<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9100761888144266006</id><updated>2011-12-09T03:31:14.693Z</updated><title type='text'>Sanesecurity phishing/scam signatures for ClamAV</title><subtitle type='html'>A hopefully interesting blog from the world of spam/phishing and other security related items.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>75</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3242065142241391509</id><published>2011-05-19T10:13:00.003+01:00</published><updated>2011-05-19T10:22:38.466+01:00</updated><title type='text'>fake dhl email using pif</title><content type='html'>Another round of fake DHL emails... but this time... it's got a PIF attachment, instead of the&lt;br /&gt;normal zipped exe variety.&lt;br /&gt;&lt;br /&gt;Here's the email....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-nafUcxY-EIM/TdTfd3WfrHI/AAAAAAAAAFs/9IfKlAVgbbA/s1600/dhlfake.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/-nafUcxY-EIM/TdTfd3WfrHI/AAAAAAAAAFs/9IfKlAVgbbA/s320/dhlfake.jpg" alt="" id="BLOGGER_PHOTO_ID_5608353140150611058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted to Threatexpert:&lt;br /&gt;http://www.threatexpert.com/report.aspx?md5=8b7c994f4d5b0b5e35216bd68d87edb3&lt;br /&gt;&lt;br /&gt;Submitted to VirusTotal (7/43)&lt;br /&gt;http://www.virustotal.com/file-scan/report.html?id=2936d561853db9119ac2d5e7120f80d4e8ed39fa191365b5d8be83cfa4f95343-1305796256&lt;br /&gt;&lt;br /&gt;It seems to be interested in the following banks:&lt;br /&gt;http://eureka.cyber-ta.org/OUTPUT/8b7c994f4d5b0b5e35216bd68d87edb3/dns.txt&lt;br /&gt;&lt;br /&gt;Detected as:&lt;br /&gt;&lt;br /&gt;Sanesecurity.Rogue.2050 and Sanesecurity.Malware.16418&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3242065142241391509?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3242065142241391509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3242065142241391509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3242065142241391509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3242065142241391509'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2011/05/another-round-of-fake-dhl-emails.html' title='fake dhl email using pif'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-nafUcxY-EIM/TdTfd3WfrHI/AAAAAAAAAFs/9IfKlAVgbbA/s72-c/dhlfake.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4091636202547029715</id><published>2011-03-30T11:09:00.007+01:00</published><updated>2011-03-30T11:23:39.883+01:00</updated><title type='text'>strange facebook emails</title><content type='html'>Received this interesting and very simple email today...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-ZGflffSsCDg/TZMBc1_PHGI/AAAAAAAAAFE/0Kbo0G_WqP0/s1600/fake1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 101px;" src="http://4.bp.blogspot.com/-ZGflffSsCDg/TZMBc1_PHGI/AAAAAAAAAFE/0Kbo0G_WqP0/s320/fake1.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813157537193058" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the source code you can see, that the link doesn't go to facebook...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Dr89vvct9Ls/TZMB5PhBnFI/AAAAAAAAAFU/ttI01-HLWh4/s1600/fake3.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 11px;" src="http://3.bp.blogspot.com/-Dr89vvct9Ls/TZMB5PhBnFI/AAAAAAAAAFU/ttI01-HLWh4/s320/fake3.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813645426138194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;... It instead,  takes you to a forum... which has been hacked (which you can see when you look into the source code)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-uA3H45ysJzY/TZMBm-ZjLZI/AAAAAAAAAFM/1FwPIx-QE1w/s1600/fake2.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 14px;" src="http://4.bp.blogspot.com/-uA3H45ysJzY/TZMBm-ZjLZI/AAAAAAAAAFM/1FwPIx-QE1w/s320/fake2.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813331593735570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The forum then re-directs you,  via a 302 re-redirect... to another site (seen with httpfox)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-bcXA59U_sgw/TZMCMlyY3zI/AAAAAAAAAFc/j11WK-Vfijo/s1600/fake4.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 75px;" src="http://4.bp.blogspot.com/-bcXA59U_sgw/TZMCMlyY3zI/AAAAAAAAAFc/j11WK-Vfijo/s320/fake4.jpg" alt="" id="BLOGGER_PHOTO_ID_5589813977822060338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The final site you end up with... is a fake anti-virus site, which are generally a pain to remove :(&lt;br /&gt;&lt;br /&gt;Checking the actual  fake anti-virus site (in bold) with &lt;span class="f"&gt;&lt;cite&gt;&lt;b&gt;urlvoid&lt;/b&gt;.com...&lt;/cite&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-JsywdBVbrrw/TZMCknhUVvI/AAAAAAAAAFk/IQ260MfeLQs/s1600/fake5.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 302px;" src="http://4.bp.blogspot.com/-JsywdBVbrrw/TZMCknhUVvI/AAAAAAAAAFk/IQ260MfeLQs/s320/fake5.jpg" alt="" id="BLOGGER_PHOTO_ID_5589814390604191474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can see that out of 21 url checkers... they all come up clean....&lt;br /&gt;&lt;br /&gt;It's not nice out there.... but Sanesecurity.Malware.15890 and Sanesecurity.Malware.15891 are currently blocking these emails.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4091636202547029715?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4091636202547029715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4091636202547029715' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4091636202547029715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4091636202547029715'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2011/03/strange-facebook-emails.html' title='strange facebook emails'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ZGflffSsCDg/TZMBc1_PHGI/AAAAAAAAAFE/0Kbo0G_WqP0/s72-c/fake1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4799449916962613101</id><published>2010-09-14T14:16:00.003+01:00</published><updated>2010-09-14T14:20:38.163+01:00</updated><title type='text'>birth certificate malware</title><content type='html'>Here's a birth certificate email:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/TI914pEdMPI/AAAAAAAAAEk/HF78lRniwDI/s1600/ScreenShot071.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 178px; height: 320px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/TI914pEdMPI/AAAAAAAAAEk/HF78lRniwDI/s320/ScreenShot071.png" alt="" id="BLOGGER_PHOTO_ID_5516757684509815026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Inside the zip... is surprise, surprise... an exe file:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/TI92GoQ241I/AAAAAAAAAEs/LERE5meF1Ew/s1600/ScreenShot072.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 53px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/TI92GoQ241I/AAAAAAAAAEs/LERE5meF1Ew/s320/ScreenShot072.png" alt="" id="BLOGGER_PHOTO_ID_5516757924811563858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted to VirusTotal:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/TI92URkcV-I/AAAAAAAAAE0/hpKf2Kau5MU/s1600/ScreenShot073.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 148px;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/TI92URkcV-I/AAAAAAAAAE0/hpKf2Kau5MU/s320/ScreenShot073.png" alt="" id="BLOGGER_PHOTO_ID_5516758159237863394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Added detection as:&lt;br /&gt;&lt;br /&gt;Sanesecurity.Rogue.0hr.0914v32427 (rogue.hdb)&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4799449916962613101?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4799449916962613101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4799449916962613101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4799449916962613101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4799449916962613101'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2010/09/birth-certificate-malware.html' title='birth certificate malware'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/TI914pEdMPI/AAAAAAAAAEk/HF78lRniwDI/s72-c/ScreenShot071.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4048458397083620192</id><published>2010-08-26T11:45:00.004+01:00</published><updated>2010-08-26T11:53:06.917+01:00</updated><title type='text'>New FedEx malware run... Zbot</title><content type='html'>Been a while since I've posted to here, so thought it was about time...&lt;br /&gt;&lt;br /&gt;A new malware run *just* came in... with a nice jpg and a not-so-nice exe in a zip file...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/THZF3E0LYHI/AAAAAAAAAEM/qd69p05qr3U/s1600/ScreenShot062.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 298px;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/THZF3E0LYHI/AAAAAAAAAEM/qd69p05qr3U/s320/ScreenShot062.png" alt="" id="BLOGGER_PHOTO_ID_5509668006622093426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted the exe to VirusTotal and the detection, isn't great...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/THZGFUy4fKI/AAAAAAAAAEU/jrtr_ARqtNM/s1600/ScreenShot063.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 64px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/THZGFUy4fKI/AAAAAAAAAEU/jrtr_ARqtNM/s320/ScreenShot063.png" alt="" id="BLOGGER_PHOTO_ID_5509668251429797026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Already being detected as: Sanesecurity.Malware.14529.UNOFFICIAL&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4048458397083620192?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4048458397083620192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4048458397083620192' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4048458397083620192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4048458397083620192'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2010/08/new-fedex-malware-run-zbot.html' title='New FedEx malware run... Zbot'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/THZF3E0LYHI/AAAAAAAAAEM/qd69p05qr3U/s72-c/ScreenShot062.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2262780379364684878</id><published>2009-10-27T08:13:00.003Z</published><updated>2009-10-27T08:15:28.634Z</updated><title type='text'>Fake Facebook Password Reset Confirmation</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Has loads of these hit the inbox this morning....&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SuartYrz9ZI/AAAAAAAAAEA/nYmmYclQFDE/s1600-h/fb1.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 230px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SuartYrz9ZI/AAAAAAAAAEA/nYmmYclQFDE/s320/fb1.JPG" alt="" id="BLOGGER_PHOTO_ID_5397189999658792338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Virus Total:&lt;br /&gt;&lt;br /&gt;&lt;table style="display: block;" id="tableado" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Antivirus&lt;/td&gt;&lt;td&gt;Version&lt;/td&gt;&lt;td style="text-align: center;"&gt;Last Update&lt;/td&gt;&lt;td&gt;Result&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;a-squared&lt;/td&gt;&lt;td&gt;4.5.0.41&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AhnLab-V3&lt;/td&gt;&lt;td&gt;5.0.0.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AntiVir&lt;/td&gt;&lt;td&gt;7.9.1.44&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Antiy-AVL&lt;/td&gt;&lt;td&gt;2.0.3.7&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Authentium&lt;/td&gt;&lt;td&gt;5.1.2.4&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;W32/Bredolab!Generic&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Avast&lt;/td&gt;&lt;td&gt;4.8.1351.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AVG&lt;/td&gt;&lt;td&gt;8.5.0.423&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Win32/Heur&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;BitDefender&lt;/td&gt;&lt;td&gt;7.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Downloader.Bredolab.AZ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;CAT-QuickHeal&lt;/td&gt;&lt;td&gt;10.00&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ClamAV&lt;/td&gt;&lt;td&gt;0.94.1&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Comodo&lt;/td&gt;&lt;td&gt;2744&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Heur.Packed.Unknown&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;DrWeb&lt;/td&gt;&lt;td&gt;5.0.0.12182&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eSafe&lt;/td&gt;&lt;td&gt;7.0.17.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.25&lt;/td&gt;&lt;td style="color: red;"&gt;Suspicious File&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eTrust-Vet&lt;/td&gt;&lt;td&gt;35.1.7084&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Prot&lt;/td&gt;&lt;td&gt;4.5.1.85&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;F-Secure&lt;/td&gt;&lt;td&gt;9.0.15370.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.22&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Downloader.Bredolab.AZ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Fortinet&lt;/td&gt;&lt;td&gt;3.120.0.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;GData&lt;/td&gt;&lt;td&gt;19&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Downloader.Bredolab.AZ&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ikarus&lt;/td&gt;&lt;td&gt;T3.1.1.72.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Jiangmin&lt;/td&gt;&lt;td&gt;11.0.800&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;K7AntiVirus&lt;/td&gt;&lt;td&gt;7.10.879&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.24&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Kaspersky&lt;/td&gt;&lt;td&gt;7.0.0.125&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Packed.Win32.Krap.w&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee&lt;/td&gt;&lt;td&gt;5783&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Bredolab.gen.a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee+Artemis&lt;/td&gt;&lt;td&gt;5783&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Bredolab.gen.a&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;McAfee-GW-Edition&lt;/td&gt;&lt;td&gt;6.8.5&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft&lt;/td&gt;&lt;td&gt;1.5202&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;TrojanDownloader:Win32/Bredolab.X&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;NOD32&lt;/td&gt;&lt;td&gt;4545&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Norman&lt;/td&gt;&lt;td&gt;6.03.02&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;W32/Obfuscated.D2!genr&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;nProtect&lt;/td&gt;&lt;td&gt;2009.1.8.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Panda&lt;/td&gt;&lt;td&gt;10.0.2.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;PCTools&lt;/td&gt;&lt;td&gt;4.4.2.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.19&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Prevx&lt;/td&gt;&lt;td&gt;3.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Rising&lt;/td&gt;&lt;td&gt;21.53.10.00&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sophos&lt;/td&gt;&lt;td&gt;4.46.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;Mal/Bredo-A&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Sunbelt&lt;/td&gt;&lt;td&gt;3.2.1858.2&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td style="color: red;"&gt;Trojan.Win32.Bredolab.Gen.1 (v)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Symantec&lt;/td&gt;&lt;td&gt;1.4.4.12&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TheHacker&lt;/td&gt;&lt;td&gt;6.5.0.2.054&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;TrendMicro&lt;/td&gt;&lt;td&gt;8.950.0.1094&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td style="color: red;"&gt;TROJ_BREDLAB.SMF&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VBA32&lt;/td&gt;&lt;td&gt;3.12.10.11&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ViRobot&lt;/td&gt;&lt;td&gt;2009.10.27.2006&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.27&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VirusBuster&lt;/td&gt;&lt;td&gt;4.6.5.0&lt;/td&gt;&lt;td style="text-align: center;"&gt;2009.10.26&lt;/td&gt;&lt;td&gt;-&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="4" height="10"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Detected as: &lt;br /&gt;&lt;br /&gt;Sanesecurity.Malware.12841&lt;br /&gt;Sanesecurity.Malware.12842&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-2262780379364684878?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2262780379364684878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2262780379364684878' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2262780379364684878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2262780379364684878'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/10/fake-facebook-password-reset.html' title='Fake Facebook Password Reset Confirmation'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SuartYrz9ZI/AAAAAAAAAEA/nYmmYclQFDE/s72-c/fb1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-570155081795202794</id><published>2009-08-26T15:57:00.006+01:00</published><updated>2009-08-26T16:01:30.675+01:00</updated><title type='text'>Spammer Fail</title><content type='html'>A nice big...&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://hellridemusic.com/SpamFail.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 360px; height: 360px;" src="http://hellridemusic.com/SpamFail.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;to the spammer that sent this...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SpVNmpfflAI/AAAAAAAAADw/_532vy0yTvE/s1600-h/ScreenShot016.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 42px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SpVNmpfflAI/AAAAAAAAADw/_532vy0yTvE/s320/ScreenShot016.png" alt="" id="BLOGGER_PHOTO_ID_5374287056704869378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Firefox says....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SpVNyhJcmjI/AAAAAAAAAD4/dww3VyK4w1I/s1600-h/ScreenShot017.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 70px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SpVNyhJcmjI/AAAAAAAAAD4/dww3VyK4w1I/s320/ScreenShot017.png" alt="" id="BLOGGER_PHOTO_ID_5374287260623346226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I think they meant http:// not htt://&lt;br /&gt;&lt;br /&gt;:)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-570155081795202794?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/570155081795202794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=570155081795202794' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/570155081795202794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/570155081795202794'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/08/spammer-fail.html' title='Spammer Fail'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SpVNmpfflAI/AAAAAAAAADw/_532vy0yTvE/s72-c/ScreenShot016.