCs are used today.&amp;nbsp; This would be even more difficult to detect than a PC based malware infection, however as I do not believe that there are any network device based rootkit/malware detection engines that even exist right now (please do correct me if I am wrong here) although this may certainly create a market for them.&amp;nbsp; Would you be able to easily detect if your router was being used to distribute spam if it wasn&apos;t affecting your web browsing or normal internet usage?&amp;nbsp; Not likely.&lt;br /&gt;
&lt;br /&gt;
One of the things that concerned me from the article was the quote from EuSecWest conference organizer Dragos Ruiu where he said that &amp;quot;nobody thought you could actually build exploits for Cisco.&amp;quot;&amp;nbsp; This is a dangerous attitude to have for any software application.&amp;nbsp; I like to say &amp;quot;Where there is software, there are vulnerabilities.&amp;quot;&amp;nbsp; This is often followed by &amp;quot;Where there are vulnerabilities, there are exploits&amp;quot; although far more vulnerabilities exist than there are exploits written for them.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
One should never assume that software is hacker-proof.&amp;nbsp; It very well may be (however unlikely), but even making the assumption or suggestion is when you&apos;ve conceded that your guard has been let down.&amp;nbsp; Always remain diligent in your pursuit of security!&lt;br /&gt;
&lt;br /&gt;
Ok, I&apos;ll step off my soapbox now.&amp;nbsp; Have a great weekend!&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Rootkit-Written-Targeting-Cisco-Routers.cfm</link>
	<dc:date>2008-05-16T13:42:45-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Cell-Phone-Spam-Becoming-More-Invasive.cfm">
	<title>Cell Phone Spam Becoming More Invasive</title>
	<description>&lt;br /&gt;
I wanted to take a moment to respond to the &lt;a href=&quot;http://www.nytimes.com/2008/05/10/technology/10spam.html?em&amp;amp;ex=1210651200&amp;amp;en=706ed2f092bb1811&amp;amp;ei=5087%0A&quot;&gt;New York Times article&lt;/a&gt; that appeared on their website on May 10th with respect to mobile phone spam.&lt;br /&gt;
&lt;br /&gt;
Largely up to this point the United States has missed the boat as it relates to mobile phone spam.&amp;nbsp; This is largely because the problem pales in comparison in the US to the rest of the world.&amp;nbsp; When it is more of an issue here, however it will definitely become more problematic for consumers.&amp;nbsp; In the United States your cell phone number very much becomes tied to your identity.&amp;nbsp; If you change your cell phone number it is a real pain to have to make sure you notify everyone in your contact list (family members, friends, colleagues, etc) that you can no longer be reached at your old number.&amp;nbsp; This combined with cell phone number portability that was introduced a few years ago makes it simple to even switch carriers and keep your number, which hadn&apos;t previously been possible.&amp;nbsp; In some other countries, like Japan where mobile spam is a huge problem, cell phone numbers are throwaway.&amp;nbsp; When the Japanese start getting spam on their cell phone, they change numbers until the new number starts getting spammed.&amp;nbsp; Rinse and repeat.&lt;br /&gt;
&lt;br /&gt;
In the United States there has mostly been a wait and see mentality as it relates to mobile spam, but few who have gotten spam on their mobile phone would disagree that it isn&apos;t an issue that needs to be addressed.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Let&apos;s look at it from the carrier&apos;s perspective first though.&amp;nbsp; The article states that &amp;quot;Communications companies say they are not interested in spam as a profit center.&amp;quot;&amp;nbsp; I would say that &amp;quot;publicly&amp;quot; this is true, but if you look at it from a sheer numbers perspective, they carrier&apos;s are already making big money as a result of mobile spam.&amp;nbsp; Let&apos;s use the following statement from the article: &amp;quot;getting as few as 10 unsolicited text messages a month at 20 cents each would cost an extra $24 a year&amp;quot;.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Here is where the numbers game really kicks in.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
If you assume 10 unsolicited text messages per month (which is a lot in my opinion!) this equates to $2 per month (using their pricing model).&amp;nbsp; Surely some people will wait on the phone on principle alone in order to fight this additional $2 charge on their bill every month, however many will say that the long telephone waits in order to fight the charge and get it removed is simply not a productive use of their time and will leave it alone.&amp;nbsp; This, of course, begs the question what the breaking point is?&amp;nbsp; At what point do the lines cross whereby it is an efficient use of time to fight the charge.&amp;nbsp; The answer to that question will lie with each individual consumer.&lt;br /&gt;
&lt;br /&gt;
Where was I?&amp;nbsp; Oh, yes!&amp;nbsp; Security!&lt;br /&gt;
&lt;br /&gt;
The article mentions that &amp;quot;The carriers regularly adjust spam filters to block offending messages. At Sprint, more than 65 percent of all text messages sent over its network are identified and blocked as spam before they reach customers.&amp;quot;&amp;nbsp; Spammers are aware that spam filtering for SMS spam is still not very mature.&amp;nbsp; As such, it is a target that is more easily exploited than spam over email.&amp;nbsp; To look at this as a cynic, is this also something that cell phone companies are putting considerable money towards stopping considering the amount of revenue being generated?&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
