<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Database &#187; E-mail</title>
	<atom:link href="http://malwaredatabase.net/blog/index.php/cat/e-mail/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwaredatabase.net/blog</link>
	<description>Malware Database is a group of security professionals and a few hobbyists who each contribute to a private distributed database of malicious binaries while raising awareness on current malware trends through our website.</description>
	<lastBuildDate>Fri, 16 Jul 2010 07:11:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>More mailing list unsubscription phishing websites</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/11/27/more-mailing-list-unsubscription-phishing-websites/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/11/27/more-mailing-list-unsubscription-phishing-websites/#comments</comments>
		<pubDate>Fri, 28 Nov 2008 06:04:18 +0000</pubDate>
		<dc:creator>mwdisector</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1215</guid>
		<description><![CDATA[STAY AWAY from these because in reality they are being used to collect email addresses likely for future SPAM campaigns.  I also suspect these domains are part of a current fake XP activation SPAM campaign.
DOMAINS:
campingchip.com
daily&#8211;movie-code.info
daily&#8211;movie-code.net
daily&#8211;movie-code.org
daily-movie&#8211;code.info
daily-movie&#8211;code.net
daily-movie-code.info
get&#8211;activation-code1.com
movie&#8211;code&#8211;online.info
movie&#8211;online-promo.info
movie-code-online.com
movie-code-online.info
movie-code-online.net
movie-code-online.org
movie-online-promo.info
movie-online-promo.org
net&#8211;activation&#8211;code1.com
net&#8211;activation&#8211;code1.net
net&#8211;activation-code1.info
net&#8211;activation-code1.net
net&#8211;activation-code1.org
net&#8211;code&#8211;activation.com
net&#8211;code&#8211;activation.info
net&#8211;code&#8211;activation.net
net&#8211;code-activation.com
net&#8211;code-activation.info
net&#8211;code-activation.net
net&#8211;code-activation.org
net&#8211;movie&#8211;promo.net
net&#8211;online&#8211;product.info
net&#8211;online&#8211;product.org
net&#8211;online-product.info
net&#8211;online-product.org
net&#8211;pdf&#8211;promo.info
net&#8211;pdf&#8211;promo.net
net&#8211;pdf-promo.com
net&#8211;pdf-promo.info
net&#8211;pdf-promo.net
net&#8211;pdf-promo.org
net-activation&#8211;code1.info
net-activation&#8211;code1.net
net-activation-code.com
net-activation-code1.info
net-activation-code1.net
net-activation-code1.org
net-online&#8211;product.info
net-online&#8211;promos.info
net-online-product.info
net-online-product.org
net-pdf&#8211;promo.info
net-pdf&#8211;promo.net
net-pdf-promo.com
net-pdf-promo.info
net-pdf-promo.net
net-pdf-promo.org
new&#8211;movie&#8211;code.net
new&#8211;product&#8211;offer.com
new&#8211;product&#8211;offers.com
new-movie&#8211;code.info
new-movie&#8211;code.net
new-movie&#8211;code.org
online&#8211;activation&#8211;code.net
online&#8211;activation-code.org
online&#8211;movie&#8211;promo.info
online&#8211;movie-promo.info
online&#8211;product-promos.info
online&#8211;promo&#8211;products.info
online&#8211;promo&#8211;products.org
online&#8211;promo-products.info
online&#8211;promo-products.org
online-activation&#8211;code.org
online-activation-code.com
online-activation-code.org
online-movie&#8211;promo.info
online-movie-promo.info
online-product&#8211;promo.net
online-product-promo.com
online-promo&#8211;products.info
online-promo-products.info
online-tv&#8211;promo.info
pdf&#8211;online&#8211;promo.org
pdf&#8211;online-promo.info
pdf&#8211;online-promo.org
pdf&#8211;promo-info1.net
pdf-online&#8211;promo.info
pdf-online&#8211;promo.org
pdf-online-promo.info
pdf-promo&#8211;code.org
pdf-promo&#8211;info1.net
pdf-promo-info.net
pdf-promo-info1.net
superiway.com
tv-new-promo.info
IPs INVOLVED:
27645 &#124; 66.79.162.82 &#124; ASN-NA-MSG-01 &#8211; Managed Solutions Group, Inc.