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1079661993455761339</id><published>2009-06-26T15:39:00.005+01:00</published><updated>2009-06-26T16:14:38.597+01:00</updated><title type='text'>michael jackson virus already :(</title><content type='html'>Well, it didn't take long for the "them" to abuse the situation did it? :(&lt;br /&gt;&lt;br /&gt;News item, with a picture and "video" to download:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SkTd43eDYZI/AAAAAAAAADo/azOLXY0uxcs/s1600-h/ScreenShot001.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 270px; height: 320px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SkTd43eDYZI/AAAAAAAAADo/azOLXY0uxcs/s320/ScreenShot001.png" alt="" id="BLOGGER_PHOTO_ID_5351646226255405458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://anubis.iseclab.org/?action=result&amp;amp;task_id=198bf811a1a7b7134512124c6f24f6006&amp;amp;call=first"&gt;Here's the Anubis report on the "video"&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Being detected as : Sanesecurity.Malware.11747.UNOFFICIAL&lt;br /&gt;&lt;br /&gt;Update: Other article with translation &lt;a href="http://securitylabs.websense.com/content/Alerts/3426.aspx"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;Sanesecurity&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1079661993455761339?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1079661993455761339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1079661993455761339' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1079661993455761339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1079661993455761339'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/06/michael-jackson-virus-already.html' title='michael jackson virus already :('/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SkTd43eDYZI/AAAAAAAAADo/azOLXY0uxcs/s72-c/ScreenShot001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7730317611777332272</id><published>2009-03-16T11:30:00.004Z</published><updated>2009-03-16T11:35:54.109Z</updated><title type='text'>Fake News/Flash Player</title><content type='html'>Interesting email came in just:&lt;br /&gt;&lt;br /&gt;I worry about you httx: // ho.bestbreakingfree.com/news.php&lt;br /&gt;&lt;br /&gt;Here's the "news page" that you are taken too....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/Sb44hzcDJYI/AAAAAAAAADY/p1DETzHcH3M/s1600-h/ScreenShot027.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 277px;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/Sb44hzcDJYI/AAAAAAAAADY/p1DETzHcH3M/s320/ScreenShot027.png" alt="" id="BLOGGER_PHOTO_ID_5313746763738457474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Downloading the fake Player and running it through VirusTotal gives you this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/Sb44osZrCII/AAAAAAAAADg/4c67HuN6TvA/s1600-h/ScreenShot028.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 250px;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/Sb44osZrCII/AAAAAAAAADg/4c67HuN6TvA/s320/ScreenShot028.png" alt="" id="BLOGGER_PHOTO_ID_5313746882108524674" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/382cc7e124ef02198da69efbc35caf69"&gt;VirusTotal&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see the 0-hour detection rates aren't that good (3/39 scanners) :(&lt;br /&gt;&lt;br /&gt;I'm sure we'll see more of this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7730317611777332272?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7730317611777332272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7730317611777332272' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7730317611777332272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7730317611777332272'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/03/fake-newsflash-player.html' title='Fake News/Flash Player'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q-EvxUNMgdw/Sb44hzcDJYI/AAAAAAAAADY/p1DETzHcH3M/s72-c/ScreenShot027.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1566997928559144096</id><published>2009-02-25T08:21:00.004Z</published><updated>2009-02-25T08:29:33.419Z</updated><title type='text'>A good way to cut down on costs.. or not</title><content type='html'>I received an email today, looks quite safe and perhaps needed in the current climate...  cutting costs:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SaUAEKdNn0I/AAAAAAAAADA/PKLCTGQkNCM/s1600-h/coupon0.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 50px;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SaUAEKdNn0I/AAAAAAAAADA/PKLCTGQkNCM/s320/coupon0.png" alt="" id="BLOGGER_PHOTO_ID_5306647807452356418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Clicking on the link, you are taken to a nice friendly looking coupon page to save money...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUALo4mEEI/AAAAAAAAADI/33QNBiJpWes/s1600-h/coupon1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 230px;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUALo4mEEI/AAAAAAAAADI/33QNBiJpWes/s320/coupon1.png" alt="" id="BLOGGER_PHOTO_ID_5306647935879352386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ah... it's asking to download an exe file...  best submit to virus total first....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUAQ7UhhrI/AAAAAAAAADQ/H8qR0_sbqGA/s1600-h/coupon2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 230px;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SaUAQ7UhhrI/AAAAAAAAADQ/H8qR0_sbqGA/s320/coupon2.png" alt="" id="BLOGGER_PHOTO_ID_5306648026727679666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/07e751c5db4dd533a036e544d78475f2"&gt;VirusTotal Results&lt;/a&gt; shows it's not exactly going to save us money... but does give us something nasty... for free :(&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1566997928559144096?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1566997928559144096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1566997928559144096' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1566997928559144096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1566997928559144096'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/02/good-way-to-cut-down-on-costs-or-not.html' title='A good way to cut down on costs.. or not'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SaUAEKdNn0I/AAAAAAAAADA/PKLCTGQkNCM/s72-c/coupon0.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4018019773155350686</id><published>2009-02-13T21:27:00.002Z</published><updated>2009-02-13T21:30:38.245Z</updated><title type='text'>13.01.09: News</title><content type='html'>Lots of changes have been made recently to the download scripts, so if you haven't&lt;br /&gt;checked out the new versions recently, it might be worth taking a look in the &lt;a href="http://sanesecurity.net/usage.htm"&gt;usage page&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In other news, there is now a support forum available &lt;a href="http://sanesecurity.org.uk/forum/"&gt;here&lt;/a&gt; and there is now a searchable mailing list available &lt;a href="http://news.gmane.org/gmane.comp.security.virus.clamav.sanesecurity"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4018019773155350686?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4018019773155350686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4018019773155350686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4018019773155350686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4018019773155350686'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/02/130109-news.html' title='13.01.09: News'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7196788235482369738</id><published>2009-01-31T21:41:00.001Z</published><updated>2009-01-31T21:44:10.924Z</updated><title type='text'>20.01.09: News</title><content type='html'>&lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;strong&gt;31.01.09: Update...  aka Oops... forgot to update the main blog&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;strong&gt;20.01.09:                   News&lt;/strong&gt;&lt;br /&gt;         &lt;br /&gt;           It's been a while... but the Sanesecurity signatures have returned!&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;We                 disappeared for a while due a DDos, a                 small number of users who overloaded the shared hosting servers                   by downloading the signatures every second and in reality,                 an unscalable download system.&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;The                 old download system doesn't work any more and won't be coming                 back, so if you haven't done already, please disable your cron jobs and                 wget/curls downloads, as a new round-robin rsync based download url is available.&lt;br /&gt;             &lt;br /&gt;               All the changes are detailed &lt;a href="http://sanesecurity.org/changes.pdf"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;There's                 also a Sanesecurity list, which is recommended that signature                 users subscribe to, so that any future problems can be reported                 directly to you:&lt;br /&gt;           &lt;/span&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;br /&gt;             Subscribe                           to Sanesecurity list, by sending an email to &lt;strong&gt;the address &lt;/strong&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;in                           the below graphic&lt;/span&gt;&lt;/strong&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;, with               a subject of: &lt;strong&gt;subscribe&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana,Arial,Helvetica,sans-serif;"&gt;&lt;a href="mailto:hellospammer@spammer.invalid" target="_parent"&gt;&lt;img src="http://sanesecurity.org/subscribe.png" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;             &lt;br /&gt;               &lt;span style="font-size:85%;"&gt;There is an archive, so you can read previous                 messages &lt;a href="http://www.freelists.org/archive/sanesecurity"&gt;here&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;             &lt;br /&gt;               &lt;span style="font-size:85%;"&gt;Finally, thank you for all the support and feedback.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;             &lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;Steve&lt;br /&gt;               &lt;strong&gt;Sanesecurity&lt;/strong&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7196788235482369738?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7196788235482369738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7196788235482369738' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7196788235482369738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7196788235482369738'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/01/200109-news.html' title='20.01.09: News'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7918749623626943511</id><published>2009-01-18T13:23:00.000Z</published><updated>2009-01-18T13:24:28.630Z</updated><title type='text'>Update 18/01/09</title><content type='html'>&lt;p align="center"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Subscribe                 to Sanesecurity list, by sending an email to the address in the                 below graphic,&lt;br /&gt;          &lt;/span&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;with                 a subject of: &lt;strong&gt;subscribe&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="center"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;a href="mailto:hellospammer@spammer.invalid" target="_parent"&gt;&lt;img src="http://www.sanesecurity.com/clamav/subscribe.png" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;                                        &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Currently               there is a great deal of work going on behind the scenes in getting             the signatures back. This is the status so far:&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;strong&gt;*                   wget/curl etc. will no longer be used to download the signatures,             we're moving to rsync. So please disable all downloads for             the signatures, as they won't be coming back using the old urls.&lt;br /&gt;            &lt;/strong&gt;&lt;br /&gt;            &lt;strong&gt;* Signatures will now be signed using GnuPG, ensuring integrity of             the signatures. The public key for these signature will be available             from &lt;a href="http://www.sanesecurity.com/clamav/publickey.gpg"&gt;here&lt;/a&gt;.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;em&gt;For example, here's a good verify:&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;gpg --verify junk.ndb.sig&lt;br /&gt;              gpg: Signature made 01/09/09 09:55:48 using DSA key ID 31EA4D9E&lt;br /&gt;              gpg: Good signature from "Sanesecurity (Sanesecurity Signatures)"&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Here's a bad verify:&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;gpg --verify junk.ndb.sig&lt;br /&gt;              gpg: Signature made 01/09/09 09:55:48 using DSA key ID 31EA4D9E&lt;br /&gt;              gpg: BAD signature from "Sanesecurity (Sanesecurity Signatures)"&lt;br /&gt;            &lt;/span&gt;&lt;/em&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;&lt;br /&gt;            &lt;strong&gt;* will be using round-robin dns system, to help spread the             load over rsync servers&lt;/strong&gt;.&lt;br /&gt;           &lt;br /&gt;            &lt;strong&gt;* three new databases added: spear.ndb, spamimg.hdb and spam.ldb&lt;br /&gt;           &lt;br /&gt;            * donation page, using PayPal will now also accept credit cards and             hopefully will be able to provide and invoice for people who want             one.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;             &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Hopefully,                   there will be more updates soon... so signup to the Sanesecurity             list for more news.&lt;/span&gt;&lt;/p&gt;             &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Finally                 a Huuuuuuge&lt;strong&gt; thank you &lt;/strong&gt;to everyone who has helped and offered             help. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7918749623626943511?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7918749623626943511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7918749623626943511' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7918749623626943511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7918749623626943511'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2009/01/update-180109.html' title='Update 18/01/09'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7460270063264828933</id><published>2008-12-15T19:46:00.000Z</published><updated>2008-12-15T19:47:05.287Z</updated><title type='text'>14/12/08: Sanesecurity signatures ddos</title><content type='html'>&lt;p align="center"&gt;&lt;strong&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Sanesecurity signatures are no longer being                   updated or distributed&lt;/strong&gt;                due to extremely                   high server resource usage, which appears to be from a distributed                   denial of service attack (DDoS). I've moved server hosts twice                   (which takes time) and both times have resulted in the site                   being suspended.&lt;/span&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;As                   many of you know, I produce the signatures and run the site,                 in my spare time and with Christmas approaching I’m finding                 my spare time is currently limited.&lt;br /&gt;             &lt;br /&gt;                Hopefully this won’t be the end of the signatures and                   I’m hoping that they may return in the New Year.&lt;/span&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;May I take this opportunity to thank everyone who has helped                 this project, either by&lt;br /&gt;              providing samples, bandwidth, download scripts or donating.&lt;/span&gt;&lt;/p&gt;               &lt;p align="left"&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;Thanks                   and sorry to let you all down.&lt;/span&gt;&lt;/p&gt;               &lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;"&gt;Steve&lt;br /&gt;              Sanesecurity&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7460270063264828933?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7460270063264828933/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7460270063264828933' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7460270063264828933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7460270063264828933'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/12/141208-sanesecurity-signatures-ddos.html' title='14/12/08: Sanesecurity signatures ddos'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6848091120981129845</id><published>2008-08-14T13:53:00.003+01:00</published><updated>2008-08-14T13:58:36.339+01:00</updated><title type='text'>Fake Auto Identification Card documents</title><content type='html'>Just received the following email, with a zip file attached (containing an exe file):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SKQq5c20uuI/AAAAAAAAACE/jCIFgaA3stM/s1600-h/autoidcard1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SKQq5c20uuI/AAAAAAAAACE/jCIFgaA3stM/s320/autoidcard1.png" alt="" id="BLOGGER_PHOTO_ID_5234355833398409954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitted the file to VirusTotal and the result isn't very good (3/36 scanners):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQrH8WBHYI/AAAAAAAAACM/WQZwifBO7bA/s1600-h/autoidcard2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQrH8WBHYI/AAAAAAAAACM/WQZwifBO7bA/s320/autoidcard2.png" alt="" id="BLOGGER_PHOTO_ID_5234356082368912770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitting the file to ThreatExpert, gives&lt;a href="http://www.threatexpert.com/report.aspx?uid=85c13b48-b468-4f96-b2be-7b2f36230697"&gt; the following result&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Threat characteristics of ZBot - a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Added detection as: Email.Malware.Sanesecurity.08081405&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6848091120981129845?