I as well as many others across the security industry have been predicting the wider scale movement of spam to mobile devices for the past couple of years now and have also discussed how much easier that movement is becoming due to the inbox and the personal computer becoming a lot more mobile.&amp;nbsp; I wouldn&apos;t yet say that we have turned the corner as it relates to mobile spam nor would I say that we are on the verge of an epic increase, but the problem definitely continues to grow as the filtering technology lags behind.&amp;nbsp; Mobile malware continues to grow also, albeit not nearly at the same rate as personal computer based malware. &amp;nbsp; Now that most phones are coming with internet access, however the protections on those devices need to be at least on par with what is being provided for PCs.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Cell-Phone-Spam-Becoming-More-Invasive.cfm</link>
	<dc:date>2008-05-12T12:35:30-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Whaling-Scam-from-the-US-Tax-Court.cfm">
	<title>Whaling Scam from the US Tax Court</title>
	<description>&lt;br /&gt;
Please be on the lookout for yet another government agency tax scam making the rounds today; this one not spoofing the IRS, but rather the US Tax Court.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Here is an elided sample that has been received by our Threat Operations Center:&lt;br /&gt;
&lt;br /&gt;
&lt;table width=&quot;70%&quot; cellspacing=&quot;0&quot; cellpading=&quot;0&quot;&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;td width=&quot;70%&quot; align=&quot;left&quot;&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;UNITED STATES TAX  COURT&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;WASHINGTON, DC  20217&lt;/strong&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td colspan=&quot;2&quot;&gt;
            &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-family: Courier;&quot;&gt;Docket No. 622-555. Filed  May, 2008.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;COMMISSIONER OF INTERNAL  REVENUE&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;em style=&quot;&quot;&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;Petitioner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;  &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;br /&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;span style=&quot;&quot;&gt;v.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;br /&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;EXECUTIVE NAME HERE&lt;br /&gt;
            COMPANY NAME HERE&lt;br /&gt;
            COMPANY PHONE NUMBER HERE&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;em style=&quot;&quot;&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;Respondent.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;  &lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;br /&gt;
            &lt;br /&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;&lt;span style=&quot;&quot;&gt;&amp;nbsp;  &lt;/span&gt;PETITION &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;The Petitioner hereby petitions  for a redetermination of forth by the Commissioner of Internal Revenue in his  notice of deficiency (AP:FE:BOS:JHK) dated May 4,  2008&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;br /&gt;
            &lt;br /&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;&lt;strong&gt;&lt;em&gt;&lt;span style=&quot;font-family: Times;&quot;&gt;&lt;a title=&quot;http://www.us-tax.org/ViewCase.php?nr=622-555&quot; href=&quot;http://www.us-taxxxxxxxxxxx.org/ViewCase.php?nr=622-555&quot;&gt;Please download a Copy of  the Order, Letter, Notice or Other Document Being  Appealed&lt;/a&gt;&lt;/span&gt;&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
            &lt;br /&gt;
            &lt;br /&gt;
            &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0pt; line-height: normal;&quot;&gt;This matter  is before the Court on respondent.s Motion for Summary Judgment, filed May 10,  2006, and respondent.s Motion for Penalty under I.R.C. Section 6673, also filed  May 10, 2006.&amp;nbsp; As motions, without prejudice, and remand this case to  respondent.s Office of Appeals.&lt;span style=&quot;font-size: 12pt; font-family: Courier;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;br /&gt;
            &lt;br /&gt;
            &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-size: 5px; font-family: Courier;&quot;&gt;&lt;strong&gt;Respectfully  submitted,&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-family: Courier;&quot;&gt;&lt;em&gt;&lt;strong&gt;Bennett H.  Klein&lt;/strong&gt;&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-family: Courier;&quot;&gt;&lt;em&gt;Tax Court Bar No  KB0214&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-family: Courier;&quot;&gt;&lt;em&gt;400 Second Street,  N.W.,&lt;br /&gt;
            Washington, D.C. 20217.&lt;br /&gt;
            &lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;
&lt;br /&gt;
The link in above sample goes to a web page hosted at the domain us-tax.org, which was just registered 4 days ago, May 8th.&amp;nbsp; Based on the format of the scam URL in the above message this looks very much like some of the other recent executive targeted scams (like the &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/04/New-Government-Phish--This-Time-Targeting-the-US-District-Court.cfm&quot;&gt;US District Court scam&lt;/a&gt; that I also blogged about) that we have seen lately.&amp;nbsp; It would not surprise me if the same people behind those scams are also originating from the same group of people.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*** UPDATE 5/12/2008 12:40pm MDT *** We are currently seeing these whaling scams hit our systems at the rate of about 150 per hour.&amp;nbsp; Very low volumes in an attempt to fly under the radar as much as possible.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Whaling-Scam-from-the-US-Tax-Court.cfm</link>