33314 &#124; 66.79.162.82 &#124; ASN-AKANOC-SJC-01 &#8211; AKANOC Solutions Inc.
16131 &#124; 91.199.50.101 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>STAY AWAY</strong> from these because in reality they are being used to collect email addresses likely for future SPAM campaigns.  I also suspect these domains are part of a current fake XP activation SPAM campaign.</p>
<p>DOMAINS:<br />
<strong>campingchip.com<br />
daily&#8211;movie-code.info<br />
daily&#8211;movie-code.net<br />
daily&#8211;movie-code.org<br />
daily-movie&#8211;code.info<br />
daily-movie&#8211;code.net<br />
daily-movie-code.info<br />
get&#8211;activation-code1.com<br />
movie&#8211;code&#8211;online.info<br />
movie&#8211;online-promo.info<br />
movie-code-online.com<br />
movie-code-online.info<br />
movie-code-online.net<br />
movie-code-online.org<br />
movie-online-promo.info<br />
movie-online-promo.org<br />
net&#8211;activation&#8211;code1.com<br />
net&#8211;activation&#8211;code1.net<br />
net&#8211;activation-code1.info<br />
net&#8211;activation-code1.net<br />
net&#8211;activation-code1.org<br />
net&#8211;code&#8211;activation.com<br />
net&#8211;code&#8211;activation.info<br />
net&#8211;code&#8211;activation.net<br />
net&#8211;code-activation.com<br />
net&#8211;code-activation.info<br />
net&#8211;code-activation.net<br />
net&#8211;code-activation.org<br />
net&#8211;movie&#8211;promo.net<br />
net&#8211;online&#8211;product.info<br />
net&#8211;online&#8211;product.org<br />
net&#8211;online-product.info<br />
net&#8211;online-product.org<br />
net&#8211;pdf&#8211;promo.info<br />
net&#8211;pdf&#8211;promo.net<br />
net&#8211;pdf-promo.com<br />
net&#8211;pdf-promo.info<br />
net&#8211;pdf-promo.net<br />
net&#8211;pdf-promo.org<br />
net-activation&#8211;code1.info<br />
net-activation&#8211;code1.net<br />
net-activation-code.com<br />
net-activation-code1.info<br />
net-activation-code1.net<br />
net-activation-code1.org<br />
net-online&#8211;product.info<br />
net-online&#8211;promos.info<br />
net-online-product.info<br />
net-online-product.org<br />
net-pdf&#8211;promo.info<br />
net-pdf&#8211;promo.net<br />
net-pdf-promo.com<br />
net-pdf-promo.info<br />
net-pdf-promo.net<br />
net-pdf-promo.org<br />
new&#8211;movie&#8211;code.net<br />
new&#8211;product&#8211;offer.com<br />
new&#8211;product&#8211;offers.com<br />
new-movie&#8211;code.info<br />
new-movie&#8211;code.net<br />
new-movie&#8211;code.org<br />
online&#8211;activation&#8211;code.net<br />
online&#8211;activation-code.org<br />
online&#8211;movie&#8211;promo.info<br />
online&#8211;movie-promo.info<br />
online&#8211;product-promos.info<br />
online&#8211;promo&#8211;products.info<br />
online&#8211;promo&#8211;products.org<br />
online&#8211;promo-products.info<br />
online&#8211;promo-products.org<br />
online-activation&#8211;code.org<br />
online-activation-code.com<br />
online-activation-code.org<br />
online-movie&#8211;promo.info<br />
online-movie-promo.info<br />
online-product&#8211;promo.net<br />
online-product-promo.com<br />
online-promo&#8211;products.info<br />
online-promo-products.info<br />
online-tv&#8211;promo.info<br />
pdf&#8211;online&#8211;promo.org<br />
pdf&#8211;online-promo.info<br />
pdf&#8211;online-promo.org<br />
pdf&#8211;promo-info1.net<br />
pdf-online&#8211;promo.info<br />
pdf-online&#8211;promo.org<br />
pdf-online-promo.info<br />
pdf-promo&#8211;code.org<br />
pdf-promo&#8211;info1.net<br />
pdf-promo-info.net<br />
pdf-promo-info1.net<br />
superiway.com<br />
tv-new-promo.info</strong></p>
<p>IPs INVOLVED:<br />
27645 | 66.79.162.82 | ASN-NA-MSG-01 &#8211; Managed Solutions Group, Inc.<br />
33314 | 66.79.162.82 | ASN-AKANOC-SJC-01 &#8211; AKANOC Solutions Inc.<br />
16131 | 91.199.50.101 | GRAFIX-IS GrafiX Internet B.V.</p>
<p>–mwdisector</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/11/27/more-mailing-list-unsubscription-phishing-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Response Lab 2009</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/10/08/virus-response-lab-2009-2/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/10/08/virus-response-lab-2009-2/#comments</comments>