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6848091120981129845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6848091120981129845' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6848091120981129845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6848091120981129845'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/fake-auto-identification-card-documents.html' title='Fake Auto Identification Card documents'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SKQq5c20uuI/AAAAAAAAACE/jCIFgaA3stM/s72-c/autoidcard1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5575641642846871347</id><published>2008-08-14T10:48:00.011+01:00</published><updated>2008-08-14T12:01:07.710+01:00</updated><title type='text'>Fake Contract Documents</title><content type='html'>Received the following email, which looks the same as a version received about a week ago:&lt;br /&gt;&lt;br /&gt;&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQCbKs4TuI/AAAAAAAAABs/0SkySfzTbk8/s1600-h/contract1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQCbKs4TuI/AAAAAAAAABs/0SkySfzTbk8/s320/contract1.png" alt="" id="BLOGGER_PHOTO_ID_5234311332663676642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;Received: from [199.214.241.xxx] (h-199-214-241-xxx.norquest.ca [199.214.241.xxx]&lt;br /&gt;by raq0402.xxxxxxxxxx.co.uk (8.13.1/8.13.1) with ESMTP id m7E5rk9W028214&lt;br /&gt;for &lt;/span&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;span style="font-size:78%;"&gt;; &lt;/span&gt;&lt;span style="font-weight: bold;font-size:78%;" &gt;Thu, 14 Aug 2008 06:53:47 +0100&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;xxxxx@xxxxx.co.uk&gt;As you can see, it's got a zip attachment, which submitting to VirusTotal, gives us:&lt;br /&gt;&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKQCraAB2tI/AAAAAAAAAB0/ODvpf2VD1Kg/s1600-h/contract2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKQCraAB2tI/AAAAAAAAAB0/ODvpf2VD1Kg/s320/contract2.png" alt="" id="BLOGGER_PHOTO_ID_5234311611648432850" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I'd already added a signature to catch the earlier version (11th August) and it also detected this latest version too:  Email.Malware.Sanesecurity.08081101 (added 11th August 2008)&lt;br /&gt;&lt;br /&gt;Submitting this to ThreatExpert, gives you &lt;a href="http://www.threatexpert.com/report.aspx?uid=a85f9f97-734d-4a9d-9120-029a17abbcd1"&gt;this worrying result&lt;/a&gt; !&lt;br /&gt;&lt;br /&gt;Ie: "&lt;/xxxxx@xxxxx.co.uk&gt;&lt;span style="font-style: italic;"&gt;Installs a default debugger that is injected into the execution sequence of a target application. If a threat is installed as a default debugger, it will be run every time a target application is attempted to be launched - either to mimic it and hide its own presence (e.g. an open port or a running process), or simply to be activated as often as possible&lt;/span&gt;."&lt;br /&gt;&lt;br /&gt;As you can see from the stats, it's still being spammed out:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQO2AKA9FI/AAAAAAAAAB8/afzHDdwxB_U/s1600-h/contract3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQO2AKA9FI/AAAAAAAAAB8/afzHDdwxB_U/s320/contract3.png" alt="" id="BLOGGER_PHOTO_ID_5234324987829089362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;xxxxx@xxxxx.co.uk&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;None of this is a worry, to those admins who are blocking exe's inside zip files though :)&lt;br /&gt;&lt;/xxxxx@xxxxx.co.uk&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5575641642846871347?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5575641642846871347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5575641642846871347' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5575641642846871347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5575641642846871347'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/fake-contract-documents.html' title='Fake Contract Documents'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKQCbKs4TuI/AAAAAAAAABs/0SkySfzTbk8/s72-c/contract1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5953206725262904921</id><published>2008-08-14T07:53:00.002+01:00</published><updated>2008-08-14T08:04:58.932+01:00</updated><title type='text'>MSNBC StormNews Spam: Update</title><content type='html'>Well they've changed the landing page URL yesterday evening... but this change was detected with the generic Email.Malware.Sanesecurity.08081301.StormNews.MSNBCGen signature I'd added yesterday morming &lt;phew&gt;&lt;br /&gt;&lt;br /&gt;As well as the URL change... they managed to make the make an Msnbc logoed one, instead of the CNN one, we had yesterday :)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKPWiWLKebI/AAAAAAAAABk/qlSd8_KLPMk/s1600-h/msnbc4.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKPWiWLKebI/AAAAAAAAABk/qlSd8_KLPMk/s320/msnbc4.png" alt="" id="BLOGGER_PHOTO_ID_5234263077490948530" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There was also a change to the domain, that serves the fake anti-virus software too.&lt;br /&gt;&lt;br /&gt;On my servers.... the stats so far...&lt;br /&gt;&lt;br /&gt;CNN vs Msnbc:&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.08081003.StormNews.CnnGen: 9,519&lt;br /&gt;Email.Malware.Sanesecurity.08080606.StormNews.Cnn: 5,138&lt;br /&gt;Email.Malware.Sanesecurity.08080802.StormNews.CnnGen: 3,483&lt;br /&gt;Email.Malware.Sanesecurity.08081002.StormNews.CnnGen: 3,182&lt;br /&gt;Email.Malware.Sanesecurity.08080800.StormNews.Cnn: 1,608&lt;br /&gt;Email.Malware.Sanesecurity.08080902.StormNews.Cnn: 1,032&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.08081300.StormNews.MSNBC: 2,018&lt;br /&gt;Email.Malware.Sanesecurity.08081302.StormNews.MSNBC: 1,985&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5953206725262904921?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5953206725262904921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5953206725262904921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5953206725262904921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5953206725262904921'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/msnbc-stormnews-spam-update.html' title='MSNBC StormNews Spam: Update'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Q-EvxUNMgdw/SKPWiWLKebI/AAAAAAAAABk/qlSd8_KLPMk/s72-c/msnbc4.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8314451113513179322</id><published>2008-08-13T10:38:00.004+01:00</published><updated>2008-08-13T10:45:26.959+01:00</updated><title type='text'>MSNBC StormNews Spam</title><content type='html'>Following on from the CNN virus spam we all know and love...looks like the spammers have got bored with CNN and moved onto MSNBC:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKr0SuVEQI/AAAAAAAAABM/fkvQQ5H88i8/s1600-h/msnbc1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKr0SuVEQI/AAAAAAAAABM/fkvQQ5H88i8/s320/msnbc1.png" alt="" id="BLOGGER_PHOTO_ID_5233934631825641730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;... but the MSNBC landing page... erm... still shows the CNN logo... ooops:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsB0RfUnI/AAAAAAAAABU/QuadUoCl-20/s1600-h/msnbc2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsB0RfUnI/AAAAAAAAABU/QuadUoCl-20/s320/msnbc2.png" alt="" id="BLOGGER_PHOTO_ID_5233934864169783922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exe file info: &lt;a href="http://www.virustotal.com/analisis/91c9092b5bf423aad4ac5788feaa36d6"&gt;VirusTotal&lt;/a&gt; and &lt;a href="http://www.threatexpert.com/report.aspx?md5=06bd0701d470475d32c6d98a0c685e4b"&gt;ThreatExpert&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;However, we do now have popups for some free rogue anti-virus scanning software:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsf6DDc1I/AAAAAAAAABc/52FlDF19i4E/s1600-h/msnbc3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKsf6DDc1I/AAAAAAAAABc/52FlDF19i4E/s320/msnbc3.png" alt="" id="BLOGGER_PHOTO_ID_5233935381115925330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Needless to say, don't even try to download this!&lt;br /&gt;&lt;br /&gt;Detection added as: Email.Malware.Sanesecurity.08081300.StormNews.MSNBC&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8314451113513179322?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8314451113513179322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8314451113513179322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8314451113513179322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8314451113513179322'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/msnbc-stormnews-spam.html' title='MSNBC StormNews Spam'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Q-EvxUNMgdw/SKKr0SuVEQI/AAAAAAAAABM/fkvQQ5H88i8/s72-c/msnbc1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7291562754981408341</id><published>2008-08-08T08:48:00.004+01:00</published><updated>2008-08-08T08:53:26.751+01:00</updated><title type='text'>New Fake CNN email</title><content type='html'>Looks like a new round of CNN News emails are coming in:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJv6iZxB_lI/AAAAAAAAAA8/aaA5Ab6Um2Y/s1600-h/cnn1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJv6iZxB_lI/AAAAAAAAAA8/aaA5Ab6Um2Y/s320/cnn1.png" alt="" id="BLOGGER_PHOTO_ID_5232050861059997266" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here's the fake landing page:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SJv6ulQ_PPI/AAAAAAAAABE/c90fnJLdedc/s1600-h/cnn2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SJv6ulQ_PPI/AAAAAAAAABE/c90fnJLdedc/s320/cnn2.png" alt="" id="BLOGGER_PHOTO_ID_5232051070305254642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.virustotal.com/analisis/384a1cccde675b03a963043c9225d2db"&gt;Virus Total Report&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Detection added as: Email.Malware.Sanesecurity.08080800.StormNews.Cnn&lt;br /&gt;&lt;br /&gt;Note: if you are using Firefox and the Noscript plugin, won't see the above page&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7291562754981408341?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7291562754981408341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7291562754981408341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7291562754981408341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7291562754981408341'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/new-fake-cnn-email.html' title='New Fake CNN email'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJv6iZxB_lI/AAAAAAAAAA8/aaA5Ab6Um2Y/s72-c/cnn1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-944365145555192720</id><published>2008-08-05T08:27:00.004+01:00</published><updated>2008-08-05T08:40:40.973+01:00</updated><title type='text'>0 hour UPS Invoice</title><content type='html'>There was another spam run of the fake UPS invoice yesterday, this time with a different version of the malware, in the zip attachment:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJgBJlA7rhI/AAAAAAAAAAs/_2Di9DU0uHg/s1600-h/ups_invoice1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJgBJlA7rhI/AAAAAAAAAAs/_2Di9DU0uHg/s320/ups_invoice1.png" alt="" id="BLOGGER_PHOTO_ID_5230932231257304594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What was interesting, was that the signatures I'd added to catch the last one, detected the new varient too:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SJgBjDTPEEI/AAAAAAAAAA0/j9dBpSftfYo/s1600-h/ups_invoice2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_Q-EvxUNMgdw/SJgBjDTPEEI/AAAAAAAAAA0/j9dBpSftfYo/s320/ups_invoice2.png" alt="" id="BLOGGER_PHOTO_ID_5230932668883865666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the above stats graph, Email_Malware_Sanesecurity_08072227&lt;br /&gt;(in yellow) was being blocked from around 5.30pm to 7pm.   ClamAV started detecting the attched file at 7pm (Trojan_Zbot_1737).&lt;br /&gt;&lt;br /&gt;What does the exe file do? (contained in the zip)... well, here's what &lt;a href="http://www.threatexpert.com/report.aspx?uid=e277f47c-23e9-4a70-800a-99563c205224"&gt;ThreatExpert said&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-944365145555192720?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/944365145555192720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=944365145555192720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/944365145555192720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/944365145555192720'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/08/0-hour-ups-invoice.html' title='0 hour UPS Invoice'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SJgBJlA7rhI/AAAAAAAAAAs/_2Di9DU0uHg/s72-c/ups_invoice1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2630223824837187872</id><published>2008-07-30T12:35:00.003+01:00</published><updated>2008-07-30T12:45:16.793+01:00</updated><title type='text'>Signature update notices via Twitter</title><content type='html'>&lt;a href="https://twitter.com/sanesecurity"&gt;Signature update notices via Twitter&lt;/a&gt; &lt;span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-2630223824837187872?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2630223824837187872/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2630223824837187872' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2630223824837187872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2630223824837187872'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/07/signature-update-notices-via-twitter.html' title='Signature update notices via Twitter'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1405470043517071407</id><published>2008-07-03T20:26:00.002+01:00</published><updated>2008-07-14T09:34:41.784+01:00</updated><title type='text'>ClamAV Third-Party Signature names</title><content type='html'>Just a heads up really, that the next version of ClamAV will automatically add an ".UNOFFICIAL" suffix to ALL 3rd party signatures.&lt;br /&gt;&lt;br /&gt;Example 1:&lt;br /&gt;&lt;br /&gt;Email.Phishing.Bank.Gen2559.Sanesecurity.08070201 would become Email.Phishing.Bank.Gen2559.Sanesecurity.08070201.UNOFFICIAL&lt;br /&gt;&lt;br /&gt;Example 2:&lt;br /&gt;&lt;br /&gt;MSRBL-SPAM.Feed.Blaster.2759 would become&lt;br /&gt;MSRBL-SPAM.Feed.Blaster.2759.UNOFFICIAL&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1405470043517071407?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1405470043517071407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1405470043517071407' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1405470043517071407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1405470043517071407'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/07/clamav-third-party-signature-names.html' title='ClamAV Third-Party Signature names'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5439927241495511630</id><published>2008-05-20T15:41:00.002+01:00</published><updated>2008-05-20T15:53:36.287+01:00</updated><title type='text'>SQL Injection: example blocked</title><content type='html'>There's still a huge amount of SQL injected sites still out there (&lt;a href="http://isc.sans.org/diary.html?storyid=4439"&gt;list of serving sites&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;For example:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SDLjdGjP2xI/AAAAAAAAAAM/qvw1xoFo4DY/s1600-h/sql1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Q-EvxUNMgdw/SDLjdGjP2xI/AAAAAAAAAAM/qvw1xoFo4DY/s320/sql1.png" alt="" id="BLOGGER_PHOTO_ID_5202470608680508178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Looking at the html for the site, you can see the .js file, added inside the TITLE html code:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SDLjjWjP2yI/AAAAAAAAAAU/cJaipcKVLuw/s1600-h/sql2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Q-EvxUNMgdw/SDLjjWjP2yI/AAAAAAAAAAU/cJaipcKVLuw/s320/sql2.png" alt="" id="BLOGGER_PHOTO_ID_5202470716054690594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you are using &lt;a href="http://www.clarkconnect.com/"&gt;clarkconnect&lt;/a&gt; (or other ClamAV based web-filtering) the latest update to the SaneSecurity signatures should help block the current sites:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SDLjo2jP2zI/AAAAAAAAAAc/U-CZHHp0EM4/s1600-h/sql3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Q-EvxUNMgdw/SDLjo2jP2zI/AAAAAAAAAAc/U-CZHHp0EM4/s320/sql3.png" alt="" id="BLOGGER_PHOTO_ID_5202470810543971122" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Signature(s): &lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.08051902.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052000.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052001.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052002.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.08052003.SQLInj (generic)&lt;br /&gt;Email.Malware.Sanesecurity.Url.SQLInj_xx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5439927241495511630?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5439927241495511630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5439927241495511630' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5439927241495511630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5439927241495511630'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/05/sql-injection-example-blocked.html' title='SQL Injection: example blocked'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Q-EvxUNMgdw/SDLjdGjP2xI/AAAAAAAAAAM/qvw1xoFo4DY/s72-c/sql1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3688008949050012305</id><published>2008-05-07T14:53:00.002+01:00</published><updated>2008-05-07T15:03:26.320+01:00</updated><title type='text'>Rogue MP3 Trojan streaks across P2P networks</title><content type='html'>&lt;p&gt;Hopefully people have seen this.. but it's worth posting:&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Hundreds of thousands of examples of a new Trojan that poses as a media file have flooded onto P2P networks.&lt;/p&gt;  &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Since Friday 2 May&lt;/span&gt; more than half a million instances of the Trojan have been detected on consumer PCs, according to net security firm McAfee. The anti-virus firm reports the spread of the Downloader-UA.h Trojan as the most significant malware outbreak in the last three years.