<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9100761888144266006</id><updated>2013-03-30T19:22:04.307Z</updated><title type='text'>Sanesecurity phishing/scam signatures for ClamAV</title><subtitle type='html'>A hopefully interesting blog from the world of spam/phishing and other security related items.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default?start-index=26&amp;max-results=25'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>76</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2715400269153374061</id><published>2013-03-30T19:22:00.000Z</published><updated>2013-03-30T19:22:04.314Z</updated><title type='text'>New website</title><content type='html'>Well, it's been a while since I've updated the blog, so I thought I'd better do so.  To start with, the new website is live, on the &lt;a href="http://www.sanesecurity.com"&gt;sanesecurity.com&lt;/a&gt; domain at the moment.  More new stuff coming shortly....</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2715400269153374061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2715400269153374061' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2715400269153374061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2715400269153374061'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2013/03/new-website.html' title='New website'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3242065142241391509</id><published>2011-05-19T10:13:00.003+01:00</published><updated>2011-05-19T10:22:38.466+01:00</updated><title type='text'>fake dhl email using pif</title><content type='html'>Another round of fake DHL emails... but this time... it's got a PIF attachment, instead of the&lt;br /&gt;normal zipped exe variety.&lt;br /&gt;&lt;br /&gt;Here's the email....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-nafUcxY-EIM/TdTfd3WfrHI/AAAAAAAAAFs/9IfKlAVgbbA/s1600/dhlfake.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/-nafUcxY-EIM/TdTfd3WfrHI/AAAAAAAAAFs/9IfKlAVgbbA/s320/dhlfake.jpg" alt="" id="BLOGGER_PHOTO_ID_5608353140150611058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted to Threatexpert:&lt;br /&gt;http://www.threatexpert.com/report.aspx?md5=8b7c994f4d5b0b5e35216bd68d87edb3&lt;br /&gt;&lt;br /&gt;Submitted to VirusTotal (7/43)&lt;br /&gt;http://www.virustotal.com/file-scan/report.html?id=2936d561853db9119ac2d5e7120f80d4e8ed39fa191365b5d8be83cfa4f95343-1305796256&lt;br /&gt;&lt;br /&gt;It seems to be interested in the following banks:&lt;br /&gt;http://eureka.cyber-ta.org/OUTPUT/8b7c994f4d5b0b5e35216bd68d87edb3/dns.txt&lt;br /&gt;&lt;br /&gt;Detected as:&lt;br /&gt;&lt;br /&gt;Sanesecurity.Rogue.2050 and Sanesecurity.Malware.16418&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3242065142241391509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3242065142241391509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3242065142241391509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3242065142241391509'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2011/05/another-round-of-fake-dhl-emails.html' title='fake dhl email using pif'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-nafUcxY-EIM/TdTfd3WfrHI/AAAAAAAAAFs/9IfKlAVgbbA/s72-c/dhlfake.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4091636202547029715</id><published>2011-03-30T11:09:00.007+01:00</published><updated>2011-03-30T11:23:39.883+01:00</updated><title type='text'>strange facebook emails</title><content type='html'>Received this interesting and very simple email today...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-ZGflffSsCDg/TZMBc1_PHGI/AAAAAAAAAFE/0Kbo0G_WqP0/s1600/fake1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 101px;" src="http://4.bp.blogspot.com/-ZGflffSsCDg/TZMBc1_PHGI/AAAAAAAAAFE/0Kbo0G_WqP0/s320/fake1.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813157537193058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the source code you can see, that the link doesn't go to facebook...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Dr89vvct9Ls/TZMB5PhBnFI/AAAAAAAAAFU/ttI01-HLWh4/s1600/fake3.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 11px;" src="http://3.bp.blogspot.com/-Dr89vvct9Ls/TZMB5PhBnFI/AAAAAAAAAFU/ttI01-HLWh4/s320/fake3.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813645426138194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;... It instead,  takes you to a forum... which has been hacked (which you can see when you look into the source code)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-uA3H45ysJzY/TZMBm-ZjLZI/AAAAAAAAAFM/1FwPIx-QE1w/s1600/fake2.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 14px;" src="http://4.bp.blogspot.com/-uA3H45ysJzY/TZMBm-ZjLZI/AAAAAAAAAFM/1FwPIx-QE1w/s320/fake2.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813331593735570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The forum then re-directs you,  via a 302 re-redirect... to another site (seen with httpfox)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-bcXA59U_sgw/TZMCMlyY3zI/AAAAAAAAAFc/j11WK-Vfijo/s1600/fake4.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 75px;" src="http://4.bp.blogspot.com/-bcXA59U_sgw/TZMCMlyY3zI/AAAAAAAAAFc/j11WK-Vfijo/s320/fake4.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813977822060338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The final site you end up with... is a fake anti-virus site, which are generally a pain to remove :(&lt;br /&gt;&lt;br /&gt;Checking the actual  fake anti-virus site (in bold) with &lt;span class="f"&gt;&lt;cite&gt;&lt;b&gt;urlvoid&lt;/b&gt;.com...&lt;/cite&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-JsywdBVbrrw/TZMCknhUVvI/AAAAAAAAAFk/IQ260MfeLQs/s1600/fake5.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 302px;" src="http://4.bp.blogspot.com/-JsywdBVbrrw/TZMCknhUVvI/AAAAAAAAAFk/IQ260MfeLQs/s320/fake5.jpg" alt="" id="BLOGGER_PHOTO_ID_5589814390604191474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can see that out of 21 url checkers... they all come up clean....&lt;br /&gt;&lt;br /&gt;It's not nice out there.... but Sanesecurity.Malware.15890 and Sanesecurity.Malware.15891 are currently blocking these emails.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4091636202547029715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4091636202547029715' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4091636202547029715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4091636202547029715'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2011/03/strange-facebook-emails.html' title='strange facebook emails'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ZGflffSsCDg/TZMBc1_PHGI/AAAAAAAAAFE/0Kbo0G_WqP0/s72-c/fake1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4799449916962613101</id><published>2010-09-14T14:16:00.003+01:00</published><updated>2010-09-14T14:20:38.163+01:00</updated><title type='text'>birth certificate malware</title><content type='html'>Here's a birth certificate email:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/TI914pEdMPI/AAAAAAAAAEk/HF78lRniwDI/s1600/ScreenShot071.