		<pubDate>Wed, 08 Oct 2008 13:13:02 +0000</pubDate>
		<dc:creator>stingner</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=766</guid>
		<description><![CDATA[Virus Response Lab 2009 malware sites. File is available in our repository under /stingner-malware/.
BE ADVISED: These sites may still be live. Proceed at your own risk.
Site:
hxxp://virus-labs2009.com/
hxxp://virus-response.com/
hxxp://virusresplab.com/
hxxp://virusresponse2009.com/
File virlab_install.exe
Result: 12/36 (33.34%)
Virustotal
Removal:
Remove this threat with MalwareBytes!
Malware link:
hxxp://virus-labs2009.com/download.php
hxxp://virusresponse2009.com/download.php
hxxp://virus-response.com/download.php
hxxp://virusresplab.com/download.php
]]></description>
			<content:encoded><![CDATA[<p>Virus Response Lab 2009 malware sites. File is available in our repository under /stingner-malware/.</p>
<p>BE ADVISED: These sites may still be live. Proceed at your own risk.</p>
<p>Site:</p>
<p>hxxp://virus-labs2009.com/</p>
<p>hxxp://virus-response.com/</p>
<p>hxxp://virusresplab.com/</p>
<p>hxxp://virusresponse2009.com/</p>
<p>File virlab_install.exe<br />
Result: 12/36 (33.34%)</p>
<p><a href="http://www.virustotal.com/analisis/8c599e036a86395f560668d651f008c2" target="_blank">Virustotal</a></p>
<h2>Removal:</h2>
<h2><span style="color: #ff0000;"><a href="http://remove.malwaredatabase.net" target="_blank">Remove this threat with MalwareBytes!</a></span></h2>
<p>Malware link:</p>
<p>hxxp://virus-labs2009.com/download.php</p>
<p>hxxp://virusresponse2009.com/download.php</p>
<p>hxxp://virus-response.com/download.php</p>
<p>hxxp://virusresplab.com/download.php</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/10/08/virus-response-lab-2009-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malspam: Notices from IRS (taxform_for_print.scr)</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/09/07/malspam-notices-from-irs-taxform-for-print-scr/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/09/07/malspam-notices-from-irs-taxform-for-print-scr/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 00:12:13 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware Distribution]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[IRS]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=443</guid>
		<description><![CDATA[<p style="text-align: left;"></p>
<p style="text-align: left;">Here is a piece of malspam we received that poses to be from the IRS telling you that you are due for a refund.  The one we got was from taxinform32@taxreducers.com.  Simply follow the steps below and the money is yours! (Proceed at your own risk. File available in /pnuemo-malware/.)</p>
<blockquote>
<p style="text-align: left;">Get Your Refund $1927.10 in Just 3 Easy Steps:<br />
1. Print and fill a short tax interview (click to download)<br />
2. Send it online<br />
3. Receive your tax refund</p></blockquote>
<p style="text-align: left;">The link included takes you to the following address and file: hxxp://freepromo.cn/documents/taxform_for_print.scr</p>
<p style="text-align: center;">
<p style="text-align: left;"><a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg"><img class="aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg" alt="" width="230" height="300" /></a><strong></strong></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong><span id="status_nombre">taxform_for_print.scr<br />
</span></strong>Result: <span id="porcentaje"><span style="color: red;">7</span>/36 (19.45%)<br />
MD5: </span>a705a1df1fc36f696f0eb0fea72870d3<br />
<a href="http://www.virustotal.com/analisis/cd38f2d6b50c36486d16d784a92f2b85" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a705a1df1fc36f696f0eb0fea72870d3" target="_blank"> ThreatExpert Analysis</a></p>
]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"></p>