&lt;/p&gt;&lt;p&gt;Source: &lt;a href="http://www.theregister.co.uk/2008/05/07/mp3_trojan_blitz/"&gt;TheRegister&lt;/a&gt;&lt;br /&gt;Source: &lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/05/06/fake-mp3s-running-rampant"&gt;Mcafee&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;What's interesting about this, is that I came across this "new" idea from a post by ISS (dated 29th April), which you can see &lt;a href="http://isc.sans.org/diary.html?storyid=4355"&gt;here&lt;/a&gt;&lt;/p&gt;&lt;p&gt;While the above post talked about  .ASF files,  all the bad-guys have done is rename the .asf files to .mp3... Windows Media Player just reads Metadata in the header and runs the script :(&lt;br /&gt;&lt;/p&gt;&lt;p&gt;SaneSecurity ClamAV Generic detection was added on 30th April 2008 for this new idea and so I was interested to find that these "new" mp3s McAfee are talking about, are found using the same generic signature :)&lt;br /&gt;&lt;/p&gt;Eg: eview-T-3545425-turbanlporno.mp3: Email.Malware.Sanesecurity.&lt;span style="font-weight: bold;"&gt;080430&lt;/span&gt;01.WmaScript FOUND&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Note: You must be using ClamAV v0.93 to be able to detect this&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3688008949050012305?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3688008949050012305/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3688008949050012305' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3688008949050012305'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3688008949050012305'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2008/05/rogue-mp3-trojan-streaks-across-p2p.html' title='Rogue MP3 Trojan streaks across P2P networks'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8861870892776252406</id><published>2007-11-12T10:58:00.000Z</published><updated>2007-11-12T11:09:18.226Z</updated><title type='text'>Fake YouTube email spammed</title><content type='html'>Interesting YouTube email has just been spammed:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/youtube1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/youtube1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the link, it's a fake YouTube site, which takes you here:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/youtube3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/youtube3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Current VirusTotal detection for the install_flash_player.exe file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/youtube2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/youtube2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Email detected as:  Email.Malware.Sanesecurity.07111200&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8861870892776252406?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8861870892776252406/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8861870892776252406' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8861870892776252406'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8861870892776252406'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/11/interesting-youtube-email-has-just-been.html' title='Fake YouTube email spammed'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2729075461917819194</id><published>2007-10-05T09:48:00.000+01:00</published><updated>2007-10-08T08:32:44.673+01:00</updated><title type='text'>0hour testing</title><content type='html'>Well, a new email came in, which looked very odd, here's the headers:&lt;br /&gt;&lt;br /&gt;Return-Path: &lt;totty.dalzell@vagnsvvs.xx&gt;&lt;br /&gt;Received: from 88-139-180-230.adslgp.cegetel.xxx (88-139-180-230.adslgp.cegetel.&lt;br /&gt;by raq0402.keele.netcentral.co.xx (8.9.3/8.9.3) with ESMTP id JAA02419&lt;br /&gt;for &lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;; &lt;span style="font-weight: bold;"&gt;Fri, 5 Oct 2007 09:28:25&lt;/span&gt; +0100&lt;br /&gt;Received: from [88.139.180.230] by mx2.servershost.xxx; Fri, 5 Oct 2007 02:37:20&lt;br /&gt;From: "Shirley Xxxxxxx" &lt;totty.dalzell@vagnsvvs.xx&gt;&lt;br /&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;Date: Fri, 5 Oct 2007 02:37:20 +0100&lt;br /&gt;&lt;br /&gt;Here's the actual email:&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;So, I submitted the zip file to VirusTotal to see what the latest detection was like and then repeated the same file, at various times after that, to see roughly when vendors added detection.&lt;br /&gt;&lt;br /&gt;Note:  it's not exactly scientific, so your mileage may vary etc.&lt;br /&gt;&lt;br /&gt;Here's the results:&lt;br /&gt;&lt;br /&gt;As you can see, Antivir did well!&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ClamAV team did a very quick job on adding this one, still beating the big boys:&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;totty.dalzell@vagnsvvs.xx&gt;&lt;nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;/nicolaa@xxxxxxxxxxx.xx.xx&gt;&lt;/totty.dalzell@vagnsvvs.xx&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_4.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_4.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;F-Secure and F-Prot, now have detection:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_5.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_5.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nod32 users now covered:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_6.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_6.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Kaspersky users now covered:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_7.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_7.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For the AVG users out there, detection has now been added:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_8.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_8.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here's the situation on Monday morning:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/0hr_9.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/0hr_9.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-2729075461917819194?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2729075461917819194/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2729075461917819194' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2729075461917819194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2729075461917819194'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/10/0hour-testing.html' title='0hour testing'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3591526146851434217</id><published>2007-09-19T16:26:00.000+01:00</published><updated>2007-09-19T16:36:59.081+01:00</updated><title type='text'>SaneSecurity News: Corrupt Signatures</title><content type='html'>For a few hours today, one of the mirrors  had a corrupt version of phish.ndb.gz.&lt;br /&gt;&lt;br /&gt;After being alerted to the fact by a user, I informed the mirror admin about the issue and the problem was then fixed.&lt;br /&gt;&lt;br /&gt;The scripts on the SaneSecurity site, check the integrity of the signatures before being moved into the ClamAV database directory for use... and have done for some time.  &lt;br /&gt;&lt;br /&gt;This is important not only for the SaneSecurity signatures but indeed for any Third-Party signatures, as if you move a corrupt signature file into the ClamAV directory, it's going to stop ClamAV from scanning your emails, until you sort the problem out.&lt;br /&gt;&lt;br /&gt;If you're running your own script or have an old version of the SaneSecurity scripts, it might be worth updating them:&lt;br /&gt;&lt;br /&gt;http://sanesecurity.co.uk/clamav/usage.htm&lt;br /&gt;&lt;br /&gt;I do always check signature integrity before uploading... so they leave here fine... but the &lt;span style="font-weight: bold;"&gt;end-user must always double-check their download integrity before use&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Apologies for the corrupt file and any problems caused.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3591526146851434217?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3591526146851434217/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3591526146851434217' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3591526146851434217'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3591526146851434217'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/sanesecurity-news-corrupt-signatures.html' title='SaneSecurity News: Corrupt Signatures'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5950002731116464568</id><published>2007-09-16T12:27:00.000+01:00</published><updated>2007-09-16T12:33:46.324+01:00</updated><title type='text'>Storm Worm Again: free games</title><content type='html'>You know the drill by now...&lt;br /&gt;&lt;br /&gt;First you get an email, something like this one, with a IP address url:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm1_160907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm1_160907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You are taken to a fake page, asking to download an exe file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm2_160907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm2_160907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;But the exe file, isn't all that it seems.  Here's what VirusTotal had to say:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm3_160907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm3_160907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Currently detected as: Email.Malware.Sanesecurity.0709160x (0-3)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5950002731116464568?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5950002731116464568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5950002731116464568' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5950002731116464568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5950002731116464568'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/storm-worm-again-free-games.html' title='Storm Worm Again: free games'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1877883204595361062</id><published>2007-09-11T08:12:00.000+01:00</published><updated>2007-09-11T08:13:35.957+01:00</updated><title type='text'>SaneSecurity news</title><content type='html'>&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;Firstly, some quite amazing news, on Wednesday, 5th September                 9pm, &lt;/span&gt;&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;I                 was lucky enough to have a 30 minute phone chat with Dean Drako,                 CEO of Barracuda Networks.&lt;br /&gt;&lt;br /&gt;                Dean confirmed that  &lt;a href="http://www.barracudacentral.com/index.cgi?p=spam"&gt;Barracuda&lt;/a&gt; are                 using my signatures as part of their multi-layer of defence.                 Dean also confirmed that Barracuda are now a SaneSecurity signature                 mirror and Sanesecurity even get a mention &lt;a href="http://www.barracudanetworks.com/ns/company/open-source.php"&gt;here&lt;/a&gt; too.&lt;br /&gt;               &lt;br /&gt;                Secondly, a new experimental project PhishBar, which you can                 read more about &lt;a href="http://sanesecurity.co.uk/clamav/phishbar.htm"&gt;here&lt;/a&gt;, but please read the big red flashing led warning bits before                 using.&lt;br /&gt;               &lt;br /&gt;                In a nutshell,                  It's a way of seeing if any of your users have phishing                 sites stored in                 their home directories/user space on your servers.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1877883204595361062?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1877883204595361062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1877883204595361062' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1877883204595361062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1877883204595361062'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/sanesecurity-news.html' title='SaneSecurity news'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5863230128355513196</id><published>2007-09-09T00:14:00.000+01:00</published><updated>2007-09-09T00:23:05.641+01:00</updated><title type='text'>Storm Worm Again: NFL</title><content type='html'>New storm worm version just hitting, all about NFL Football (12 am:uk)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm1_080907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm1_080907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Links goes to a very nice looking NFL site, asking to download a tracker exe file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm2_080907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm2_080907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitting the exe file to VirusTotal, shows the following current patchy results:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm3_080907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm3_080907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Detection for the email, currently: Email.Malware.Sanesecurity.070908xx (02-06)&lt;br /&gt;&lt;br /&gt;I'm sure there will be more!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5863230128355513196?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5863230128355513196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5863230128355513196' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5863230128355513196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5863230128355513196'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/stock-spam-nfl.html' title='Storm Worm Again: NFL'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6475998557073973345</id><published>2007-09-06T19:52:00.000+01:00</published><updated>2007-09-06T19:57:25.719+01:00</updated><title type='text'>storm worm: all change :)</title><content type='html'>Heads up, new storm worm incoming... oooooh... the RIAA are after everybody and worryingly&lt;br /&gt;some people might fall for this one:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm1_060907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm1_060907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;when you click on the given link, you get taken to this page, asking you to download an exe file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm2_060907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm2_060907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Current detection is a little patchy:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm3_060907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm3_060907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So far, the following Sanesecurity signatures match the variants seen so far:&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.07090600&lt;br /&gt;Email.Malware.Sanesecurity.07090601&lt;br /&gt;Email.Malware.Sanesecurity.07090602&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6475998557073973345?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6475998557073973345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6475998557073973345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6475998557073973345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6475998557073973345'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/storm-worm-all-change.html' title='storm worm: all change :)'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7983920366236712509</id><published>2007-09-04T14:27:00.000+01:00</published><updated>2007-09-04T14:29:53.702+01:00</updated><title type='text'>419 DOC spam</title><content type='html'>Here's a slightly different 419 spam:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/4191_040907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/4191_040907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The attached Word document looks like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/4192_040907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/4192_040907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Detection for this is: Email.Scam4.Gen1002.Sanesecurity.07090406.doc&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7983920366236712509?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7983920366236712509/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7983920366236712509' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7983920366236712509'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7983920366236712509'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/419-doc-spam.html' title='419 DOC spam'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6835198208968099145</id><published>2007-09-04T14:19:00.001+01:00</published><updated>2007-09-04T14:27:47.233+01:00</updated><title type='text'>storm work: labor day</title><content type='html'>Little bit late on this writeup... but no doubt you've seen these various ecards:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/strorm1_040907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/strorm1_040907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you click on the link, you can a lovely page, like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/strorm2_040907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/strorm2_040907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Which asks you to download an exe file.    Submitting the exe file to VirusTotal, give the following results:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/strorm3_040907.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/strorm3_040907.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Detection for these cards are:&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.070903xx (02-11)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6835198208968099145?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6835198208968099145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6835198208968099145' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6835198208968099145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6835198208968099145'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/09/storm-work-labor-day.html' title='storm work: labor day'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8893358447990390393</id><published>2007-08-21T19:46:00.000+01:00</published><updated>2007-08-21T20:10:25.966+01:00</updated><title type='text'>storm worm: next generation</title><content type='html'>Sorry for the late right up on this.. but it was more important to get all the signatures out this morning to cover all these variants then to do a write up.&lt;br /&gt;&lt;br /&gt;Here's one of the many variants of the storm worm "member"/"logon" emails:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm1_210807.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm1_210807.