	<dc:date>2008-05-12T10:24:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/The-Google-Calendar-Spam-Dilemma.cfm">
	<title>The Google Calendar Spam Dilemma</title>
	<description>&lt;br /&gt;
There have been more and more complaints popping up on the internet lately in relation to a new type of spam: Calendar Spam.&amp;nbsp; Calendar Spam introduces some new annoyances and some potential tricky pitfalls that we are used to seeing from typical spam.&lt;br /&gt;
&lt;br /&gt;
Since the announcement of the Google CAPTCHA compromise and the influx of spam and blowback that has been eminating out of the Google network since, it is clear that there is no easy solution to this problem from Google&apos;s standpoint (I am giving them the benefit of the doubt that more is being done on the backend than their claims that they are shutting accounts down as quickly as they can, which is clearly a futile effort).&amp;nbsp;&amp;nbsp; Now spammers have started also abusing the Google system to send out spam calendar invites.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
One might say: Calendar invites are no more intrusive than spam.&amp;nbsp; I can easily delete them from my inbox just like any other message.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
True, except the default behavior of the Google Calendar (and of the Outlook calendar, actually) is to automatically display events that you have been invited to in your calendar, even if you have not responded to them.&amp;nbsp; So, what this means is that if the spammy calendar event was sent to you with a reminder (which they all are), then you will still receive the reminder notification even if you deleted the original invite from your mailbox.&lt;br /&gt;
&lt;br /&gt;
So, what to do?&amp;nbsp; Should you decline these events?&amp;nbsp; Doing so and sending a notification back to the original sender is essentially a validation of your email address which will open the floodgates for more spam.&amp;nbsp; Ignoring it obviously doesn&apos;t yield the desired result either as we just discussed.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
In fairness, Google does provide &lt;a href=&quot;http://groups.google.com/group/google-calendar-help-misc/browse_thread/thread/18742b9ef209c472/e8ff376635545fc7&quot;&gt;some guidance&lt;/a&gt; on how to prevent Calendar Spam, which essentially involves not auto-adding events to your calendar.&amp;nbsp; A nice work around, but certainly not a &amp;quot;fix&amp;quot; in my opinion.&amp;nbsp;&amp;nbsp; This is an important calendaring feature, which is why many of the widely used calendars support it.&amp;nbsp; Simply turning it off because you are receiving spam calendar invites is merely an inconvenient band-aid.&lt;br /&gt;
&lt;br /&gt;
I&apos;ve also seen some people say &amp;quot;Google signs their mail with DKIM.&amp;nbsp; Shouldn&apos;t that help?&amp;quot;&amp;nbsp; Neither DKIM nor Sender ID Framework do anything to determine the reputation of the sender nor does it make any positive or negative determination as to the content of the message.&amp;nbsp; They only help to determine whether or not the message was spoofed or forged.&amp;nbsp; In this case, since the message is originating through Google&apos;s own servers, it will pass any kind of authentication mechanism.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
This goes back to the age old discussion that we have had many times in that spammers will latch onto any type of technology they can get their hands on and will use and abuse it in every way possible (many times in ways you and I never even thought they could be abused!). &lt;br /&gt;
&lt;br /&gt;
Clearly Google&apos;s problems are running deeper and deeper by the day.&amp;nbsp; New vulnerabilities and abuses of their services are being unconvered on a seemingly daily basis.&amp;nbsp; More and more service providers are starting to block communications from Google as a result which will start to make them a less viable option for users and businesses alike which will cut into Google&apos;s top and bottom lines.&amp;nbsp; Google has some great tools and certainly are an innovation driven company.&amp;nbsp; Now if only their security would start to catch up to their innovation...&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/The-Google-Calendar-Spam-Dilemma.cfm</link>
	<dc:date>2008-05-12T09:52:31-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Google-AdWords-Phishing.cfm">
	<title>Google AdWords Phishing</title>
	<description>&lt;br /&gt;
The folks over at Trend Micro have a &lt;a href=&quot;http://blog.trendmicro.com/google-adwords-phishing/&quot;&gt;good write up&lt;/a&gt; on a new type of phishing scam that has started floating around over the last week or so: Google AdWords Phishing.&lt;br /&gt;
&lt;br /&gt;
It looks like the scammers are using the same general content in their phish with a couple of different variations on the subject line and the tagline that appears at the end of the message.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
The phishing link mentioned in Trend&apos;s blog points to a Chinese registered domain that appears to have been taken down as of the time of this posting, but being the resilient type that cyber criminals are they have started to send out a new spam run with links pointing a new domain (also Chinese registered): adwords.google.com.s0leo9.cn, which is currently still active.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Below is a screen shot of one of the phish examples that we saw hit one of our spamtraps (note where it is different between here and the screen shot posted on Trend&apos;s blog):&lt;br /&gt;
&lt;br /&gt;