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 178px; height: 320px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/TI914pEdMPI/AAAAAAAAAEk/HF78lRniwDI/s320/ScreenShot071.png" alt="" id="BLOGGER_PHOTO_ID_5516757684509815026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Inside the zip... is surprise, surprise... an exe file:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/TI92GoQ241I/AAAAAAAAAEs/LERE5meF1Ew/s1600/ScreenShot072.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 53px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/TI92GoQ241I/AAAAAAAAAEs/LERE5meF1Ew/s320/ScreenShot072.png" alt="" id="BLOGGER_PHOTO_ID_5516757924811563858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted to VirusTotal:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/TI92URkcV-I/AAAAAAAAAE0/hpKf2Kau5MU/s1600/ScreenShot073.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 148px;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/TI92URkcV-I/AAAAAAAAAE0/hpKf2Kau5MU/s320/ScreenShot073.png" alt="" id="BLOGGER_PHOTO_ID_5516758159237863394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Added detection as:&lt;br /&gt;&lt;br /&gt;Sanesecurity.Rogue.0hr.0914v32427 (rogue.hdb)&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4799449916962613101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4799449916962613101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4799449916962613101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4799449916962613101'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2010/09/birth-certificate-malware.html' title='birth certificate malware'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/TI914pEdMPI/AAAAAAAAAEk/HF78lRniwDI/s72-c/ScreenShot071.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4048458397083620192</id><published>2010-08-26T11:45:00.004+01:00</published><updated>2010-08-26T11:53:06.917+01:00</updated><title type='text'>New FedEx malware run... Zbot</title><content type='html'>Been a while since I've posted to here, so thought it was about time...&lt;br /&gt;&lt;br /&gt;A new malware run *just* came in... with a nice jpg and a not-so-nice exe in a zip file...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/THZF3E0LYHI/AAAAAAAAAEM/qd69p05qr3U/s1600/ScreenShot062.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 298px;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/THZF3E0LYHI/AAAAAAAAAEM/qd69p05qr3U/s320/ScreenShot062.png" alt="" id="BLOGGER_PHOTO_ID_5509668006622093426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted the exe to VirusTotal and the detection, isn't great...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/THZGFUy4fKI/AAAAAAAAAEU/jrtr_ARqtNM/s1600/ScreenShot063.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 64px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/THZGFUy4fKI/AAAAAAAAAEU/jrtr_ARqtNM/s320/ScreenShot063.png" alt="" id="BLOGGER_PHOTO_ID_5509668251429797026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Already being detected as: Sanesecurity.Malware.14529.UNOFFICIAL&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4048458397083620192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4048458397083620192' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4048458397083620192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4048458397083620192'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2010/08/new-fedex-malware-run-zbot.html' title='New FedEx malware run... Zbot'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/THZF3E0LYHI/AAAAAAAAAEM/qd69p05qr3U/s72-c/ScreenShot062.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2262780379364684878</id><published>2009-10-27T08:13:00.003Z</published><updated>2009-10-27T08:15:28.634Z</updated><title type='text'>Fake Facebook Password Reset Confirmation</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Has loads of these hit the inbox this morning....&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SuartYrz9ZI/AAAAAAAAAEA/nYmmYclQFDE/s1600-h/fb1.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 230px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SuartYrz9ZI/AAAAAAAAAEA/nYmmYclQFDE/s320/fb1.JPG" alt="" id="BLOGGER_PHOTO_ID_5397189999658792338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Virus Total:&lt;br /&gt;&lt;br /&gt;&lt;table style="display: block;" id="tableado" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Antivirus&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;td style="text-align: center;"&gt;Last Update&lt;/td&gt;&lt;td&gt;Result&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;a-squared&lt;/td&gt;&lt;td&gt;4.5.0.41&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AhnLab-V3&lt;/td&gt;&lt;td&gt;5.0.0.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AntiVir&lt;/td&gt;&lt;td&gt;7.9.1.44&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antiy-AVL&lt;/td&gt;&lt;td&gt;2.0.3.7&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authentium&lt;/td&gt;&lt;td&gt;5.1.2.4&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;W32/Bredolab!Generic&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Avast&lt;/td&gt;&lt;td&gt;4.8.1351.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;8.5.0.423&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Win32/Heur&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;BitDefender&lt;/td&gt;&lt;td&gt;7.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Downloader.Bredolab.AZ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;10.00&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ClamAV&lt;/td&gt;&lt;td&gt;0.94.1&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Comodo&lt;/td&gt;&lt;td&gt;2744&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Heur.Packed.Unknown&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;5.0.0.12182&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;7.0.17.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.25&lt;/td&gt;&lt;td style="color: red;"&gt;Suspicious File&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eTrust-Vet&lt;/td&gt;&lt;td&gt;35.1.7084&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Prot&lt;/td&gt;&lt;td&gt;4.5.1.85&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;9.0.15370.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.22&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Downloader.Bredolab.AZ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;3.120.0.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;GData&lt;/td&gt;&lt;td&gt;19&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Downloader.Bredolab.AZ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;T3.1.1.72.