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you do click on the link you either get an auto-downloaded exe file or you get to see the following page (note: firefox pops up a warning about the page [red stop sign])&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm2_210807.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm2_210807.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The exe file you are asked to download is re-packed every 30 mins or so, to try and avoid detection by anti-virus software.   The sample above was submitted to VirusTotal with the following results:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/storm3_210807.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/storm3_210807.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Detection for all these email variants was  added about 09:30am BST as the following:&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.070821&lt;span style="font-weight: bold;"&gt;00&lt;/span&gt; to Email.Malware.Sanesecurity.070821&lt;span style="font-weight: bold;"&gt;07&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8893358447990390393?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8893358447990390393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8893358447990390393' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8893358447990390393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8893358447990390393'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/08/storm-worm-next-generation.html' title='storm worm: next generation'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7461348257161706973</id><published>2007-08-10T17:52:00.000+01:00</published><updated>2007-08-10T23:01:17.680+01:00</updated><title type='text'>Stock Spam changes format: FDF</title><content type='html'>As reported by the &lt;a href="http://www.f-secure.com/weblog/#00001246"&gt;F-Secure blog&lt;/a&gt; instead of using PDF spam, we now have  FDF formatted spam....which stands for &lt;span style="font-weight: bold;"&gt;format data format&lt;/span&gt;, used by various PDF readers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update:&lt;/span&gt; it appears that all is not what it seems:  the first few bytes of the .FDF file are actually&lt;span style="font-family: monospace;"&gt; &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;%PDF-1.5&lt;/span&gt;, which means that all the spammers have done is renamed the extension from .PDF to .FDF.    A real .FDF file has the magic-bytes &lt;span style="font-size:-1;"&gt;%&lt;b&gt;FDF-1.2&lt;/b&gt;&lt;/span&gt;.  The pdf readers just open it as a PDF because of the magic-bytes.  Sneaky&lt;br /&gt;&lt;br /&gt;Here's an example email that came in:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fdf_stock1_100807.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fdf_stock1_100807.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And here's it's contents:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fdf_stock2_100807.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fdf_stock2_100807.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note the random hex number (shown in red) which is used by the spammers to change the Adobe encrypted contents of the file, so it's hard to detect a pattern, ie: you can't use an md5 hash of the file (just like the problems caused by the image spams)&lt;br /&gt;&lt;br /&gt;The good news is, that although this was a new technique that the spammers used... it was already 0-hour protected by signature: Email.Stk.Gen606.Sanesecurity.07080101.pdf &lt;br /&gt;&lt;br /&gt;Which was nice :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7461348257161706973?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7461348257161706973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7461348257161706973' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7461348257161706973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7461348257161706973'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/08/stock-spam-changes-format-fdf.html' title='Stock Spam changes format: FDF'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4600679196257802397</id><published>2007-08-10T07:33:00.001+01:00</published><updated>2007-08-10T07:41:18.981+01:00</updated><title type='text'>New E-Card Storm Worm</title><content type='html'>Incoming....&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ecard1_100807.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ecard1_100807.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ecard1_100807.png"&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Email.Malware.Sanesecurity.070810xx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4600679196257802397?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4600679196257802397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4600679196257802397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4600679196257802397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4600679196257802397'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/08/new-e-card-storm-worm.html' title='New E-Card Storm Worm'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3792126046060376499</id><published>2007-07-31T19:48:00.000+01:00</published><updated>2007-07-31T19:49:56.380+01:00</updated><title type='text'>Important: signature location</title><content type='html'>Well after hitting 25 gig of bandwidth again this month, it's time to force people to move over to the latest round-robin urls. So, if your using an old script then you will no longer be receiving the Sanesecurity signatures, as the phish and scam databases at the old download locations have now been blanked.&lt;br /&gt;&lt;br /&gt;use the updated scripts from the usage page;&lt;br /&gt;&lt;br /&gt;round-robin urls:&lt;br /&gt;&lt;br /&gt;http://www.sanesecurity.com/clamav/phishsigs/phish.ndb.gz&lt;br /&gt;http://www.sanesecurity.com/clamav/scamsigs/scam.ndb.gz&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3792126046060376499?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3792126046060376499/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3792126046060376499' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3792126046060376499'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3792126046060376499'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/important-signature-location.html' title='Important: signature location'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-749988448714145467</id><published>2007-07-31T08:29:00.000+01:00</published><updated>2007-07-31T08:33:10.575+01:00</updated><title type='text'>stock spam evolve again... to zip... erm... rar</title><content type='html'>Well, spammers have again this morning changed tactics again... were now seeing a  standard text stock spam... inside what looks like a zip file.&lt;br /&gt;&lt;br /&gt;However, looking at the zip file.. it's actually a rar file... another confusing trick.&lt;br /&gt;&lt;br /&gt;Detection added as: Email.Stk.Gen603.Sanesecurity.07073100.zip&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-749988448714145467?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/749988448714145467/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=749988448714145467' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/749988448714145467'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/749988448714145467'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/stock-spam-evolve-again-to-zip-erm-rar.html' title='stock spam evolve again... to zip... erm... rar'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1298502335537178438</id><published>2007-07-22T23:07:00.000+01:00</published><updated>2007-07-22T23:10:59.956+01:00</updated><title type='text'>From PDF to XLS to Zipped XLS: Stock spam</title><content type='html'>Received another variant of the XLS stock spam... this time... the spammers are zipping the XLS stock spreadsheet.&lt;br /&gt;&lt;br /&gt;Sample Received date: 22 Jul 2007 15:48:20 +0200&lt;br /&gt;&lt;br /&gt;Signature Email.Stk.Gen598.Sanesecurity.07072000.xls from yesterday already detected it :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1298502335537178438?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1298502335537178438/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1298502335537178438' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1298502335537178438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1298502335537178438'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/from-pdf-to-xls-to-zipped-xls-stock.html' title='From PDF to XLS to Zipped XLS: Stock spam'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-878732971666393134</id><published>2007-07-21T21:49:00.000+01:00</published><updated>2007-07-21T22:03:29.174+01:00</updated><title type='text'>From PDF to XLS: Stock spam</title><content type='html'>Well well, the spammers change tactics yet again, from the image spam and the pdf spam... to the downright sneeky Excel spreadsheet spam. &lt;br /&gt;&lt;br /&gt;As most companies use XLS (and PDF for that matter) the spammers know that companies won't block these extension types, as it'll stop genuine email too.&lt;br /&gt;&lt;br /&gt;21st July 2007 timeline&lt;br /&gt;&lt;br /&gt;At 16:11 UK time, I received an interesting stock spam  sample and started to analyse; &lt;br /&gt;At 17:00 UK time, I was received five more samples.... all XLS spreadsheets.&lt;br /&gt;&lt;br /&gt;At 18:05 UK time, the first signature was uploaded to the mirrors:&lt;br /&gt;&lt;br /&gt;Email.Stk.Gen598.Sanesecurity.07072000.xls&lt;br /&gt;&lt;br /&gt;Here's  a screenshot:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/xlxstk1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/xlxstk1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Wonder what format is going to be next for the spammers?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-878732971666393134?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/878732971666393134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=878732971666393134' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/878732971666393134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/878732971666393134'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/from-pdf-to-xls-stock-spam.html' title='From PDF to XLS: Stock spam'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3054123295880708510</id><published>2007-07-16T15:19:00.000+01:00</published><updated>2007-07-16T15:22:11.005+01:00</updated><title type='text'>Phishers go Green!</title><content type='html'>It's nice to know that even the phishers care about saving the planet, I mean it looks legit:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gogreen1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gogreen1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;... well, apart from hsbc.co.uk with a .hk domain ending:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gogreen2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gogreen2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3054123295880708510?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3054123295880708510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3054123295880708510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3054123295880708510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3054123295880708510'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/phishers-go-green.html' title='Phishers go Green!'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5226834607572903715</id><published>2007-07-05T16:01:00.000+01:00</published><updated>2007-07-05T16:05:21.527+01:00</updated><title type='text'>Digg Post</title><content type='html'>Here's a post on Digg from a user, for a bit of useful sounding software:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/digg1_040707.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/digg1_040707.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When you click on the link, you are taken to a download site:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/digg2_040707.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/digg2_040707.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Scanning the download file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/digg3_040707.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/digg3_040707.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, is this just a false positive or a different way of getting malware out to the world ??&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5226834607572903715?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5226834607572903715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5226834607572903715' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5226834607572903715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5226834607572903715'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/digg-post.html' title='Digg Post'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-538609933592293967</id><published>2007-07-05T15:55:00.001+01:00</published><updated>2007-07-05T15:59:21.217+01:00</updated><title type='text'>PayPal phish using a word document</title><content type='html'>Here's a phish that came in from PayPal which contained a word document.  &lt;br /&gt;&lt;br /&gt;As the email used an image for the main text body and a word document, the phisher no doubt thought it would bypass filters.&lt;br /&gt;&lt;br /&gt;Here's the main email:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ppay1_020707.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ppay1_020707.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here's the content of the word document:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ppay2_020707.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ppay2_020707.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ppay3_020707.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ppay3_020707.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-538609933592293967?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/538609933592293967/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=538609933592293967' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/538609933592293967'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/538609933592293967'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/07/paypal-phish-using-word-document.html' title='PayPal phish using a word document'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4756682895018035891</id><published>2007-06-26T08:26:00.000+01:00</published><updated>2007-06-26T12:50:08.002+01:00</updated><title type='text'>stock spam evolve: new syle pdfs</title><content type='html'>Spammers have now come up with a new style of stock emails.&lt;br /&gt;&lt;br /&gt;First they used just plain text, next they used static image files.    Next, they used random image files, all to avoid filtering.&lt;br /&gt;&lt;br /&gt;Due to people starting to use FuzzyOcr,  the stock spammers, moved into pdfs.&lt;br /&gt;&lt;br /&gt;The pdfs contained plain text, which again using the right tools can be  filtered.&lt;br /&gt;&lt;br /&gt;This morning, the "next generation" appeared; pdf's with random images embedded in the pdf :(&lt;br /&gt;&lt;br /&gt;Firstly, here's the email you receive:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stkpdf1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stkpdf1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pdf example 1:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stkpdf3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stkpdf3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pdf example 2:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stkpdf2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stkpdf2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Interestingly, both pdfs would not open in a couple of the free pdf readers but they seem to open fine in Adobe Pdf reader.&lt;br /&gt;&lt;br /&gt;Initial detection of this varient has been added as: Email.Stk.Gen538.Sanesecurity.07062600.pdf&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update (12:45):  &lt;/span&gt;more new varients using random pdf filenames  now!&lt;br /&gt;&lt;br /&gt;Pdf example 3:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stkpdf4.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stkpdf4.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pdf example 4:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stkpdf5.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stkpdf5.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pdf example 5:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stkpdf6.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stkpdf6.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4756682895018035891?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4756682895018035891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4756682895018035891' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4756682895018035891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4756682895018035891'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/06/stock-spam-evolve-new-syle-pdfs.html' title='stock spam evolve: new syle pdfs'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8989912632876051089</id><published>2007-06-18T10:51:00.000+01:00</published><updated>2007-06-18T18:55:13.492+01:00</updated><title type='text'>Greeting Card: fun.exe</title><content type='html'>ISC has an interesting article on an &lt;a href="http://isc.sans.org/diary.html?storyid=2985"&gt;Attack involving .hk domains&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So, perhaps this is a related attack.&lt;br /&gt;&lt;br /&gt;It starts with a greeting card:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard1_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard1_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you've not got Javascript enabled, you'll see this screen, where the file it wan't you do download is on a .hk server and the exe is called fun.exe:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard2_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard2_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Looking deeper at the code, it's doing something iffy:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard3_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard3_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you do click on the link, you are served an exe file, which when submitted to VirusTotal gives you this result:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard4_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard4_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Again, coverage not too hot :(&lt;br /&gt;&lt;br /&gt;Currently detected as: Email.Malware.Sanesecurity.07061701&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8989912632876051089?