&lt;img alt=&quot;&quot; src=&quot;../../../../itsecurityblog/1/custom/adwords_phish3.gif&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
From a volume standpoint these phishing attempts appear to be coming in waves.&amp;nbsp; For example, on Tuesday, May 6th our Threat Operations Center was seeing approximately 2,200 of these hitting our systems in the early morning hours up to about 7:00am.&amp;nbsp; After that it dropped off to about 2 per hour.&amp;nbsp; In the early morning hours of May 7th we were again seeing up to 550 per hour. &amp;nbsp;  &lt;br /&gt;
&lt;br /&gt;
This tactic won&apos;t resonate very well with most people as even though there are quite a few organizations out there who are using Google Adwords to promote their products on Google search result pages, the actual audience that this type of scam will make sense to is pretty limited. &lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Google-AdWords-Phishing.cfm</link>
	<dc:date>2008-05-07T13:49:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Peter-Gabriels-Web-Server-Stolen.cfm">
	<title>Peter Gabriel&apos;s Web Server Stolen</title>
	<description>&lt;br /&gt;
According to &lt;a href=&quot;http://en.wikipedia.org/wiki/Peter_gabriel&quot;&gt;Peter Gabriel&apos;s&lt;/a&gt; &lt;a href=&quot;http://www.petergabriel.com/&quot;&gt;web site&lt;/a&gt; sometime on Sunday Night or Monday Morning their web servers were stolen from their data center.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
I wonder if they broke in with a &lt;a href=&quot;http://www.allthelyrics.com/song/341089/&quot;&gt;Sledgehammer&lt;/a&gt;?&amp;nbsp; Or if they were &lt;a href=&quot;http://www.allthelyrics.com/lyrics/peter_gabriel/quiet_and_alone-lyrics-603342.html&quot;&gt;Quiet and Alone&lt;/a&gt;?&amp;nbsp; I wonder if the RIAA will sue the thieves for stealing music?&lt;br /&gt;
&lt;br /&gt;
Ok, enough jokes....&lt;br /&gt;
&lt;br /&gt;
Kind of makes you wonder how they got in....or does it?&amp;nbsp; I&apos;ve been speaking to several colleagues lately who either currently perform social engineering engagements or did them in previous lives and it is amazing to me the areas of buildings that they have been able to access and the confidential information that they have uncovered just by every day, common techniques that we all do: tailgating, acting like you misplaced your access badge, or just looking like you belong somewhere.&lt;br /&gt;
&lt;br /&gt;
Then once they were in the data center, how did they access the cabinet that the servers were in?&amp;nbsp; Many cabinets go from the floor to the ceiling or have safeguards in place to prevent the cabinet from being compromised from on top.&amp;nbsp; They should also have at minimum either a keylock or combination lock (or both), not to mention that the data center should also have security cameras covering every square inch of floor space.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
We talk about proofs of concept very frequently where the occurrence of one crime is a finger pointing towards the potential occurrence of something much more damaging.&amp;nbsp; This is definitely one of those types of crimes.&amp;nbsp; If it can happen at this data center, what is to say that this same thing couldn&apos;t happen at any number of others as well?&amp;nbsp; What security policies does your data center have?&amp;nbsp; How well do they follow them? &lt;br /&gt;
&lt;br /&gt;
We make a lot of assumptions with regards to the security of data centers, but all the technology controls in the world don&apos;t make a bit of difference if they can easily be bypassed.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Peter-Gabriels-Web-Server-Stolen.cfm</link>
	<dc:date>2008-05-06T12:48:26-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam,Social Engineering,Data Security,Network Security</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/05/Happy-Birthday-Spam.cfm">
	<title>Happy Birthday Spam!</title>
	<description>It would be inappropriate for me to let this day go by without wishing a happy birthday to one of the most important and controversial terms of the early 21st century.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Spam!&lt;br /&gt;
&lt;br /&gt;
No, not &lt;a href=&quot;http://spam.com/&quot;&gt;SPAM&lt;/a&gt;!&lt;br /&gt;
&lt;br /&gt;
Spam! &lt;br /&gt;
&lt;br /&gt;
I try to shy away from actual definitions of spam because it&apos;s scope has gotten so much wider from when the first spam message was sent by Gary Thuerk to a large swath of &lt;a href=&quot;http://en.wikipedia.org/wiki/ARPANET&quot;&gt;ARPANET&lt;/a&gt; addresses 30 years ago this month.&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
So, was Thuerk an overly aggressive marketer?&amp;nbsp; Or a pioneer setting the stage for modern day cybercrime?&amp;nbsp; In my opinion the answer is both, but to that I would add the disclaimer that if he didn&apos;t do it surely someone else would have.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
One could also make the claim that spam started even prior to that using the CTSS (Compatible Time-Sharing System) &amp;quot;mail&amp;quot; command back in 1971 where a developer wrote a long anti-war message that began with &amp;quot;THERE IS NO WAY TO PEACE.&amp;nbsp; PEACE IS THE WAY.&amp;quot;&amp;nbsp; Despite being told that using the CTSS mail system in that way would likely be viewed as abusive he defended his position with the statement of &amp;quot;but this is important!&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Obviously spam has evolved quite a bit from its days of ARPANET and CTSS, but there are still a lot of parallels in why spam is sent.&amp;nbsp; The primary end-goal was the use of network technology and over the wire communication for the purpose of making money.&amp;nbsp; Whether that has to do with trying to sell a product (either legitimate or illegitimate) or trying to get a user to install adware or crimeware on their PC, money has been, still is, and will continue to be the primary reason for spam.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