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Jiangmin&lt;/td&gt;&lt;td&gt;11.0.800&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;K7AntiVirus&lt;/td&gt;&lt;td&gt;7.10.879&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.24&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;7.0.0.125&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Packed.Win32.Krap.w&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;5783&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Bredolab.gen.a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;5783&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Bredolab.gen.a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;6.8.5&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;1.5202&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;TrojanDownloader:Win32/Bredolab.X&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NOD32&lt;/td&gt;&lt;td&gt;4545&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Norman&lt;/td&gt;&lt;td&gt;6.03.02&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;W32/Obfuscated.D2!genr&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;nProtect&lt;/td&gt;&lt;td&gt;2009.1.8.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;10.0.2.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PCTools&lt;/td&gt;&lt;td&gt;4.4.2.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.19&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Prevx&lt;/td&gt;&lt;td&gt;3.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;21.53.10.00&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;4.46.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Mal/Bredo-A&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;3.2.1858.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Win32.Bredolab.Gen.1 (v)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;1.4.4.12&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TheHacker&lt;/td&gt;&lt;td&gt;6.5.0.2.054&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;8.950.0.1094&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;TROJ_BREDLAB.SMF&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;3.12.10.11&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ViRobot&lt;/td&gt;&lt;td&gt;2009.10.27.2006&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VirusBuster&lt;/td&gt;&lt;td&gt;4.6.5.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4" height="10"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Detected as: &lt;br /&gt;&lt;br /&gt;Sanesecurity.Malware.12841&lt;br /&gt;Sanesecurity.Malware.12842</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2262780379364684878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2262780379364684878' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2262780379364684878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2262780379364684878'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/10/fake-facebook-password-reset.html' title='Fake Facebook Password Reset Confirmation'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SuartYrz9ZI/AAAAAAAAAEA/nYmmYclQFDE/s72-c/fb1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-570155081795202794</id><published>2009-08-26T15:57:00.006+01:00</published><updated>2009-08-26T16:01:30.675+01:00</updated><title type='text'>Spammer Fail</title><content type='html'>A nice big...&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://hellridemusic.com/SpamFail.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 360px; height: 360px;" src="http://hellridemusic.com/SpamFail.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;to the spammer that sent this...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SpVNmpfflAI/AAAAAAAAADw/_532vy0yTvE/s1600-h/ScreenShot016.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 42px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SpVNmpfflAI/AAAAAAAAADw/_532vy0yTvE/s320/ScreenShot016.png" alt="" id="BLOGGER_PHOTO_ID_5374287056704869378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Firefox says....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SpVNyhJcmjI/AAAAAAAAAD4/dww3VyK4w1I/s1600-h/ScreenShot017.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 70px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SpVNyhJcmjI/AAAAAAAAAD4/dww3VyK4w1I/s320/ScreenShot017.png" alt="" id="BLOGGER_PHOTO_ID_5374287260623346226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I think they meant http:// not htt://&lt;br /&gt;&lt;br /&gt;:)</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/570155081795202794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=570155081795202794' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/570155081795202794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/570155081795202794'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/08/spammer-fail.html' title='Spammer Fail'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SpVNmpfflAI/AAAAAAAAADw/_532vy0yTvE/s72-c/ScreenShot016.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1079661993455761339</id><published>2009-06-26T15:39:00.005+01:00</published><updated>2009-06-26T16:14:38.597+01:00</updated><title type='text'>michael jackson virus already :(</title><content type='html'>Well, it didn't take long for the "them" to abuse the situation did it? :(&lt;br /&gt;&lt;br /&gt;News item, with a picture and "video" to download:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SkTd43eDYZI/AAAAAAAAADo/azOLXY0uxcs/s1600-h/ScreenShot001.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 270px; height: 320px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SkTd43eDYZI/AAAAAAAAADo/azOLXY0uxcs/s320/ScreenShot001.png" alt="" id="BLOGGER_PHOTO_ID_5351646226255405458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=198bf811a1a7b7134512124c6f24f6006&amp;amp;call=first"&gt;Here's the Anubis report on the "video"&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Being detected as : Sanesecurity.Malware.11747.UNOFFICIAL&lt;br /&gt;&lt;br /&gt;Update: Other article with translation &lt;a href="http://securitylabs.websense.com/content/Alerts/3426.aspx"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1079661993455761339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1079661993455761339' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1079661993455761339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1079661993455761339'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/06/michael-jackson-virus-already.html' title='michael jackson virus already :('/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SkTd43eDYZI/AAAAAAAAADo/azOLXY0uxcs/s72-c/ScreenShot001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7730317611777332272</id><published>2009-03-16T11:30:00.004Z</published><updated>2009-03-16T11:35:54.109Z</updated><title type='text'>Fake News/Flash Player</title><content type='html'>Interesting email came in just:&lt;br /&gt;&lt;br /&gt;I worry about you httx: // ho.bestbreakingfree.com/news.php&lt;br /&gt;&lt;br /&gt;Here's the "news page" that you are taken too....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/Sb44hzcDJYI/AAAAAAAAADY/p1DETzHcH3M/s1600-h/ScreenShot027.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 277px;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/Sb44hzcDJYI/AAAAAAAAADY/p1DETzHcH3M/s320/ScreenShot027.png" alt="" id="BLOGGER_PHOTO_ID_5313746763738457474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Downloading the fake Player and running it through VirusTotal gives you this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/Sb44osZrCII/AAAAAAAAADg/4c67HuN6TvA/s1600-h/ScreenShot028.