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8989912632876051089/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8989912632876051089' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8989912632876051089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8989912632876051089'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/06/greeting-card-funexe.html' title='Greeting Card: fun.exe'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-49205308947339290</id><published>2007-06-18T10:45:00.000+01:00</published><updated>2007-06-18T12:38:44.579+01:00</updated><title type='text'>Greeting card</title><content type='html'>Received a whole load of these "greeting cards" this morning:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ecard1_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ecard1_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The fake site you visit has some "re-direct" code:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ecard2_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ecard2_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you do actually go to the site, it'll look something like this, followed by an auto-download of&lt;br /&gt;the "flash-player" needed:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ecard3_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ecard3_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitting the exe file to VirusTotal reveals, surprise surprise... it's not a flash-player:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ecard4_180607.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ecard4_180607.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The email is currently being detected as: Email.Malware.Sanesecurity.07061801&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-49205308947339290?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/49205308947339290/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=49205308947339290' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/49205308947339290'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/49205308947339290'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/06/greeting-card.html' title='Greeting card'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8281578380382630727</id><published>2007-06-18T09:51:00.001+01:00</published><updated>2007-06-18T09:55:18.923+01:00</updated><title type='text'>Free Video malware</title><content type='html'>Received a few copies of this email this morning, which as you can see, is asking to click on a link to download an exe file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fv1.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fv1.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the source code, they've tried to hide the contents by encoding the email with base64:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fv2.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fv2.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Submitting the exe file to VirusTotal, gives us this worrying picture:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fv3.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fv3.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hopefully, now it's been submitted to VirusTotal, more AV's will add detection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8281578380382630727?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8281578380382630727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8281578380382630727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8281578380382630727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8281578380382630727'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/06/free-video-malware.html' title='Free Video malware'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-285964694027774736</id><published>2007-05-26T07:48:00.000+01:00</published><updated>2007-05-26T08:01:21.297+01:00</updated><title type='text'>rtf malware spam</title><content type='html'>This seems to be a new formatted malware spam going around, along the same lines as the "&lt;a href="http://isc.sans.org/index.html?isc=335984a4f495d0579c6654648eab8e7a"&gt;Better Business Bureau targeted malware spam&lt;/a&gt;" that SANS reported today.&lt;br /&gt;&lt;br /&gt;Here's a screenshot from the new style spam:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/rtf_malware1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/rtf_malware1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you go to the top level directory of the domain that's hosting the file, you can see an open directory:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/rtf_malware2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/rtf_malware2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What's interesting is the date of the actual "bad" RTF file, 9th May 2007... so as it's been there a while now, let see how the Anti-Virus scanners coped:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Complete scanning result of "superpages.rtf", received in VirusTotal at 05.26.2007, 08:23:20 (CET).&lt;br /&gt;&lt;br /&gt;AhnLab-V3    2007.5.24.0    05.25.2007    no virus found&lt;br /&gt;AntiVir    7.4.0.27    05.25.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Authentium&lt;/span&gt;    4.93.8    05.23.2007    &lt;span style="font-weight: bold;"&gt;Possibly a new variant of W32/CrazyCrunch-based!Maximus&lt;/span&gt;&lt;br /&gt;Avast    4.7.997.0    05.25.2007    no virus found&lt;br /&gt;AVG    7.5.0.467    05.25.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;BitDefender&lt;/span&gt;    7.2    05.26.2007    &lt;span style="font-weight: bold;"&gt;Trojan.Spy.Agent.NDQ&lt;/span&gt;&lt;br /&gt;CAT-QuickHeal    9.00    05.25.2007    no virus found&lt;br /&gt;ClamAV    devel-20070416    05.25.2007    no virus found&lt;br /&gt;DrWeb    4.33    05.25.2007    no virus found&lt;br /&gt;eSafe    7.0.15.0    05.24.2007    no virus found&lt;br /&gt;eTrust-Vet    30.7.3665    05.26.2007    no virus found&lt;br /&gt;Ewido    4.0    05.25.2007    no virus found&lt;br /&gt;FileAdvisor    1    05.26.2007    no virus found&lt;br /&gt;Fortinet    2.85.0.0    05.26.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;F-Prot&lt;/span&gt;    4.3.2.48    05.25.2007    &lt;span style="font-weight: bold;"&gt;W32/CrazyCrunch-based!Maximus&lt;/span&gt;&lt;br /&gt;Ikarus    T3.1.1.8    05.26.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Kaspersky&lt;/span&gt;    4.0.2.24    05.26.2007    &lt;span style="font-weight: bold;"&gt;Trojan-Spy.Win32.Delf.jq&lt;/span&gt;&lt;br /&gt;McAfee    5039    05.25.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Microsoft &lt;/span&gt;   1.2503    05.26.2007   &lt;span style="font-weight: bold;"&gt; TrojanSpy:Win32/Logsnif.gen&lt;/span&gt;&lt;br /&gt;NOD32v2    2292    05.25.2007    no virus found&lt;br /&gt;Norman    5.80.02    05.25.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Panda &lt;/span&gt;   9.0.0.4    05.25.2007    &lt;span style="font-weight: bold;"&gt;Trj/Passtealer.DE&lt;/span&gt;&lt;br /&gt;Prevx1    V2    05.26.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Sophos&lt;/span&gt;    4.18.0    05.25.2007    &lt;span style="font-weight: bold;"&gt;Troj/Agent-FPG&lt;/span&gt;&lt;br /&gt;Sunbelt    2.2.907.0    05.26.2007    no virus found&lt;br /&gt;Symantec    10    05.26.2007    no virus found&lt;br /&gt;TheHacker    6.1.6.123    05.25.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;VBA32 &lt;/span&gt;   3.12.0    05.26.2007    &lt;span style="font-weight: bold;"&gt;suspected of Malware.Delf.43&lt;/span&gt;&lt;br /&gt;VirusBuster    4.3.23:9    05.25.2007    no virus found&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Webwasher-Gateway&lt;/span&gt;    6.0.1    05.26.2007    &lt;span style="font-weight: bold;"&gt;Trojan.Spy.Delf.JQ.112 (suspicious)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Aditional Information&lt;br /&gt;File size: 157686 bytes&lt;br /&gt;MD5: d948f4b41be0aee7b3bd292e33082313&lt;br /&gt;SHA1: 5e4f9655effbcb7ff8f03f05a6a4f778bf9a54f6&lt;br /&gt;packers: UPX&lt;br /&gt;packers: UPX, BINARYRES, UPX&lt;br /&gt;packers: UPX&lt;br /&gt;&lt;/blockquote&gt;Hopefully this will improve now that VirusTotal have the file. Until then... I've added a simple detection for this new type:  Html.Malware.Sanesecurity.07052600&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-285964694027774736?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/285964694027774736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=285964694027774736' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/285964694027774736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/285964694027774736'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/rtf-malware-spam.html' title='rtf malware spam'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7317102315361882681</id><published>2007-05-24T12:49:00.000+01:00</published><updated>2007-05-24T12:54:21.837+01:00</updated><title type='text'>OpenDNS</title><content type='html'>OpenDNS.... maybe you've heard of it... but it's so easy to setup... and free... try it :)&lt;br /&gt;&lt;br /&gt;OpenDNS replaces your ISP's dns servers... but with one important improvement... OpenDNS will warn you if a site or link you have just clicked on...  is a known phishing site!&lt;br /&gt;&lt;br /&gt;Use it as a backup to the normal FireFox/IE phishing toolbar plugins.&lt;br /&gt;&lt;br /&gt;More info &lt;a href="http://www.opendns.com/start/windows.php"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7317102315361882681?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7317102315361882681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7317102315361882681' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7317102315361882681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7317102315361882681'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/opendns.html' title='OpenDNS'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3917148396120073237</id><published>2007-05-24T11:48:00.000+01:00</published><updated>2007-05-24T12:05:49.125+01:00</updated><title type='text'>Another mailto eBay phish</title><content type='html'>Here's a genuine looking eBay phishing attempt that came in today.   As you can see all the links point back to the genuine eBay site:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ebay1_240507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ebay1_240507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It's only when you view the source code that you notice that something doesn't seem right with this email.   You can see that if you did try and login to eBay directly from this email, your eBay login details would be kindly sent to seflab...@yahoo.com via the mailto server mailhost.dglnet.com.br:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ebay2_240507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ebay2_240507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, lets take a look at mailhost.dglnet.com.br.   Well, looks like they are running &lt;a href="http://www.blogger.com/www.squirrelmail.org/"&gt;squirrelmail&lt;/a&gt; but let's checkout the version number.... hmmm... v1.4.4:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ebay3_240507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ebay3_240507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Let's go to the main &lt;a href="http://www.blogger.com/www.squirrelmail.org/"&gt;squirrelmail&lt;/a&gt; site and see what version is the current one.    Well, the latest one is:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;SquirrelMail 1.4.10a Released&lt;/b&gt;&lt;br /&gt;&lt;small&gt;&lt;span style="color: rgb(85, 85, 85);"&gt;&lt;i&gt;May 09, 2007 by Thijs Kinkhorst&lt;/i&gt;&lt;/span&gt;&lt;/small&gt;&lt;br /&gt;&lt;table border="0" cellpadding="0" cellspacing="0" width="100%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td width="15"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td&gt;   The SquirrelMail Project Team is proud to announce the release of SquirrelMail 1.4.10a. &lt;p&gt; The 1.4.10 release contains &lt;span style="font-weight: bold;"&gt;multiple fixes for cross site scripting issues&lt;/span&gt; triggered by viewing HTML mail. Besides that it contains bug fixes and stability enhancements&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;The version before that looks something like this changelog wise:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/ebay4_240507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/ebay4_240507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Are the any problems with running older versions... yep...&lt;a href="http://www.securityfocus.com/bid/23910"&gt; just a few&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;So, looks like keeping webmail software up to date is a must.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3917148396120073237?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3917148396120073237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3917148396120073237' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3917148396120073237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3917148396120073237'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/another-mailto-ebay-phish.html' title='Another mailto eBay phish'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5248191101272326196</id><published>2007-05-22T19:59:00.000+01:00</published><updated>2007-05-22T20:04:13.632+01:00</updated><title type='text'>News Update</title><content type='html'>Just a quick news update:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Thanks to Internet Solutions we now have another mirror, live from South Africa&lt;/li&gt;&lt;li&gt;Thanks to FreeForm Technologies we now have another mirror&lt;/li&gt;&lt;li&gt;Thanks to Geekeffect there is now another download mirror&lt;br /&gt;  &lt;/li&gt;&lt;/ul&gt;So, just a reminder,  the new download urls are:&lt;br /&gt;&lt;br /&gt;http://www.sanesecurity.com/clamav/phishsigs/phish.ndb.gz&lt;br /&gt;http://www.sanesecurity.com/clamav/scamsigs/scam.ndb.gz&lt;br /&gt;&lt;br /&gt;Quote of the day: Isn't smooth peanut butter for the timid and the weak? (happyslip.com)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5248191101272326196?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5248191101272326196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5248191101272326196' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5248191101272326196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5248191101272326196'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/news-update.html' title='News Update'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-7103292786995695248</id><published>2007-05-21T20:00:00.000+01:00</published><updated>2007-05-22T19:59:21.520+01:00</updated><title type='text'>Signatures added in May...</title><content type='html'>I knew this month... things seem to have jumped in the number of new phishing/scam emails. So I thought I'd just have a very quick look at how many sigs I'd actually done in May (so far) and compare with how many I'd done in the while of April:&lt;br /&gt;&lt;br /&gt;May (so far):&lt;br /&gt;&lt;br /&gt;phish.ndb.gz: 296 new sigs&lt;br /&gt;scam.ndb.gz: 539 new sigs&lt;br /&gt;&lt;br /&gt;April:&lt;br /&gt;&lt;br /&gt;phish.ndb.gz: 139 new sigs&lt;br /&gt;scam.ndb.gz: 377 new sigs&lt;br /&gt;&lt;br /&gt;No wonder my fingers ache :(&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-7103292786995695248?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/7103292786995695248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=7103292786995695248' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7103292786995695248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/7103292786995695248'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/signatures-add-in-may.html' title='Signatures added in May...'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8582762064286906606</id><published>2007-05-18T10:07:00.000+01:00</published><updated>2007-05-18T10:17:54.045+01:00</updated><title type='text'>New type of Fake BlueMountain eCard</title><content type='html'>Here's a new type of fake eCard.   Normally you can spot them a mile away, as they have links to exe/scr/pif files. when you hover your mouse of the link.&lt;br /&gt;&lt;br /&gt;This one however, this one doesn't have any of the above type... just a genuine looking attach dll filename, which would make sense as it's an attachment:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/FlashPlayer_eCard1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/FlashPlayer_eCard1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;However, if you do click on the link, you are asked to download a file called FlashPlayer_eCard.exe, which again you might think it okay... as the above email does suggest that you might have to use Macromedia Flash Plug-in.&lt;br /&gt;&lt;br /&gt;But submitting the file to VirusTotal, well... not good:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/FlashPlayer_eCard2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/FlashPlayer_eCard2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bancos family malware are usually password-stealing Trojans which can also downloads code.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8582762064286906606?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8582762064286906606/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8582762064286906606' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8582762064286906606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8582762064286906606'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/new-type-of-fake-bluemountain-ecard.html' title='New type of Fake BlueMountain eCard'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6981695978100792345</id><published>2007-05-17T13:31:00.000+01:00</published><updated>2007-05-17T13:38:02.974+01:00</updated><title type='text'>example phish hosted by home user?</title><content type='html'>Here's the fake screen that you get when you click on one particular phishing email:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/static1_170507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/static1_170507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What's interesting is that static address, which indicates a possible broadband hosted, static ip address website.   