As we also know, &amp;quot;Spam Ain&apos;t Just for Email Anymore.&amp;quot; but still carries the common theme of network abuse.&amp;nbsp; Social and mobile networks have been common recent additional avenues that spammers have been exploiting as well through SMS spam, blog spam.&amp;nbsp; Also, communication technologies like Instant Messenger and Voice over IP (VoIP) haven&apos;t been immune either whose abuse have borne acronyms like SPIM and SPIT.&lt;br /&gt;
&lt;br /&gt;
Bill Gates was clearly way off base when he predicted in January, 2004 that spam would be gone in two years.&amp;nbsp; Spam is more prevalent than ever not only in our inboxes, but in just about every way that we communicate and collaborate.&amp;nbsp; As long as people continue to respond to spam it isn&apos;t going anywhere.&amp;nbsp; In fact, it will only continue to become more pervasive and unavoidable.&amp;nbsp; &lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/05/Happy-Birthday-Spam.cfm</link>
	<dc:date>2008-05-01T13:07:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam,Social Engineering,Data Security,Network Security,Spam</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/04/Telecommuters-Surf-Twice-as-Much-Porn.cfm">
	<title>Telecommuters Surf Twice as Much Porn</title>
	<description>&lt;br /&gt;
According to &lt;a href=&quot;http://www.pcpro.co.uk/news/188850/home-workers-surf-twice-as-much-smut.html&quot;&gt;this article&lt;/a&gt; posted at PC Pro, ScanSafe says that remote employees are more than twice as likely to be surfing porn than employees who work in the office.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
This is not a surprising stat as telecommuting takes a level of discipline on the part of the teleworker that is far and away greater than office-bound employees.&amp;nbsp; What is surprising to me is that companies are ALLOWING this type of web surfing to be taking place on their corporate computers!&lt;br /&gt;
&lt;br /&gt;
Porn sites are one of the biggest security risks out there.&amp;nbsp; Porn sites commonly install malware, adware,&amp;nbsp; tracking cookies, and other security risks that could cause a security breach to your organization.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
In most cases you want to use technology as an enabler for employees to be as efficient as possible, particularly your remote employees who are frequently less scrutinized because most of management&apos;s attention is focused on the employees that are in the office every day.&amp;nbsp; This, however is one of those instances where technology needs to enforce the policies of the organization so that the company can protect itself and its intellectual property from compromise and disclosure.&amp;nbsp; Data leakage as a result of inappropriate employee web surfing and irresponsible organizational content filtering policies is one of the easiest insider threats to mitigate.&amp;nbsp; Companies should be doing everything that they can be to assure that this is not an avenue of information disclosure.&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/04/Telecommuters-Surf-Twice-as-Much-Porn.cfm</link>
	<dc:date>2008-04-23T15:46:26-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam,Social Engineering,Data Security,Network Security,Spam,Data Security,Insider Threat,Security Awareness</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/04/New-Phishing-Scam-Targetting-Economic-Stimulus-Payments.cfm">
	<title>New Phishing Scam Targeting Economic Stimulus Payments</title>
	<description>&lt;br /&gt;
Right on cue we are starting to see phishing scams with an economic stimulus payment flavor.&amp;nbsp; As we discussed in one of the &lt;a href=&quot;http://mxlogic.com/itsecurityblog/1/2008/03/New-IRS-Refund-Scam-with-a-Vishing-Twist.cfm&quot;&gt;IRS phishing scam blog entries&lt;/a&gt; we predicted that as the economic stimulus payment distribution got closer (currently scheduled to begin May 2nd based on the last two digits of your Social Security Number) we would start to see more scams around these payments.&amp;nbsp; We are starting to see some of the first iterations of those scams today.&lt;br /&gt;
&lt;br /&gt;
As has been common with most of the government agency spoofs that we have seen over the past year, this one has an IRS logo at the top of the message that is being pulled directly from the IRS web site at irs.gov.&lt;br /&gt;
&lt;br /&gt;
The samples that we are seeing allege to be from &amp;quot;service@irs.gov&amp;quot; and have a subject line of &amp;quot;2008 Economic Stimulus Refund.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The phish content is as follows:&lt;br /&gt;
&lt;br /&gt;
Over 130 million Americans will receive refunds as&lt;br /&gt;
part of President Bush program to jumpstart the economy.&lt;br /&gt;
&lt;br /&gt;
Our records indicate that you are qualified to receive the&lt;br /&gt;
2008 Economic Stimulus Refund.&lt;br /&gt;
&lt;br /&gt;
The fastest and easiest way to receive your refund is by&lt;br /&gt;
direct deposit to your checking/savings account.&lt;br /&gt;
&lt;br /&gt;
Please click on the link and fill out the form and submit&lt;br /&gt;
before April 24th, 2008 to ensure that your refund will be&lt;br /&gt;
processed as soon as possible.&lt;br /&gt;
&lt;br /&gt;
Submitting your form on April 24th, 2008 or later means that&lt;br /&gt;
your refund will be delayed due to the volume of requests we&lt;br /&gt;
anticipate for the Economic Stimulus Refund.&lt;br /&gt;
&lt;br /&gt;
To access Economic Stimulus Refund, please click here.&lt;br /&gt;