<p style="text-align: left;">Here is a piece of malspam we received that poses to be from the IRS telling you that you are due for a refund.  The one we got was from taxinform32@taxreducers.com.  Simply follow the steps below and the money is yours! (Proceed at your own risk. File available in /pnuemo-malware/.)</p>
<blockquote>
<p style="text-align: left;">Get Your Refund $1927.10 in Just 3 Easy Steps:<br />
1. Print and fill a short tax interview (click to download)<br />
2. Send it online<br />
3. Receive your tax refund</p></blockquote>
<p style="text-align: left;">The link included takes you to the following address and file: hxxp://freepromo.cn/documents/taxform_for_print.scr</p>
<p style="text-align: center;">
<p style="text-align: left;"><a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg"><img class="aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg" alt="" width="230" height="300" /></a><strong></strong></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong><span id="status_nombre">taxform_for_print.scr<br />
</span></strong>Result: <span id="porcentaje"><span style="color: red;">7</span>/36 (19.45%)<br />
MD5: </span>a705a1df1fc36f696f0eb0fea72870d3<br />
<a href="http://www.virustotal.com/analisis/cd38f2d6b50c36486d16d784a92f2b85" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a705a1df1fc36f696f0eb0fea72870d3" target="_blank"> ThreatExpert Analysis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/09/07/malspam-notices-from-irs-taxform-for-print-scr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>YouTube Message Malspam</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/27/youtube-message-malspam/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/27/youtube-message-malspam/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 00:17:08 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=280</guid>
		<description><![CDATA[I received this in my inbox today from YouTube that someone had sent me a message.  The URL in the message takes the user through two redirects and then prompts the user to download a file.  This files is malware and currently has a low detection rate.  Here is the information I&#8217;ve [...]]]></description>
			<content:encoded><![CDATA[<p>I received this in my inbox today from YouTube that someone had sent me a message.  The URL in the message takes the user through two redirects and then prompts the user to download a file.  This files is malware and currently has a low detection rate.  Here is the information I&#8217;ve gathered.  All of the URL&#8217;s below are still live so proceed at your own risk.</p>
<p style="text-align: center;"><a title="sshot" rel="lightbox[pics280]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/sshot.jpg"><img class="attachment wp-att-282 centered aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/sshot.jpg" alt="sshot" width="500" height="183" /></a></p>
<p style="center;">
<p>hxxp://zz.gd/1d7d6a<br />
-&gt; hxxp://sghghdfgh.actionpooses.com/dfhgfhgfh<br />
&#8211;&gt; hxxp://actionpooses.com/livenow/live-now.htm<br />
&#8212;&gt; hxxp://212.179.35.9/Free-Girls-Cams-Viewer.exe</p>
<p><strong><span>Free-Girls-Cams-Viewer.exe<br />
</span></strong>Result: <span><span style="red;">6</span>/36 (16.67%)<br />
MD5: </span>716adbf47c6fffbd77604be9e9dd7043<br />
<a href="http://www.virustotal.com/analisis/a0ff35d080a8d8122d2aabfd4f129737" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=716adbf47c6fffbd77604be9e9dd7043" target="_blank"> ThreatExpert Analysis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/27/youtube-message-malspam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Antivirus 2008 Pro XP</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/25/antivirus-2008-pro-xp/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/25/antivirus-2008-pro-xp/#comments</comments>
		<pubDate>Mon, 25 Aug 2008 08:58:35 +0000</pubDate>
		<dc:creator>ion</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Rogue Security Software]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Antivirus 2008 Pro XP]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=252</guid>