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 250px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/Sb44osZrCII/AAAAAAAAADg/4c67HuN6TvA/s320/ScreenShot028.png" alt="" id="BLOGGER_PHOTO_ID_5313746882108524674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/382cc7e124ef02198da69efbc35caf69"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see the 0-hour detection rates aren't that good (3/39 scanners) :(&lt;br /&gt;&lt;br /&gt;I'm sure we'll see more of this.</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7730317611777332272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7730317611777332272' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7730317611777332272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7730317611777332272'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/03/fake-newsflash-player.html' title='Fake News/Flash Player'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q-EvxUNMgdw/Sb44hzcDJYI/AAAAAAAAADY/p1DETzHcH3M/s72-c/ScreenShot027.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1566997928559144096</id><published>2009-02-25T08:21:00.004Z</published><updated>2009-02-25T08:29:33.419Z</updated><title type='text'>A good way to cut down on costs.. or not</title><content type='html'>I received an email today, looks quite safe and perhaps needed in the current climate...  cutting costs:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SaUAEKdNn0I/AAAAAAAAADA/PKLCTGQkNCM/s1600-h/coupon0.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 50px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SaUAEKdNn0I/AAAAAAAAADA/PKLCTGQkNCM/s320/coupon0.png" alt="" id="BLOGGER_PHOTO_ID_5306647807452356418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Clicking on the link, you are taken to a nice friendly looking coupon page to save money...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUALo4mEEI/AAAAAAAAADI/33QNBiJpWes/s1600-h/coupon1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 230px;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUALo4mEEI/AAAAAAAAADI/33QNBiJpWes/s320/coupon1.png" alt="" id="BLOGGER_PHOTO_ID_5306647935879352386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ah... it's asking to download an exe file...  best submit to virus total first....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUAQ7UhhrI/AAAAAAAAADQ/H8qR0_sbqGA/s1600-h/coupon2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 230px;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUAQ7UhhrI/AAAAAAAAADQ/H8qR0_sbqGA/s320/coupon2.png" alt="" id="BLOGGER_PHOTO_ID_5306648026727679666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/07e751c5db4dd533a036e544d78475f2"&gt;VirusTotal Results&lt;/a&gt; shows it's not exactly going to save us money... but does give us something nasty... for free :(</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1566997928559144096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1566997928559144096' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1566997928559144096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1566997928559144096'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/02/good-way-to-cut-down-on-costs-or-not.html' title='A good way to cut down on costs.. or not'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SaUAEKdNn0I/AAAAAAAAADA/PKLCTGQkNCM/s72-c/coupon0.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4018019773155350686</id><published>2009-02-13T21:27:00.002Z</published><updated>2009-02-13T21:30:38.245Z</updated><title type='text'>13.01.09: News</title><content type='html'>Lots of changes have been made recently to the download scripts, so if you haven't&lt;br /&gt;checked out the new versions recently, it might be worth taking a look in the &lt;a href="http://sanesecurity.net/usage.htm"&gt;usage page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In other news, there is now a support forum available &lt;a href="http://sanesecurity.org.uk/forum/"&gt;here&lt;/a&gt; and there is now a searchable mailing list available &lt;a href="http://news.gmane.org/gmane.comp.security.virus.clamav.sanesecurity"&gt;here&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4018019773155350686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4018019773155350686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4018019773155350686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4018019773155350686'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/02/130109-news.html' title='13.01.09: News'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7196788235482369738</id><published>2009-01-31T21:41:00.001Z</published><updated>2009-01-31T21:44:10.924Z</updated><title type='text'>20.01.09: News</title><content type='html'>&lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;strong&gt;31.01.09: Update...  aka Oops... forgot to update the main blog&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;strong&gt;20.01.09:                   News&lt;/strong&gt;&lt;br /&gt;         &lt;br /&gt;           It's been a while... but the Sanesecurity signatures have returned!&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;We                 disappeared for a while due a DDos, a                 small number of users who overloaded the shared hosting servers                   by downloading the signatures every second and in reality,                 an unscalable download system.&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;The                 old download system doesn't work any more and won't be coming                 back, so if you haven't done already, please disable your cron jobs and                 wget/curls downloads, as a new round-robin rsync based download url is available.&lt;br /&gt;             &lt;br /&gt;               All the changes are detailed &lt;a href="http://sanesecurity.org/changes.pdf"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;There's                 also a Sanesecurity list, which is recommended that signature                 users subscribe to, so that any future problems can be reported                 directly to you:&lt;br /&gt;           &lt;/span&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;br /&gt;             Subscribe                           to Sanesecurity list, by sending an email to &lt;strong&gt;the address &lt;/strong&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;in                           the below graphic&lt;/span&gt;&lt;/strong&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;, with               a subject of: &lt;strong&gt;subscribe&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;&lt;a href="mailto:hellospammer@spammer.invalid" target="_parent"&gt;&lt;img src="http://sanesecurity.org/subscribe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;             &lt;br /&gt;               &lt;span style="font-size:85%;"&gt;There is an archive, so you can read previous                 messages &lt;a href="http://www.freelists.org/archive/sanesecurity"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;             &lt;br /&gt;               &lt;span style="font-size:85%;"&gt;Finally, thank you for all the support and feedback.