Visiting the top level, you get a nice "hello world" type website.   As you can see it's using &lt;a href="http://sourceforge.net/projects/phptriad/"&gt;PHPTriad&lt;/a&gt; which is an installer of Apache, MySQL and PHP for Windows.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/static2_170507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/static2_170507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, did this user knowingly host a phishing site using PHPTriad... or was this software installed using a trojan, without the users knowledge?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6981695978100792345?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6981695978100792345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6981695978100792345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6981695978100792345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6981695978100792345'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/example-phish-hosted-by-home-user.html' title='example phish hosted by home user?'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-9213803672222873697</id><published>2007-05-16T15:44:00.000+01:00</published><updated>2007-05-16T15:56:26.938+01:00</updated><title type='text'>Posteitaliane Phish: under the hood</title><content type='html'>Here's an example phish that arrived today:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/bank1_160507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/bank1_160507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The clickable link, wants to go to a formlogin.txt, as you can see below,  yep... that's a dot txt extension !&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/bank2_160507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/bank2_160507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here's the interesting bit of the formlogin.txt file, yep... if you'd typed in your banking details, you'd be now sending them to the nice phisher, who seems to like his 007 yahoo address:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/bank3_160507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/bank3_160507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here's the timestamps when all the fake files were created, as you can see, if you look back at the time/date of the original phishing email, the emails were sent out to people very quickly :(&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/bank4_160507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/bank4_160507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And finally... here's the web gateway that was used to send the banking details to the yahoo email adress:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/bank5_160507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/bank5_160507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-9213803672222873697?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/9213803672222873697/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=9213803672222873697' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/9213803672222873697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/9213803672222873697'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/posteitaliane-phish-under-hood.html' title='Posteitaliane Phish: under the hood'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3050931327788197797</id><published>2007-05-16T09:01:00.000+01:00</published><updated>2007-05-16T09:18:40.430+01:00</updated><title type='text'>Ebay phish in different email clients</title><content type='html'>I've been asked why an Ebay phish was detected, even though it doesn't seem to re-direct to a fake site.   This reason for this could be a false positive... but having looked at the example, it's not a false positive... but a difference in email clients.&lt;br /&gt;&lt;br /&gt;Here's the Ebay phishing attempt:&lt;br /&gt;&lt;br /&gt;Outlook Express:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/phish_oe1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/phish_oe1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thunderbird:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/phish_tb1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/phish_tb1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;You can see already a slight difference between the clients.   If you look at the link bar at the bottom, one seems to go to ebay.com and the other to signin.ebay.com&lt;br /&gt;&lt;br /&gt;If you click on the link in Outlook Express, you are taken to the fake page (which FireFox knows is a fake).  You can see in the browser url that the site is fake, i.e.:   h-sohbi.com&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/phish_oe2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/phish_oe2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you click on the link in Thunderbird, you get taken to the genuine Ebay page:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/phish_tb2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/phish_tb2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Huh?  Taking a closer look at the phishing code, you can see the phisher has kindly labeled the ID as SPOOF:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/phish_oe3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/phish_oe3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, looks like this code renders differently between Outlook Express and Thunderbird, so that's why you get taken to two different sites depending on which email client you are using.&lt;br /&gt;&lt;br /&gt;Strike one up for Thunderbird :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3050931327788197797?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3050931327788197797/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3050931327788197797' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3050931327788197797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3050931327788197797'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/ebay-phish-in-different-email-clients.html' title='Ebay phish in different email clients'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6702967939892086399</id><published>2007-05-15T21:12:00.000+01:00</published><updated>2007-05-15T21:14:08.390+01:00</updated><title type='text'>New download urls.... Go</title><content type='html'>&lt;span style="font-family:Verdana, Arial, Helvetica, sans-serif;font-size:85%;"&gt;                 It's been a busy couple of weeks, not only does there seem to                 have been a huge increase in the number of new phishing emails                 but also an increase in the number of problem scams.&lt;br /&gt;&lt;br /&gt;It's been                 hard to keep up at times!&lt;br /&gt;               &lt;br /&gt;                The main news is the new download urls, which are:&lt;br /&gt;               &lt;br /&gt;                http://www.sanesecurity.com/clamav/phishsigs/phish.ndb.gz&lt;br /&gt;                http://www.sanesecurity.com/clamav/scamsigs/scam.ndb.gz&lt;br /&gt;               &lt;br /&gt;                The above two links will now re-direct, round-robin style, to                 the new mirrors that people have "donated" in order to help the                 project.&lt;br /&gt;&lt;br /&gt;A huge thanks to the mirror providers, Christopher                 X. Candreva for the .htaccess code/idea and tbb (Nico) for pointing                 me torward the round-robin script...in order to make this all                 work.&lt;br /&gt;&lt;br /&gt;Thanks guys!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6702967939892086399?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6702967939892086399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6702967939892086399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6702967939892086399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6702967939892086399'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/new-download-urls-go.html' title='New download urls.... Go'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5329751539767908968</id><published>2007-05-15T21:07:00.000+01:00</published><updated>2007-05-15T21:12:19.475+01:00</updated><title type='text'>More image spam... sort of...</title><content type='html'>We also got hit this morning with another slight varient of the German stock spam.   This time, there isn't any image in the email.   I'm guessing this is to avoid programs like FuzzyOCR, which are helping to detect the images in the email.&lt;br /&gt;&lt;br /&gt;This simple "trick" is to use the free picture gallery sites to host their images.&lt;br /&gt;&lt;br /&gt;The email you receive is a bit like this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stk2_150507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stk2_150507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you do actually click on the link, you get this standard "scrambled" image:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stk3_150507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stk3_150507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The question is... how do the spammers setup soo many random accounts on these free hosting servers before their spam runs and what can the picture hosting companies do about it?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5329751539767908968?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5329751539767908968/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5329751539767908968' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5329751539767908968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5329751539767908968'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/more-image-spam-sort-of.html' title='More image spam... sort of...'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1570763074860615770</id><published>2007-05-15T21:04:00.000+01:00</published><updated>2007-05-15T21:07:18.994+01:00</updated><title type='text'>Image Stock Spam...arrrggghh</title><content type='html'>Wow... we got hit hard this morning with a new type of German Image stock spam. &lt;br /&gt;&lt;br /&gt;Here's a picture for those people who were luckly enough to miss this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/stk1_150507.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/stk1_150507.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1570763074860615770?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1570763074860615770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1570763074860615770' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1570763074860615770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1570763074860615770'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/image-stock-spamarrrggghh.html' title='Image Stock Spam...arrrggghh'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6577620725260632916</id><published>2007-05-13T20:08:00.000+01:00</published><updated>2007-05-13T20:10:36.764+01:00</updated><title type='text'>Fake Halifax Bank</title><content type='html'>Here's a pretty convincing Halifax Bank phish... in fact, it's just a copy/paste job from a geninue Halifax email, with just the target url changed to point to the phishers site:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/halifax1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/halifax1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Look at the bottom link... see the .co.kr (Korea)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6577620725260632916?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6577620725260632916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6577620725260632916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6577620725260632916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6577620725260632916'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/fake-halifax-bank.html' title='Fake Halifax Bank'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5869237608717760755</id><published>2007-05-13T20:03:00.000+01:00</published><updated>2007-05-13T20:06:34.707+01:00</updated><title type='text'>Fake Google webmaster tool</title><content type='html'>Bit late with this post... but seems Google's name is being as a ploy to download sometype of malware:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fakegoogle.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fakegoogle.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Yep, it's a fake!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5869237608717760755?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5869237608717760755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5869237608717760755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5869237608717760755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5869237608717760755'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/fake-google-webmaster-tool.html' title='Fake Google webmaster tool'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-8847417515316757283</id><published>2007-05-13T19:57:00.000+01:00</published><updated>2007-05-13T20:02:26.212+01:00</updated><title type='text'>new rockfish type?</title><content type='html'>Hi All,&lt;br /&gt;&lt;br /&gt;Not quite sure if this is a new type of phish using a new template... or the rockfish toolkit has been updated, here's an example:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/rockv2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/rockv2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These will be detected as a new type: Phishing.Bank.Rockv2Gen&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-8847417515316757283?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/8847417515316757283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=8847417515316757283' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8847417515316757283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/8847417515316757283'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/new-rockfish-type.html' title='new rockfish type?'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2520248335149980010</id><published>2007-05-05T23:32:00.000+01:00</published><updated>2007-05-05T23:38:12.818+01:00</updated><title type='text'>Marks and Spencer laptop theft</title><content type='html'>&lt;p&gt;It doesn't seem like they've heard of &lt;a href="http://www.truecrypt.org/"&gt;TrueCrypt&lt;/a&gt; or perhaps they should start using Seagate drives like &lt;a href="http://www.techworld.com/security/news/index.cfm?newsid=8227"&gt;this&lt;/a&gt;:&lt;br /&gt;&lt;/p&gt;&lt;p&gt;"More than 20,000 staff at Marks &amp;amp; Spencer have been told they may be at risk of identity crime after a laptop computer was stolen, it has been reported.&lt;/p&gt;&lt;p&gt;The retailer has written to 26,000 present employees in its final salary pension scheme warning they are at risk if the data is accessed by criminals.&lt;/p&gt;                                                                                &lt;p&gt;BBC Radio 4 said salary details, addresses, dates of birth, national insurance and phone numbers were on the machine, which was stolen from a printing firm."&lt;/p&gt;Source: &lt;a href="http://www.channel4.com/news/articles/uk/laptop+theft+risk+to+ms+staff+ids/499687#fold"&gt;http://www.channel4.com/news/articles/uk/laptop+theft+risk+to+ms+staff+ids/499687#fold&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-2520248335149980010?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2520248335149980010/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2520248335149980010' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2520248335149980010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2520248335149980010'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/marks-and-spencer-laptop-theft.html' title='Marks and Spencer laptop theft'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-298712123562655719</id><published>2007-05-05T21:04:00.000+01:00</published><updated>2007-05-05T21:07:27.141+01:00</updated><title type='text'>Sanesecurity Sigs: Important News</title><content type='html'>&lt;pre wrap=""&gt;Due to me nearly running out of bandwidth last month (17gb out of a 20gb host package), some urgent changes were needed to the signature hosting,otherwise I'd start getting charged for the extra bandwidth &lt;span class="moz-smiley-s2"&gt;&lt;span&gt; :( &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So, to keep this short, here's a to-do list &lt;span class="moz-smiley-s3"&gt;&lt;span&gt; ;) &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;One: Mirrors&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Three new mirrors are now available, in preferred order:&lt;br /&gt;&lt;br /&gt;Mirror 1: A huge thanks to &lt;a class="moz-txt-link-freetext" href="http://dotsrc.org/"&gt;http://dotsrc.org/&lt;/a&gt; (formerly known as SunSITE.dk) as they are now a mirror for my signatures, hourly updating from the main site.&lt;br /&gt;&lt;br /&gt;Mirror 2: Thanks to &lt;a class="moz-txt-link-freetext" href="http://tiscali.nl/"&gt;http://tiscali.nl&lt;/a&gt;, as they seem to be a mirror for my signatures,  hourly updating from the main site&lt;br /&gt;&lt;br /&gt;Mirror 3: Thanks to a special offer deal from Surpass Hosting, I setup a sanesecurity.co.uk domain, to try and ease the load from the main sanesecurity.com site.&lt;br /&gt;&lt;br /&gt;So, please could you all change your download scripts to download from the above mirrors, not only will this help avoid me getting hit with hosting charges but you benefit as you should be able to increase the frequency you check for download changes.&lt;br /&gt;&lt;br /&gt;The new download Links have been updated on the download page and so have the scripts:&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://sanesecurity.co.uk/clamav/downloads.htm"&gt;http://sanesecurity.co.uk/clamav/downloads.htm&lt;/a&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://sanesecurity.co.uk/clamav/usage.htm"&gt;http://sanesecurity.co.uk/clamav/usage.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Two: check your download scripts&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Please could everyone check that their scripts are only grabbing the signatures when they have changed.   Some users have been downloading the sigs regardless of any changes and it's not really helping.  While other users have made mistakes with their scripts/cron jobs and are trying to download every minute &lt;span class="moz-smiley-s2"&gt;&lt;span&gt; :(&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;That's it and thanks for everyone's understanding!