		<description><![CDATA[We came across a new domain name registered at estdomains today.  This site may appear seamlessly legitimate, as it sports a support page, affiliate page, terms of service, etc.  But we can assure you that it is a bad site.  Be aware of this site and do not download any of the [...]]]></description>
			<content:encoded><![CDATA[<p>We came across a new domain name registered at estdomains today.  This site may appear seamlessly legitimate, as it sports a support page, affiliate page, terms of service, etc.  But we can assure you that <strong>it is a bad site</strong>.  Be aware of this site and do not download any of the files associated with it!  Site: hxxp://antivirus2008proxp.com</p>
<p>What it looks like:</p>
<p style="text-align: center;"><a title="Antivirus 2008 Pro XP" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/antivirus2008pro.gif" rel="lightbox[252]"><img class="attachment wp-att-253 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/antivirus2008pro.gif" alt="Antivirus 2008 Pro XP" width="500" height="370" /></a></p>
<h2>Removal:</h2>
<h2><span style="color: #ff0000;"><a href="http://remove.malwaredatabase.net" target="_blank">Remove this threat with MalwareBytes!</a></span></h2>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/25/antivirus-2008-pro-xp/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Britney Spears MalSpam points to mov.exe</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/19/britney-spears-malspam-points-to-movexe/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/19/britney-spears-malspam-points-to-movexe/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 00:52:44 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Britney Spears]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=215</guid>
		<description><![CDATA[We saw a new MalSpam today.  Unfortunately, it shows a very nasty picture of Britney Spears getting out of Paris Hilton&#8217;s car.   It fowards us to hxxp://www.lenapiel.com/mov.exe, which does not appear to be up at the time of our post.
Warning: The BSD daemon may not appear in the malspam you receive.  [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">We saw a new MalSpam today.  Unfortunately, it shows a very nasty picture of Britney Spears getting out of Paris Hilton&#8217;s car.   It fowards us to hxxp://www.lenapiel.com/mov.exe, which does not appear to be up at the time of our post.</p>
<p style="text-align: center;">Warning: The BSD daemon may not appear in the malspam <em>you</em> receive.  You have been forewarned.</p>
<p style="text-align: center;"><a title="MalSpam" rel="lightbox[pics-1219192985]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/hotmovie.jpg"><img class="attachment wp-att-214 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/hotmovie.jpg" alt="MalSpam" width="500" height="402" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/19/britney-spears-malspam-points-to-movexe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malspam: Carrington Mortgage Services LLC owes you money!</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/05/malspam-carrington-mortgage-services-llc-owes-you-money/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/05/malspam-carrington-mortgage-services-llc-owes-you-money/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 01:04:36 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=101</guid>
		<description><![CDATA[There are some malspam messages that are being sent out to users with an infected attachment.  This malware may not be disinfected by your anti-malware product because it is compressed in a protected archive although the contents of the email will provide the user with the password.  The malspam contains the following message:
This [...]]]></description>
			<content:encoded><![CDATA[<p>There are some malspam messages that are being sent out to users with an infected attachment.  This malware may not be disinfected by your anti-malware product because it is compressed in a protected archive although the contents of the email will provide the user with the password.  The malspam contains the following message:</p>