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;             &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;Steve&lt;br /&gt;               &lt;strong&gt;Sanesecurity&lt;/strong&gt;&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7196788235482369738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7196788235482369738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7196788235482369738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7196788235482369738'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/01/200109-news.html' title='20.01.09: News'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7918749623626943511</id><published>2009-01-18T13:23:00.000Z</published><updated>2009-01-18T13:24:28.630Z</updated><title type='text'>Update 18/01/09</title><content type='html'>&lt;p align="center"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Subscribe                 to Sanesecurity list, by sending an email to the address in the                 below graphic,&lt;br /&gt;          &lt;/span&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;with                 a subject of: &lt;strong&gt;subscribe&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="center"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;a href="mailto:hellospammer@spammer.invalid" target="_parent"&gt;&lt;img src="http://www.sanesecurity.com/clamav/subscribe.png" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;                                        &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Currently               there is a great deal of work going on behind the scenes in getting             the signatures back. This is the status so far:&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;strong&gt;*                   wget/curl etc. will no longer be used to download the signatures,             we're moving to rsync. So please disable all downloads for             the signatures, as they won't be coming back using the old urls.&lt;br /&gt;            &lt;/strong&gt;&lt;br /&gt;            &lt;strong&gt;* Signatures will now be signed using GnuPG, ensuring integrity of             the signatures. The public key for these signature will be available             from &lt;a href="http://www.sanesecurity.com/clamav/publickey.gpg"&gt;here&lt;/a&gt;.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;em&gt;For example, here's a good verify:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;gpg --verify junk.ndb.sig&lt;br /&gt;              gpg: Signature made 01/09/09 09:55:48 using DSA key ID 31EA4D9E&lt;br /&gt;              gpg: Good signature from "Sanesecurity (Sanesecurity Signatures)"&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Here's a bad verify:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;gpg --verify junk.ndb.sig&lt;br /&gt;              gpg: Signature made 01/09/09 09:55:48 using DSA key ID 31EA4D9E&lt;br /&gt;              gpg: BAD signature from "Sanesecurity (Sanesecurity Signatures)"&lt;br /&gt;            &lt;/span&gt;&lt;/em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;br /&gt;            &lt;strong&gt;* will be using round-robin dns system, to help spread the             load over rsync servers&lt;/strong&gt;.&lt;br /&gt;           &lt;br /&gt;            &lt;strong&gt;* three new databases added: spear.ndb, spamimg.hdb and spam.ldb&lt;br /&gt;           &lt;br /&gt;            * donation page, using PayPal will now also accept credit cards and             hopefully will be able to provide and invoice for people who want             one.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Hopefully,                   there will be more updates soon... so signup to the Sanesecurity             list for more news.&lt;/span&gt;&lt;/p&gt;             &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Finally                 a Huuuuuuge&lt;strong&gt; thank you &lt;/strong&gt;to everyone who has helped and offered             help. &lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7918749623626943511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7918749623626943511' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7918749623626943511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7918749623626943511'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/01/update-180109.html' title='Update 18/01/09'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7460270063264828933</id><published>2008-12-15T19:46:00.000Z</published><updated>2008-12-15T19:47:05.287Z</updated><title type='text'>14/12/08: Sanesecurity signatures ddos</title><content type='html'>&lt;p align="center"&gt;&lt;strong&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Sanesecurity signatures are no longer being                   updated or distributed&lt;/strong&gt;                due to extremely                   high server resource usage, which appears to be from a distributed                   denial of service attack (DDoS). I've moved server hosts twice                   (which takes time) and both times have resulted in the site                   being suspended.&lt;/span&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;As                   many of you know, I produce the signatures and run the site,                 in my spare time and with Christmas approaching I’m finding                 my spare time is currently limited.&lt;br /&gt;             &lt;br /&gt;                Hopefully this won’t be the end of the signatures and                   I’m hoping that they may return in the New Year.&lt;/span&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;May I take this opportunity to thank everyone who has helped                 this project, either by&lt;br /&gt;              providing samples, bandwidth, download scripts or donating.&lt;/span&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;Thanks                   and sorry to let you all down.&lt;/span&gt;&lt;/p&gt;               &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;Steve&lt;br /&gt;              Sanesecurity&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7460270063264828933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7460270063264828933' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7460270063264828933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7460270063264828933'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/12/141208-sanesecurity-signatures-ddos.html' title='14/12/08: Sanesecurity signatures ddos'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6848091120981129845</id><published>2008-08-14T13:53:00.003+01:00</published><updated>2008-08-14T13:58:36.339+01:00</updated><title type='text'>Fake Auto Identification Card documents</title><content type='html'>Just received the following email, with a zip file attached (containing an exe file):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SKQq5c20uuI/AAAAAAAAACE/jCIFgaA3stM/s1600-h/autoidcard1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SKQq5c20uuI/AAAAAAAAACE/jCIFgaA3stM/s320/autoidcard1.png" alt="" id="BLOGGER_PHOTO_ID_5234355833398409954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted the file to VirusTotal and the result isn't very good (3/36 scanners):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQrH8WBHYI/AAAAAAAAACM/WQZwifBO7bA/s1600-h/autoidcard2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQrH8WBHYI/AAAAAAAAACM/WQZwifBO7bA/s320/autoidcard2.png" alt="" id="BLOGGER_PHOTO_ID_5234356082368912770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitting the file to ThreatExpert, gives&lt;a href="http://www.threatexpert.com/report.aspx?uid=85c13b48-b468-4f96-b2be-7b2f36230697"&gt; the following result&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Threat characteristics of ZBot - a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Added detection as: Email.Malware.Sanesecurity.08081405</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6848091120981129845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6848091120981129845' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6848091120981129845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6848091120981129845'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/fake-auto-identification-card-documents.html' title='Fake Auto Identification Card documents'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SKQq5c20uuI/AAAAAAAAACE/jCIFgaA3stM/s72-c/autoidcard1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5575641642846871347</id><published>2008-08-14T10:48:00.011+01:00</published><updated>2008-08-14T12:01:07.710+01:00</updated><title type='text'>Fake Contract Documents</title><content type='html'>Received the following email, which looks the same as a version received about a week ago:&lt;br /&gt;&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQCbKs4TuI/AAAAAAAAABs/0SkySfzTbk8/s1600-h/contract1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQCbKs4TuI/AAAAAAAAABs/0SkySfzTbk8/s320/contract1.png" alt="" id="BLOGGER_PHOTO_ID_5234311332663676642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;Received: from [199.214.241.xxx] (h-199-214-241-xxx.norquest.ca [199.214.241.xxx]&lt;br /&gt;by raq0402.xxxxxxxxxx.co.uk (8.13.1/8.13.1) with ESMTP id m7E5rk9W028214&lt;br /&gt;for &lt;/span&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;span style="font-size:78%;"&gt;; &lt;/span&gt;&lt;span style="font-weight: bold;font-size:78%;" &gt;Thu, 14 Aug 2008 06:53:47 +0100&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;xxxxx@xxxxx.co.uk&gt;As you can see, it's got a zip attachment, which submitting to VirusTotal, gives us:&lt;br /&gt;&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKQCraAB2tI/AAAAAAAAAB0/ODvpf2VD1Kg/s1600-h/contract2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKQCraAB2tI/AAAAAAAAAB0/ODvpf2VD1Kg/s320/contract2.png" alt="" id="BLOGGER_PHOTO_ID_5234311611648432850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I'd already added a signature to catch the earlier version (11th August) and it also detected this latest version too:  Email.Malware.Sanesecurity.08081101 (added 11th August 2008)&lt;br /&gt;&lt;br /&gt;Submitting this to ThreatExpert, gives you &lt;a href="http://www.threatexpert.com/report.aspx?uid=a85f9f97-734d-4a9d-9120-029a17abbcd1"&gt;this worrying result&lt;/a&gt; !&lt;br /&gt;&lt;br /&gt;Ie: "&lt;/xxxxx@xxxxx.co.uk&gt;&lt;span style="font-style: italic;"&gt;Installs a default debugger that is injected into the execution sequence of a target application. If a threat is installed as a default debugger, it will be run every time a target application is attempted to be launched - either to mimic it and hide its own presence (e.g. an open port or a running process), or simply to be activated as often as possible&lt;/span&gt;."&lt;br /&gt;&lt;br /&gt;As you can see from the stats, it's still being spammed out:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQO2AKA9FI/AAAAAAAAAB8/afzHDdwxB_U/s1600-h/contract3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQO2AKA9FI/AAAAAAAAAB8/afzHDdwxB_U/s320/contract3.png" alt="" id="BLOGGER_PHOTO_ID_5234324987829089362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;None of this is a worry, to those admins who are blocking exe's inside zip files though :)&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5575641642846871347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5575641642846871347' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5575641642846871347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5575641642846871347'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/fake-contract-documents.html' title='Fake Contract Documents'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQCbKs4TuI/AAAAAAAAABs/0SkySfzTbk8/s72-c/contract1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5953206725262904921</id><published>2008-08-14T07:53:00.002+01:00</published><updated>2008-08-14T08:04:58.932+01:00</updated><title type='text'>MSNBC StormNews Spam: Update</title><content type='html'>Well they've changed the landing page URL yesterday evening... but this change was detected with the generic Email.Malware.Sanesecurity.08081301.StormNews.MSNBCGen signature I'd added yesterday morming &lt;phew&gt;&lt;br /&gt;&lt;br /&gt;As well as the URL change... they managed to make the make an Msnbc logoed one, instead of the CNN one, we had yesterday :)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKPWiWLKebI/AAAAAAAAABk/qlSd8_KLPMk/s1600-h/msnbc4.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKPWiWLKebI/AAAAAAAAABk/qlSd8_KLPMk/s320/msnbc4.png" alt="" id="BLOGGER_PHOTO_ID_5234263077490948530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There was also a change to the domain, that serves the fake anti-virus software too.&lt;br /&gt;&lt;br /&gt;On my servers.... the stats so far...&lt;br /&gt;&lt;br /&gt;CNN vs Msnbc:&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.08081003.StormNews.CnnGen: 9,519&lt;br /&gt;Email.Malware.Sanesecurity.08080606.StormNews.Cnn: 5,138&lt;br /&gt;Email.Malware.Sanesecurity.08080802.StormNews.CnnGen: 3,483&lt;br /&gt;Email.Malware.Sanesecurity.08081002.StormNews.CnnGen: 3,182&lt;br /&gt;Email.Malware.Sanesecurity.08080800.StormNews.Cnn: 1,608&lt;br /&gt;Email.Malware.Sanesecurity.08080902.StormNews.Cnn: 1,032&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.08081300.StormNews.MSNBC: 2,018&lt;br /&gt;Email.Malware.Sanesecurity.08081302.StormNews.MSNBC: 1,985</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5953206725262904921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5953206725262904921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5953206725262904921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5953206725262904921'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/msnbc-stormnews-spam-update.html' title='MSNBC StormNews Spam: Update'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKPWiWLKebI/AAAAAAAAABk/qlSd8_KLPMk/s72-c/msnbc4.