&lt;br /&gt;
The &amp;quot;click here&amp;quot; link takes the user to a prototypical phishing site where they are asked for their bank routing number and checking account number so that the rebate can be directly deposited into their checking account.&amp;nbsp; The scammers are also trying to establish a sense of urgency to get you to click the link by saying that you have to fill out and submit the form before April 24th if you want to get your stimulus payment on time.&amp;nbsp; Failure to do so will result in delays.&amp;nbsp; This could be an effective tactic against those who may not be scheduled to receive their rebate until July or against the extremely impatient who think that this could be a shortcut to getting their rebate quicker.&lt;br /&gt;
&lt;br /&gt;
This is about the time that we expected to start seeing these scams start coming out, and this certainly won&apos;t be the last of them, especially since the distribution of the stimulus payments is expected to last a couple of months.&lt;br /&gt;
&lt;br /&gt;
As with all of the IRS scams that we have seen to date, there are a couple of things that you should remember:&lt;br /&gt;
&lt;br /&gt;
-- The IRS does not communicate with the public over email.&amp;nbsp; &lt;br /&gt;
-- To that point, the IRS does not even know what your email address is.&amp;nbsp; If you use at home tax software the software vendor might ask you for your email address, but this is for the purpose of sending you status updates with respect to your tax filing.&amp;nbsp; These emails are not from the IRS.&lt;br /&gt;
&lt;br /&gt;
With respect to the economic stimulus payments, also remember:&lt;br /&gt;
&lt;br /&gt;
-- The economic stimulus payments are being distributed based on your 2007 tax filing.&amp;nbsp; The information for how to distribute your rebate to you will be done based off of your tax forms.&amp;nbsp; &lt;br /&gt;
-- The &lt;a href=&quot;http://www.irs.gov/newsroom/article/0,,id=180247,00.html&quot;&gt;payment schedule&lt;/a&gt; for the economic stimulus payments has already been established by the IRS.&amp;nbsp; There is no way to accelerate this process.&amp;nbsp; &lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/04/New-Phishing-Scam-Targetting-Economic-Stimulus-Payments.cfm</link>
	<dc:date>2008-04-22T13:43:00-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam,Social Engineering,Data Security,Network Security,Spam,Data Security,Insider Threat,Security Awareness,Phishing,Social Engineering,Government Scams</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/04/Malicious-Google-Spam-Alleging-News-Video-from-Bin-Laden.cfm">
	<title>Malicious Google Spam Alleging News Video from Bin Laden</title>
	<description>&lt;br /&gt;
We&apos;re seeing a new Google Spam run with a malware component making the rounds where the subject line of the message alleges that some of the more popular news agencies have released a Special Report with respect to a new video having been released from Osama bin Laden.&amp;nbsp; Volume is currently only less than 1% of total inbound virus traffic, so it is pretty low, but is yet another abuse of the Google PageRank system in an attempt to deliver malware.&lt;br /&gt;
&lt;br /&gt;
Some of the subject lines that we have seen include:&lt;br /&gt;
&lt;br /&gt;
&lt;font size=&quot;2&quot; face=&quot;Arial&quot;&gt;Special issue of news from&amp;nbsp; CNN! Urgent&amp;nbsp; Fresh News Usama Ben Laden!&lt;br /&gt;
Special issue of news from&amp;nbsp; CNBC! Urgent&amp;nbsp; Fresh News Usama Ben Laden!&lt;br /&gt;
&lt;/font&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot;&gt;&lt;span style=&quot;font-size: 10pt; font-family: Arial;&quot;&gt;Special issue of news from&amp;nbsp;  Financial Times! Urgent&amp;nbsp; Shocking News Usama Ben Laden!&lt;br /&gt;
&lt;/span&gt;&lt;/font&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot;&gt;Special issue of news from &amp;nbsp;CNN! Urgent&amp;nbsp; Apocalyptic News Usama Ben Laden!&lt;br /&gt;
&lt;/font&gt;Special issue of news from&amp;nbsp; Bloomberg! Urgent&amp;nbsp; Fresh News Usama Ben Laden!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
You can see a fairly common theme here.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
The email itself is somewhat lengthy and mostly discusses the tragedies that bin Laden has orchestrated against targets around the world.&amp;nbsp; The most pertinent parts of the message appear at the top (as usual, many grammatical errors exist throughout the message):&lt;br /&gt;
&lt;br /&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;Special issue of news  from Reuters! Urgent Dangerous News!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;hxxp://www.google.com/pagead/iclk?sa=l&amp;amp;ai=PBXCNHM&amp;amp;num=03311&amp;amp;adurl=&lt;o:p&gt;&lt;/o:p&gt;http://cavalldemar.org/news_usa.php&amp;nbsp;  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;Usama bin Laden(Osama  bin Laden) one of the largest organizers of  terrorist&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;&amp;nbsp;activity, and  similarly the largest leaders of terrorist organization of  Al&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;&amp;nbsp;Kaeda, detained  American soldiery force in &lt;st1:country-region w:st=&quot;on&quot;&gt;&lt;st1:place w:st=&quot;on&quot;&gt;Iraq&lt;/st1:place&gt;&lt;/st1:country-region&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p class=&quot;MsoNormal&quot;&gt;&lt;font size=&quot;2&quot; face=&quot;Arial&quot; color=&quot;navy&quot;&gt;&lt;span style=&quot;font-size: 10pt; color: navy; font-family: Arial;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;