<blockquote><p>This email is for informational purposes only. Do not reply to the  email address above.</p>
<p>A payment to Carrington Mortgage Services LLC in the amount of $8773.85  has been made from your Checking account</p>
<p>For further information about this transaction, please download attached invoice file (Password for ZIP archive: &#8220;invoice&#8221; )</p>
<p>If you did not authorize this payment to be made, please contact your  financial institution or card issuer immediately for further  instructions.</p>
<p>FKNC Privacy Statement: The information contained in this electronic mail transmission is intended by Fort Knox National Company for the use of the named individual or entity to which it is originally directed and may contain information that is privileged or otherwise confidential. It is not intended for transmission to, or receipt by anyone other than the named addressee (or a person authorized to deliver it to the named addressee). It should not be copied or forwarded to any unauthorized persons. If you have received this electronic mail transmission in error, please delete it from your system without copying or forwarding it, and notify the sender of the error by reply email or by calling Fort Knox National Company at 866-220-7121. Unauthorized use, dissemination, distribution, or reproduction of this message is strictly prohibited and may be unlawful.</p></blockquote>
<p>The file enclosed in the archive is <strong>IN87129_717a.exe</strong>.  Below are the results from Virustotal along with the sandbox results.</p>
<p><a href="http://www.virustotal.com/analisis/6214c97b7427ba681c314e0cbb044fd2" target="_blank">Virustotal</a>: <span id="porcentaje"><span style="color: red;">15</span>/36<br />
<a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/in87129_717aexe.zip">Additional information</a> (JoeBox)</span></p>
<p>File size: 58368 bytes<br />
MD5&#8230;: eead764389f7e2b1939d147b198443a3<br />
SHA1..: 94332eb2ead4bc9464ae1108ea2ab2b3c60d824b<br />
SHA256: 74492a5d2e571ff6eae2f3ed913f372ab9620778c4ad522895d3aa805d1688f7<br />
SHA512: 92ef95984fdd1db26f526c17ce897e2898858ca8410f3c0a39636ebdf0b852c6<br />
35a2122adb4809d23363956008fae04f1071f94d7ad1afcae2834a48615a8262<br />
PEiD..: -<br />
PEInfo: PE Structure information</p>
<p>( base data )<br />
entrypointaddress.: 0&#215;40107d<br />
timedatestamp&#8230;..: 0&#215;4806e3fb (Thu Apr 17 05:45:31 2008)<br />
machinetype&#8230;&#8230;.: 0&#215;14c (I386)</p>
<p>( 4 sections )<br />
name viradd virsiz rawdsiz ntrpy md5<br />
.text 0&#215;1000 0&#215;1010 0&#215;1200 2.80 2b47bcb94b4842dbad7d705a4edde293<br />
.data 0&#215;3000 0&#215;22b9b 0xc800 7.60 ded2450cbafedda4dfe1d972a0e701f2<br />
.reloc 0&#215;26000 0&#215;1000 0&#215;0 0.00 d41d8cd98f00b204e9800998ecf8427e<br />
.rsrc 0&#215;27000 0&#215;1000 0&#215;600 4.66 0552eaf398afb9100b608d74807bcad7</p>
<p>( 1 imports )<br />
&gt; gdi32.dll: GetClipBox, GetBitmapBits, CreateDIBSection, SetTextColor, GetPixel, CreateDIBitmap, GetBrushOrgEx, CreateBitmap, CreateFontIndirectA, ExcludeClipRect</p>
<p>( 0 exports )<br />
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=eead764389f7e2b1939d147b198443a3</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/05/malspam-carrington-mortgage-services-llc-owes-you-money/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malspam spreading name.avi.exe through celebrity &#8220;pornography&#8221;</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/05/malspam-spreading-nameaviexe-through-celebrity-pornography/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/05/malspam-spreading-nameaviexe-through-celebrity-pornography/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 01:04:22 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=106</guid>
		<description><![CDATA[Lots and lots of malspam these days.  Here is a fresh round of malspam we&#8217;ve collected in the last few hours.  These are attempting to get the user to download name.avi.exe (information below).