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8314451113513179322</id><published>2008-08-13T10:38:00.004+01:00</published><updated>2008-08-13T10:45:26.959+01:00</updated><title type='text'>MSNBC StormNews Spam</title><content type='html'>Following on from the CNN virus spam we all know and love...looks like the spammers have got bored with CNN and moved onto MSNBC:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKr0SuVEQI/AAAAAAAAABM/fkvQQ5H88i8/s1600-h/msnbc1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKr0SuVEQI/AAAAAAAAABM/fkvQQ5H88i8/s320/msnbc1.png" alt="" id="BLOGGER_PHOTO_ID_5233934631825641730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;... but the MSNBC landing page... erm... still shows the CNN logo... ooops:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsB0RfUnI/AAAAAAAAABU/QuadUoCl-20/s1600-h/msnbc2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsB0RfUnI/AAAAAAAAABU/QuadUoCl-20/s320/msnbc2.png" alt="" id="BLOGGER_PHOTO_ID_5233934864169783922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exe file info: &lt;a href="http://www.virustotal.com/analisis/91c9092b5bf423aad4ac5788feaa36d6"&gt;VirusTotal&lt;/a&gt; and &lt;a href="http://www.threatexpert.com/report.aspx?md5=06bd0701d470475d32c6d98a0c685e4b"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;However, we do now have popups for some free rogue anti-virus scanning software:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsf6DDc1I/AAAAAAAAABc/52FlDF19i4E/s1600-h/msnbc3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsf6DDc1I/AAAAAAAAABc/52FlDF19i4E/s320/msnbc3.png" alt="" id="BLOGGER_PHOTO_ID_5233935381115925330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Needless to say, don't even try to download this!&lt;br /&gt;&lt;br /&gt;Detection added as: Email.Malware.Sanesecurity.08081300.StormNews.MSNBC</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8314451113513179322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8314451113513179322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8314451113513179322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8314451113513179322'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/msnbc-stormnews-spam.html' title='MSNBC StormNews Spam'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKr0SuVEQI/AAAAAAAAABM/fkvQQ5H88i8/s72-c/msnbc1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7291562754981408341</id><published>2008-08-08T08:48:00.004+01:00</published><updated>2008-08-08T08:53:26.751+01:00</updated><title type='text'>New Fake CNN email</title><content type='html'>Looks like a new round of CNN News emails are coming in:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJv6iZxB_lI/AAAAAAAAAA8/aaA5Ab6Um2Y/s1600-h/cnn1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJv6iZxB_lI/AAAAAAAAAA8/aaA5Ab6Um2Y/s320/cnn1.png" alt="" id="BLOGGER_PHOTO_ID_5232050861059997266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here's the fake landing page:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SJv6ulQ_PPI/AAAAAAAAABE/c90fnJLdedc/s1600-h/cnn2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SJv6ulQ_PPI/AAAAAAAAABE/c90fnJLdedc/s320/cnn2.png" alt="" id="BLOGGER_PHOTO_ID_5232051070305254642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/384a1cccde675b03a963043c9225d2db"&gt;Virus Total Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection added as: Email.Malware.Sanesecurity.08080800.StormNews.Cnn&lt;br /&gt;&lt;br /&gt;Note: if you are using Firefox and the Noscript plugin, won't see the above page</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7291562754981408341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7291562754981408341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7291562754981408341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7291562754981408341'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/new-fake-cnn-email.html' title='New Fake CNN email'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJv6iZxB_lI/AAAAAAAAAA8/aaA5Ab6Um2Y/s72-c/cnn1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-944365145555192720</id><published>2008-08-05T08:27:00.004+01:00</published><updated>2008-08-05T08:40:40.973+01:00</updated><title type='text'>0 hour UPS Invoice</title><content type='html'>There was another spam run of the fake UPS invoice yesterday, this time with a different version of the malware, in the zip attachment:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJgBJlA7rhI/AAAAAAAAAAs/_2Di9DU0uHg/s1600-h/ups_invoice1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJgBJlA7rhI/AAAAAAAAAAs/_2Di9DU0uHg/s320/ups_invoice1.png" alt="" id="BLOGGER_PHOTO_ID_5230932231257304594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What was interesting, was that the signatures I'd added to catch the last one, detected the new varient too:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SJgBjDTPEEI/AAAAAAAAAA0/j9dBpSftfYo/s1600-h/ups_invoice2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SJgBjDTPEEI/AAAAAAAAAA0/j9dBpSftfYo/s320/ups_invoice2.png" alt="" id="BLOGGER_PHOTO_ID_5230932668883865666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the above stats graph, Email_Malware_Sanesecurity_08072227&lt;br /&gt;(in yellow) was being blocked from around 5.30pm to 7pm.   ClamAV started detecting the attched file at 7pm (Trojan_Zbot_1737).&lt;br /&gt;&lt;br /&gt;What does the exe file do? (contained in the zip)... well, here's what &lt;a href="http://www.threatexpert.com/report.aspx?uid=e277f47c-23e9-4a70-800a-99563c205224"&gt;ThreatExpert said&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/944365145555192720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=944365145555192720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/944365145555192720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/944365145555192720'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/0-hour-ups-invoice.html' title='0 hour UPS Invoice'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJgBJlA7rhI/AAAAAAAAAAs/_2Di9DU0uHg/s72-c/ups_invoice1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2630223824837187872</id><published>2008-07-30T12:35:00.003+01:00</published><updated>2008-07-30T12:45:16.793+01:00</updated><title type='text'>Signature update notices via Twitter</title><content type='html'>&lt;a href="https://twitter.com/sanesecurity"&gt;Signature update notices via Twitter&lt;/a&gt; &lt;span&gt;&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2630223824837187872/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2630223824837187872' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2630223824837187872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2630223824837187872'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/07/signature-update-notices-via-twitter.html' title='Signature update notices via Twitter'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1405470043517071407</id><published>2008-07-03T20:26:00.002+01:00</published><updated>2008-07-14T09:34:41.784+01:00</updated><title type='text'>ClamAV Third-Party Signature names</title><content type='html'>Just a heads up really, that the next version of ClamAV will automatically add an ".UNOFFICIAL" suffix to ALL 3rd party signatures.