This particular sample was taken from a message where the subject says that the news update is from CNN so you can see that the news agency in the subject line is not necessarily consistent in the actual message itself.&amp;nbsp; If the link from the message is followed, it directs the user to a page where they download a file named videousa.exe, which contains the malware.&lt;br /&gt;
&lt;br /&gt;
Also, as of the time of this posting the link to hxxp://cavelldemar.org/news_usa.php (domain registered in Spain) is still active and AV identification is spotty:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;table width=&quot;550&quot; cellspacing=&quot;0&quot; cellpadding=&quot;0&quot; border=&quot;0&quot; id=&quot;tablaMotores&quot;&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;th&gt;Antivirus&lt;/th&gt;
            &lt;th&gt;Version&lt;/th&gt;
            &lt;th&gt;Last Update&lt;/th&gt;
            &lt;th&gt;Result&lt;/th&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;AhnLab-V3&lt;/td&gt;
            &lt;td&gt;2008.4.22.0&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Win-Trojan/Agent.77824.DX&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;AntiVir&lt;/td&gt;
            &lt;td&gt;7.8.0.8&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;TR/Crypt.XPACK.Gen&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;Authentium&lt;/td&gt;
            &lt;td&gt;4.93.8&lt;/td&gt;
            &lt;td&gt;2008.04.20&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Avast&lt;/td&gt;
            &lt;td&gt;4.8.1169.0&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;AVG&lt;/td&gt;
            &lt;td&gt;7.5.0.516&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Downloader.Zlob.12.AH&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;BitDefender&lt;/td&gt;
            &lt;td&gt;7.2&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;CAT-QuickHeal&lt;/td&gt;
            &lt;td&gt;9.50&lt;/td&gt;
            &lt;td&gt;2008.04.19&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;(Suspicious) - DNAScan&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;ClamAV&lt;/td&gt;
            &lt;td&gt;0.92.1&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;DrWeb&lt;/td&gt;
            &lt;td&gt;4.44.0.09170&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;eSafe&lt;/td&gt;
            &lt;td&gt;7.0.15.0&lt;/td&gt;
            &lt;td&gt;2008.04.17&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Suspicious File&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;eTrust-Vet&lt;/td&gt;
            &lt;td&gt;31.3.5720&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Ewido&lt;/td&gt;
            &lt;td&gt;4.0&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Backdoor.Agent.gxg&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;F-Prot&lt;/td&gt;
            &lt;td&gt;4.4.2.54&lt;/td&gt;
            &lt;td&gt;2008.04.20&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;F-Secure&lt;/td&gt;
            &lt;td&gt;6.70.13260.0&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Backdoor.Win32.Agent.gxg&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;FileAdvisor&lt;/td&gt;
            &lt;td&gt;1&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Fortinet&lt;/td&gt;
            &lt;td&gt;3.14.0.0&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;Ikarus&lt;/td&gt;
            &lt;td&gt;T3.1.1.26&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Trojan.Win32.Revelation&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Kaspersky&lt;/td&gt;
            &lt;td&gt;7.0.0.125&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Backdoor.Win32.Agent.gxg&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;McAfee&lt;/td&gt;
            &lt;td&gt;5277&lt;/td&gt;
            &lt;td&gt;2008.04.18&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Microsoft&lt;/td&gt;
            &lt;td&gt;1.3408&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;TrojanDropper:Win32/Nuwar.gen!lds&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;NOD32v2&lt;/td&gt;
            &lt;td&gt;3043&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Norman&lt;/td&gt;
            &lt;td&gt;5.80.02&lt;/td&gt;
            &lt;td&gt;2008.04.18&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;Panda&lt;/td&gt;
            &lt;td&gt;9.0.0.4&lt;/td&gt;
            &lt;td&gt;2008.04.20&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Prevx1&lt;/td&gt;
            &lt;td&gt;V2&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;Rising&lt;/td&gt;
            &lt;td&gt;20.41.02.00&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Sophos&lt;/td&gt;
            &lt;td&gt;4.28.0&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Mal/Generic-A&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;Sunbelt&lt;/td&gt;
            &lt;td&gt;3.0.1056.0&lt;/td&gt;
            &lt;td&gt;2008.04.17&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Symantec&lt;/td&gt;
            &lt;td&gt;10&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;TheHacker&lt;/td&gt;
            &lt;td&gt;6.2.92.285&lt;/td&gt;
            &lt;td&gt;2008.04.19&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;VBA32&lt;/td&gt;
            &lt;td&gt;3.12.6.4&lt;/td&gt;
            &lt;td&gt;2008.04.16&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Trojan.Win32.Revelation&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td&gt;VirusBuster&lt;/td&gt;
            &lt;td&gt;4.3.26:9&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td&gt;-&lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr class=&quot;odd&quot;&gt;
            &lt;td&gt;Webwasher-Gateway&lt;/td&gt;
            &lt;td&gt;6.6.2&lt;/td&gt;
            &lt;td&gt;2008.04.21&lt;/td&gt;
            &lt;td class=&quot;positivo&quot;&gt;Trojan.Crypt.XPACK.Gen&lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