Here are some of the intriguing subjects and bodies of this campaign.
Subject
Your order
Your order is executed
Body
Nude Celebrities (Jennifer Lopez)- huge archive [...]]]></description>
			<content:encoded><![CDATA[<p>Lots and lots of malspam these days.  Here is a fresh round of malspam we&#8217;ve collected in the last few hours.  These are attempting to get the user to download name.avi.exe (information below).</p>
<p>Here are some of the intriguing subjects and bodies of this campaign.</p>
<p><strong>Subject<br />
</strong>Your order<br />
Your order is executed</p>
<p><strong>Body</strong><br />
Nude Celebrities (Jennifer Lopez)- huge archive of Naked Celebs. Free pics &amp; videos.<br />
Angelina Jolie N@ked &#8211; Extremly Video!<br />
All your favorite celebrities caught naked !<br />
BRITNEY NUDE VIDEO. 00:58<br />
T!t$ Photo and Video Angel!na Jolie<br />
JENNIFER LOPEZ EXTREMLY NAKED!!!<br />
Angelina Jolie Videos, Pics, Celebrity $ex Tapes.<br />
Cameron Diaz Nude &#8211; Free Video &#8211; See Now!!<br />
Free Nude Celebrity &#8211; all your favorite celebrities caught naked !!<br />
Nicole Kidman N@ked &#8211; Video, Pictures</p>
<p><a href="http://www.virustotal.com/analisis/0c797bb5a23dd4c6b457055a5a932170" target="_blank">Virustotal</a>: <span id="porcentaje"><span style="color: red;">12</span>/36 </span><br />
<a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/nameaviexe.zip" target="_blank">Additional information</a> (JoeBox)</p>
<p>File size: 138752 bytes<br />
MD5&#8230;: 88be4cf23bf477d1d32f558e22607ed3<br />
SHA1..: 7e9ffece41fc0e8ae1f866fb763b0983b60e70df<br />
SHA256: c657532cc59ede8d92dc47d185407b5e7e1d72e5216396d8456aeb1f7f9aa34a<br />
SHA512: 2139d6ad9f6950ba66e1a3d7975e992c07dc40bd30a350a94e8d21b73068f5a3<br />
fbaed6dbce03366c8e2a499e460e445cfaa4ece463f2b24d43a715652ac2bb9c<br />
PEiD..: -<br />
PEInfo: PE Structure information</p>
<p>( base data )<br />
entrypointaddress.: 0&#215;402f77<br />
timedatestamp&#8230;..: 0&#215;4897342d (Mon Aug 04 16:54:05 2008)<br />
machinetype&#8230;&#8230;.: 0&#215;14c (I386)</p>
<p>( 3 sections )<br />
name viradd virsiz rawdsiz ntrpy md5<br />
.code 0&#215;1000 0&#215;3388c 0&#215;4a00 3.91 a52a8eadd95c07842ce55336e14b6226<br />
DATA 0&#215;35000 0&#215;1b380 0&#215;1ac00 8.00 92acecf8c3c1dd2466e423fe3eab02ea<br />
.rsrc 0&#215;51000 0&#215;1000 0&#215;400 6.85 e9f67bb8713e98caf74e01bf392003c8</p>
<p>( 0 imports )</p>
<p>( 0 exports )</p>
<p>Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=8185F2D7003567E21EC702A9BAA2DB00E60C9AE5<br />
ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=88be4cf23bf477d1d32f558e22607ed3</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/05/malspam-spreading-nameaviexe-through-celebrity-pornography/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New site distributing Antivirus2009 Rogue</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/07/31/new-site-distributing-antivirus2009-rogue/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/07/31/new-site-distributing-antivirus2009-rogue/#comments</comments>
		<pubDate>Thu, 31 Jul 2008 10:25:17 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Thoughts]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=77</guid>
		<description><![CDATA[We found a new site distributing the Antivirus 2009 rogue software today.