&lt;br /&gt;&lt;br /&gt;Example 1:&lt;br /&gt;&lt;br /&gt;Email.Phishing.Bank.Gen2559.Sanesecurity.08070201 would become Email.Phishing.Bank.Gen2559.Sanesecurity.08070201.UNOFFICIAL&lt;br /&gt;&lt;br /&gt;Example 2:&lt;br /&gt;&lt;br /&gt;MSRBL-SPAM.Feed.Blaster.2759 would become&lt;br /&gt;MSRBL-SPAM.Feed.Blaster.2759.UNOFFICIAL</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1405470043517071407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1405470043517071407' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1405470043517071407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1405470043517071407'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/07/clamav-third-party-signature-names.html' title='ClamAV Third-Party Signature names'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5439927241495511630</id><published>2008-05-20T15:41:00.002+01:00</published><updated>2008-05-20T15:53:36.287+01:00</updated><title type='text'>SQL Injection: example blocked</title><content type='html'>There's still a huge amount of SQL injected sites still out there (&lt;a href="http://isc.sans.org/diary.html?storyid=4439"&gt;list of serving sites&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;For example:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SDLjdGjP2xI/AAAAAAAAAAM/qvw1xoFo4DY/s1600-h/sql1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SDLjdGjP2xI/AAAAAAAAAAM/qvw1xoFo4DY/s320/sql1.png" alt="" id="BLOGGER_PHOTO_ID_5202470608680508178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Looking at the html for the site, you can see the .js file, added inside the TITLE html code:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SDLjjWjP2yI/AAAAAAAAAAU/cJaipcKVLuw/s1600-h/sql2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SDLjjWjP2yI/AAAAAAAAAAU/cJaipcKVLuw/s320/sql2.png" alt="" id="BLOGGER_PHOTO_ID_5202470716054690594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you are using &lt;a href="http://www.clarkconnect.com/"&gt;clarkconnect&lt;/a&gt; (or other ClamAV based web-filtering) the latest update to the SaneSecurity signatures should help block the current sites:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SDLjo2jP2zI/AAAAAAAAAAc/U-CZHHp0EM4/s1600-h/sql3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SDLjo2jP2zI/AAAAAAAAAAc/U-CZHHp0EM4/s320/sql3.png" alt="" id="BLOGGER_PHOTO_ID_5202470810543971122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Signature(s): &lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.08051902.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052000.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052001.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052002.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052003.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.Url.SQLInj_xx</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5439927241495511630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5439927241495511630' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5439927241495511630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5439927241495511630'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/05/sql-injection-example-blocked.html' title='SQL Injection: example blocked'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SDLjdGjP2xI/AAAAAAAAAAM/qvw1xoFo4DY/s72-c/sql1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3688008949050012305</id><published>2008-05-07T14:53:00.002+01:00</published><updated>2008-05-07T15:03:26.320+01:00</updated><title type='text'>Rogue MP3 Trojan streaks across P2P networks</title><content type='html'>&lt;p&gt;Hopefully people have seen this.. but it's worth posting:&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Hundreds of thousands of examples of a new Trojan that poses as a media file have flooded onto P2P networks.&lt;/p&gt;  &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Since Friday 2 May&lt;/span&gt; more than half a million instances of the Trojan have been detected on consumer PCs, according to net security firm McAfee. The anti-virus firm reports the spread of the Downloader-UA.h Trojan as the most significant malware outbreak in the last three years.&lt;/p&gt;&lt;p&gt;Source: &lt;a href="http://www.theregister.co.uk/2008/05/07/mp3_trojan_blitz/"&gt;TheRegister&lt;/a&gt;&lt;br /&gt;Source: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/05/06/fake-mp3s-running-rampant"&gt;Mcafee&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;What's interesting about this, is that I came across this "new" idea from a post by ISS (dated 29th April), which you can see &lt;a href="http://isc.sans.org/diary.html?storyid=4355"&gt;here&lt;/a&gt;&lt;/p&gt;&lt;p&gt;While the above post talked about  .ASF files,  all the bad-guys have done is rename the .asf files to .mp3... Windows Media Player just reads Metadata in the header and runs the script :(&lt;br /&gt;&lt;/p&gt;&lt;p&gt;SaneSecurity ClamAV Generic detection was added on 30th April 2008 for this new idea and so I was interested to find that these "new" mp3s McAfee are talking about, are found using the same generic signature :)&lt;br /&gt;&lt;/p&gt;Eg: eview-T-3545425-turbanlporno.mp3: Email.Malware.Sanesecurity.&lt;span style="font-weight: bold;"&gt;080430&lt;/span&gt;01.WmaScript FOUND&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Note: You must be using ClamAV v0.93 to be able to detect this&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3688008949050012305/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3688008949050012305' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3688008949050012305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3688008949050012305'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/05/rogue-mp3-trojan-streaks-across-p2p.html' title='Rogue MP3 Trojan streaks across P2P networks'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8861870892776252406</id><published>2007-11-12T10:58:00.000Z</published><updated>2007-11-12T11:09:18.226Z</updated><title type='text'>Fake YouTube email spammed</title><content type='html'>Interesting YouTube email has just been spammed:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/youtube1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/youtube1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the link, it's a fake YouTube site, which takes you here:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/youtube3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/youtube3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Current VirusTotal detection for the install_flash_player.exe file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/youtube2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/youtube2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Email detected as:  Email.Malware.Sanesecurity.07111200</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8861870892776252406/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8861870892776252406' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8861870892776252406'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8861870892776252406'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/11/interesting-youtube-email-has-just-been.html' title='Fake YouTube email spammed'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>