&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Steve&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-298712123562655719?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/298712123562655719/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=298712123562655719' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/298712123562655719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/298712123562655719'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/sanesecurity-sigs-important-news.html' title='Sanesecurity Sigs: Important News'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1338695118679835078</id><published>2007-05-05T12:45:00.000+01:00</published><updated>2007-05-06T17:58:31.134+01:00</updated><title type='text'>Fake IE7 update</title><content type='html'>Well, it looks like a new spam run of the fake IE7 beta is now going around again, this is currently being detected as: Email.Malware.Sanesecurity.07050500&lt;br /&gt;&lt;br /&gt;As you can see there's a link to an exe file, when you hovver your mouse over the picture:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/fakeie7.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/fakeie7.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The exe in question is another Trojan:  &lt;a href="http://www.f-secure.com/v-descs/trojan-proxy_w32_grum_a.shtml"&gt;TR/Proxy/Agent.CL&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1338695118679835078?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1338695118679835078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1338695118679835078' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1338695118679835078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1338695118679835078'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/fake-ie7-update.html' title='Fake IE7 update'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2326332733197034880</id><published>2007-05-04T19:48:00.000+01:00</published><updated>2007-05-04T19:51:48.338+01:00</updated><title type='text'>Trust No One: MS Needs Your Credit Card Details</title><content type='html'>Trojan.Kardphisher creates a genuine looking Microsoft Activation screen, the next time your pc re-boots... it asks you for your credit card details as part of the fake Activation!&lt;br /&gt;&lt;br /&gt;Very crafty...&lt;br /&gt;&lt;br /&gt;"This Trojan teaches us all a good lesson - Trust No One. This is the slogan from the TV show &lt;em&gt;The X-Files&lt;/em&gt;, and very much applies when it comes to protecting your personal information. Sometimes the creators of Trojans attempt to impersonate Microsoft, a bank, or even a government organization. Whatever the warning or message says, we must make very sure it is genuine before giving up any personal details, financial or otherwise. It's far better to doubt a genuine request until proper verification is provided, than it is to blindly place your trust in a communique simply because it appears to have come from a trusted source.&lt;br /&gt;&lt;br /&gt;Sad though it may be, the days of leaving your front door unlocked are over. In these times we not only need a lock on the door, we need a security guard watching the front door, the back door, and everywhere in between."&lt;br /&gt;&lt;br /&gt;Source:&lt;br /&gt;&lt;a href="http://www.symantec.com/enterprise/security_response/weblog/2007/05/ms_needs_your_credit_card_deta.html"&gt;http://www.symantec.com/enterprise/security_response/weblog/2007/05/ms_needs_your_credit_card_deta.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-2326332733197034880?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2326332733197034880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2326332733197034880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2326332733197034880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2326332733197034880'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/trust-no-one-ms-needs-your-credit-card.html' title='Trust No One: MS Needs Your Credit Card Details'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3382157396965628908</id><published>2007-05-04T19:04:00.000+01:00</published><updated>2007-05-04T19:07:25.504+01:00</updated><title type='text'>Hackers target wi-fi hotspots in new phishing attack</title><content type='html'>Anyone who uses "free"/"open"/un-encrypted wi-fi access, should read this:&lt;br /&gt;&lt;br /&gt;"Computer users have been warned of the dangers of using wi-fi hotspots after  it emerged that cyber-criminals are targeting the networks in café chains  including Starbucks. &lt;p&gt; Times Online has uncovered evidence that criminals are using a technique known  as an 'evil twin attack', where victims think that they are logging on to  the genuine network in a café but are in fact being diverted to a 'rogue'  connection. &lt;/p&gt;&lt;p&gt; Once logged on to the twin network, the victim's every keystroke is captured  by the fraudster, who controls the connection from a nearby laptop and uses  it to extract information for the purpose of committing identity fraud."&lt;br /&gt;&lt;br /&gt;Surce:&lt;a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article1728634.ece"&gt; http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article1728634.ece&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3382157396965628908?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3382157396965628908/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3382157396965628908' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3382157396965628908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3382157396965628908'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/hackers-target-wi-fi-hotspots-in-new.html' title='Hackers target wi-fi hotspots in new phishing attack'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-3278979768654592517</id><published>2007-05-04T16:37:00.000+01:00</published><updated>2007-05-04T16:41:55.935+01:00</updated><title type='text'>new phishing idea...</title><content type='html'>Here's a slightly new idea... instead of asking you to type in any of your bank details, the phishers are asking you to scan in your important details and then email the details instead. &lt;br /&gt;&lt;br /&gt;I'm guessing they don't really care what format you send the infomation in, eg: pdf/tiff etc.  as long as it contains all your details...  needless to say...  dont!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/visascan1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/visascan1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-3278979768654592517?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/3278979768654592517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=3278979768654592517' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3278979768654592517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/3278979768654592517'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/new-phishing-idea.html' title='new phishing idea...'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5276480683577730216</id><published>2007-05-04T16:31:00.000+01:00</published><updated>2007-05-04T16:33:43.558+01:00</updated><title type='text'>Another post card</title><content type='html'>Seems postcards are still being sent out to people... here's another example:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/card1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/card1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And here's what you get... if you did decide to click on the link:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/card2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/card2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5276480683577730216?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5276480683577730216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5276480683577730216' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5276480683577730216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5276480683577730216'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/another-post-card.html' title='Another post card'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-5148354889858485963</id><published>2007-05-03T20:57:00.000+01:00</published><updated>2007-05-03T21:02:59.722+01:00</updated><title type='text'>Watch those url spellings...</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;I've seen various PayPal phishing emails today, all the same... except that the phisher decided to change the url after each "phishing run".&lt;br /&gt;&lt;br /&gt;So, here's the first part of the url for each of the three "types":&lt;br /&gt;&lt;br /&gt;http://paymant-response&lt;br /&gt;http://peyment-resposse&lt;br /&gt;http://payment-resspons&lt;br /&gt;&lt;br /&gt;Obviously they are trying to fool your brain into thinking http://payment-responce but in reality the spelling is wrong.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-5148354889858485963?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/5148354889858485963/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=5148354889858485963' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5148354889858485963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/5148354889858485963'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/watch-those-url-spellings.html' title='Watch those url spellings...'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-2463327443878140352</id><published>2007-05-01T17:41:00.000+01:00</published><updated>2007-05-01T18:46:19.641+01:00</updated><title type='text'>boclean saves the day</title><content type='html'>While seaching for a free ftp client, as for some reason I'd forgotten about &lt;a href="http://filezilla.sourceforge.net/"&gt;FileZilla&lt;/a&gt;, I came across this nice looking site (don't try and download the filename in this picture):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/freeftpman.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/freeftpman.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I scanned the exe file with AVG and, as I was in a rush,&lt;br /&gt;ran the exe file to install the free ftp client.&lt;br /&gt;&lt;br /&gt;This is what happened next:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/freeftpman2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/freeftpman2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;That's right... AVG missed it... but &lt;a href="http://www.nsclean.com/"&gt;BoClean&lt;/a&gt; popped up saying that it had detected a nasty in the file... just before it started to do really horrible stuff to my system!&lt;br /&gt;&lt;br /&gt;Hurrah for this once commercial but now free malware program!&lt;br /&gt;&lt;br /&gt;Out of interest, I scanned the free ftp with once of the multi-av scanning sites, with the following results:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/freeftpman3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/freeftpman3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Yep... as you can see, not many of the AV's detected it... so mega full marks to &lt;a href="http://www.nsclean.com/"&gt;BoClean&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Update: &lt;a href="http://isc.sans.org/diary.html?storyid=2711"&gt;ISC&lt;/a&gt; also did a write up of the information I sent to them!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-2463327443878140352?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/2463327443878140352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=2463327443878140352' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2463327443878140352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/2463327443878140352'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/05/boclean-saves-day.html' title='boclean saves the day'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-1392276109014706341</id><published>2007-04-30T18:34:00.000+01:00</published><updated>2007-04-30T18:35:10.912+01:00</updated><title type='text'>new users suspened temporarily</title><content type='html'>Well, for the moment I've had to suspend any new users from downloading sigs/scripts.&lt;br /&gt;I've only got 20 gig hosting currently and this month, I've hit over 15 gig... so playing it safe, new users are suspened until I sort something out.&lt;br /&gt;&lt;br /&gt;Please could everyone check that their scripts are downloading using the HEAD command i.e. only grabbing the downloads when they have changed.&lt;br /&gt;&lt;br /&gt;Some users have been downloading the sigs regardless of changes and it's not really helping, while only users have made mistakes and are trying to download every minute :(&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-1392276109014706341?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/1392276109014706341/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=1392276109014706341' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1392276109014706341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/1392276109014706341'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/04/new-users-suspened-temporarily.html' title='new users suspened temporarily'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-317863024844534773</id><published>2007-04-29T19:47:00.001+01:00</published><updated>2007-04-29T22:13:19.318+01:00</updated><title type='text'>Greeting Card</title><content type='html'>Here's a slightly odd greeting card currently detected as: Email.Malware.Sanesecurity.07030201&lt;br /&gt;&lt;br /&gt;It doesn't look anything special to look at... but wait... what's this.... oh look, it's a username/password ftp link to download a normally nasty .pif file:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard1.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So, it loads the &lt;a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Backdoor.IRC.Zapchast&amp;threatid=43753"&gt;Zapchast&lt;/a&gt; trojan, as can be seen from some &lt;a href="http://www.virustotal.com"&gt;VirusTotal&lt;/a&gt; results:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard2.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now, let's look at the live FTP site, you can see from the screen grab, the .pif file containing the trojan.   Hmmm.... there seems to be other folders there too:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard3.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hang on... that's an Italian Bank name!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard4.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard4.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Let's see what it looks like in FireFox (with NoScript plugin enabled).      &lt;br /&gt;&lt;br /&gt;Yup, I'ts  a Posteitaliane bank fraud page, just waiting to capture your details:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sanesecurity.co.uk/blogimg/gcard5.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px;" src="http://www.sanesecurity.co.uk/blogimg/gcard5.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-317863024844534773?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/317863024844534773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=317863024844534773' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/317863024844534773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/317863024844534773'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/04/greeting-card.html' title='Greeting Card'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-6593065348078320129</id><published>2007-04-28T14:58:00.000+01:00</published><updated>2007-04-28T15:00:26.945+01:00</updated><title type='text'>Would you like any spam with your spam?</title><content type='html'>&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/wZ7YedEopp4"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/wZ7YedEopp4" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-6593065348078320129?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/6593065348078320129/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=6593065348078320129' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6593065348078320129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/6593065348078320129'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/04/would-you-like-any-spam-with-your-spam.html' title='Would you like any spam with your spam?'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-4682606156624878291</id><published>2007-04-28T14:37:00.000+01:00</published><updated>2007-04-28T14:44:48.930+01:00</updated><title type='text'>Is anyone going to bother?</title><content type='html'>I know the spammers have to hide from SURBL's etc so, they'vedecided to do this:&lt;br /&gt;&lt;br /&gt;Look www.2211122. And add COM after dot at the end&lt;br /&gt;&lt;br /&gt;Is anyone that receives a spam like this really going to bother, adding a .com to the&lt;br /&gt;end of www.2211122. ????&lt;br /&gt;&lt;br /&gt;It's detected as:&lt;br /&gt;Email.Spam.Gen398.Sanesecurity.07042502&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-4682606156624878291?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/4682606156624878291/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=4682606156624878291' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4682606156624878291'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/4682606156624878291'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/04/is-anyone-going-to-bother.html' title='Is anyone going to bother?'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9100761888144266006.post-754305609083916003</id><published>2007-04-28T14:29:00.000+01:00</published><updated>2007-04-28T14:32:02.254+01:00</updated><title type='text'>Sanesecurity Blog</title><content type='html'>Yup, I thought it was about time I started a blog, which might make things a little bit easier for news items... well, that's the plan anyway.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9100761888144266006-754305609083916003?l=sanesecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sanesecurity.blogspot.com/feeds/754305609083916003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9100761888144266006&amp;postID=754305609083916003' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/754305609083916003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9100761888144266006/posts/default/754305609083916003'/><link rel='alternate' type='text/html' href='http://sanesecurity.blogspot.com/2007/04/sanesecurity-blog.html' title='Sanesecurity Blog'/><author><name>Steve Basford</name><uri>http://www.blogger.com/profile/09190356137354403294</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