Fake video downloads and updates have been a pretty common theme for the Storm Worm folks for quite some time now.&amp;nbsp; This &amp;quot;news story&amp;quot; social engineering tactic is what Storm originally used to get most people infected back in January, 2007, so many people have already &amp;quot;been there, done that&amp;quot; which is likely why infection rates are staying pretty low.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/04/Malicious-Google-Spam-Alleging-News-Video-from-Bin-Laden.cfm</link>
	<dc:date>2008-04-21T11:32:54-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam,Social Engineering,Data Security,Network Security,Spam,Data Security,Insider Threat,Security Awareness,Phishing,Social Engineering,Government Scams,Storm Worm,Social Engineering,Malware</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/04/Cyber-Criminals-Go-To-Great-Lengths-To-Establish-Trust.cfm">
	<title>Cyber Criminals Go To Great Lengths To Establish Trust</title>
	<description>&lt;br /&gt;
Over the past 10 months or so we&apos;ve often discussed different social engineering tactics as it relates to different types of spam and malware campaigns.&amp;nbsp; These tactics range from using pinpoint precision to identify individual scam recipients (like CEOs and other C-Level Executives) to using tragic current events, naked celebrity videos, holiday e-cards, IRS tax refunds, or free/discounted sporting event tickets as a lure to get people to open malicious email attachments or click links that redirect them to web sites that are infested with malware.&lt;br /&gt;
&lt;br /&gt;
So, the question is: How far will cyber criminals go in an attempt to get a foothold on your PC or steal your personally identifiable information?&lt;br /&gt;
&lt;br /&gt;
The answer is simple: As far as they need to.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Cyber criminals will go to whatever lengths are necessary to trick you into doing what they need you to do in order to get infected with malware.&amp;nbsp; This means that the success of their campaign is almost solely related to their ability to establish trust and to make their campaign appear as legitimate as possible.&amp;nbsp; As an example, some of the IRS tax refund scams that we have been seeing this tax season even go so far as to link to or display the real IRS web site&apos;s logo, Privacy Policy and Online Help.&amp;nbsp; The &lt;a href=&quot;http://www.mxlogic.com/itsecurityblog/1/2008/04/New-Government-Phish--This-Time-Targeting-the-US-District-Court.cfm&quot;&gt;Federal Subpoena scam&lt;/a&gt; that we spoke about earlier this week included not only the name of the person that the scam was being sent to and their company name, but also their phone number!&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
As cyber criminals continue to hone their social engineering tactics, it is becoming more and more critical that people understand, are aware of, and keep a keen watch out for new potential threat vectors and the techniques that are being used in order to trick them into giving up information that could result in loss of identity, company secrets, or their life savings.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Losses being incurred as a result of cyber crime are increasing at an alarming rate and now we have reached the point where people are more fearful of being a victim of cyber crime than they are physical crime.&amp;nbsp; According to Gartner, losses as a result of phishing alone could top the $4B mark in 2008!&amp;nbsp; That increase is no accident and does not appear to be slowing anytime soon.&amp;nbsp; &lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/04/Cyber-Criminals-Go-To-Great-Lengths-To-Establish-Trust.cfm</link>
	<dc:date>2008-04-18T13:37:53-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,Social Engineering,Spam,Hackers,Rootkits,Botnets,Network Security,Malware,Network Security,Anti Spam,Spam,Mobile Spam,Phishing,Social Engineering,Malware,Spam,Government Scams,Whaling,Spam,Calendar Spam,Phishing,Spam,Social Engineering,Data Security,Network Security,Spam,Data Security,Insider Threat,Security Awareness,Phishing,Social Engineering,Government Scams,Storm Worm,Social Engineering,Malware,Hackers,Phishing,Social Engineering,Government Scams</dc:subject>
	</item>
	
	
 	
		
		
		
		
		
  	<item rdf:about="../../../../itsecurityblog/1/2008/04/Hold-out-on-Spammers-Get-Better-Discounts--Win-the-Spam-Game.cfm">
	<title>Hold out on Spammers, Get Better Discounts!  Win the Spam Game!</title>
	<description>&lt;br /&gt;
I just had to take a moment and share a couple of spam messages that came into our spamtraps over the past couple of days that I thought were somewhat humorous.&lt;br /&gt;
&lt;br /&gt;
So, apparently if I had bought my Viagra on Sunday, I would have gotten a 73% discount:&lt;br /&gt;
&lt;br /&gt;
&lt;img src=&quot;../../../../itsecurityblog/1/custom/spam_73.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
However, if I held out until Monday, I would get an 81% discount:&lt;br /&gt;
&lt;br /&gt;
&lt;img src=&quot;../../../../itsecurityblog/1/custom/spam_81.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
At this rate, if I hold out a couple more days I should be due about a 115% discount and actually be able to make money off the spammers and beat them at their own game!&amp;nbsp; :)&lt;br /&gt;
&lt;br /&gt;</description>
	<link>../../../../itsecurityblog/1/2008/04/Hold-out-on-Spammers-Get-Better-Discounts--Win-the-Spam-Game.cfm</link>
	<dc:date>2008-04-15T13:40:11-06:00</dc:date>
	
	<dc:subject>Storm Worm,Botnets,Malware,Spam,Fast Flux,Hackers,Botnets,Malware,Spammer Arrests,Law Enforcement,Network Security,Security Awareness,SQL Injection,Hackers,Physical Security,Botnets,Malware,Spam,Srizbi Botnet,Storm Worm,Social Engineering,Malware,Spam,Security Awareness,Physical Security,Spam,Google Spam,Botnets,Spam,SkyDrive Spam,Google Spam,Spam,Phishing,Vishing,Phishing,So