**Proceed at your own risk**
Site:  hxxp://antivirus-2009pro.com
File: hxxp://antivirus-2009pro.com/2009/download/77001106/AV2009Install.exe

Results for antivirus-2009pro.com:

Domain Name: ANTIVIRUS-2009PRO.COM

Creation Date: 30-Jul-2008
Expiration Date: 30-Jul-2009

Domain servers in listed order:
ns4.mynick.name
ns3.mynick.name
ns2.mynick.name
ns1.mynick.name

Registrant:
PrivacyProtect.org
Domain Admin        (contact@privacyprotect.org)
P.O. Box 97
Note - All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676


]]></description>
			<content:encoded><![CDATA[<p>We found a new site distributing the Antivirus 2009 rogue software today.</p>
<p><strong>**Proceed at your own risk**</strong></p>
<p>Site:  hxxp://antivirus-2009pro.com</p>
<div>File: hxxp://antivirus-2009pro.com/2009/download/77001106/AV2009Install.exe</div>
<blockquote>
<pre><strong>Results for antivirus-2009pro.com:</strong>

Domain Name: ANTIVIRUS-2009PRO.COM

Creation Date: 30-Jul-2008
Expiration Date: 30-Jul-2009

Domain servers in listed order:
ns4.mynick.name
ns3.mynick.name
ns2.mynick.name
ns1.mynick.name

Registrant:
PrivacyProtect.org
Domain Admin        (<a href="mailto:contact@privacyprotect.org">contact@privacyprotect.org</a>)
P.O. Box 97
Note - All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676</pre>
</blockquote>
<p style="text-align: center;"><a title="Antivirus 2009 Rogue" rel="lightbox[pics-1217499418]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/screenhunter_15-jul-31-03141.gif"><img class="attachment wp-att-79 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/07/screenhunter_15-jul-31-03141.gif" alt="Antivirus 2009 Rogue" width="500" height="380" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/07/31/new-site-distributing-antivirus2009-rogue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malspam Campaign Still Going Strong</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/07/29/malspam-campaign-still-going-strong/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/07/29/malspam-campaign-still-going-strong/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 17:36:22 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=68</guid>
		<description><![CDATA[The spamming campaign that has hit us full force is pushing the file get_flash_update.exe.  Most AV&#8217;s at this point have detected this file so hopefully it shouldn&#8217;t cause much havoc.  I wanted to post the emails we&#8217;ve received and the domains that are hosting this malware.
VirusTotal shows 31/35 detection and you can click [...]]]></description>
			<content:encoded><![CDATA[<p>The spamming campaign that has hit us full force is pushing the file get_flash_update.exe.  Most AV&#8217;s at this point have detected this file so hopefully it shouldn&#8217;t cause much havoc.  I wanted to post the emails we&#8217;ve received and the domains that are hosting this malware.</p>
<p><a href="http://www.virustotal.com/analisis/58620e19de195a2a1ef7b16c152819ba" target="_blank">VirusTotal</a> shows <span id="porcentaje"><span style="color: red;">31</span>/35 detection and you can click the link for more details. </span>Of course this file is available in our repository in pnuemo-malware/Classified/Trj-Exchanger.S.zip.</p>
<p>Warning:  These sites are still live as of 7/29 10:22a PST.  Proceed at your own risk!</p>
<p>hxxp://ankaraspor.com.tr/default.html<br />
hxxp://cit-inc.net/default.html<br />
hxxp://grupoestudio.com/default.html<br />
hxxp://www.dianagraf.es/default.html<br />
hxxp://venhuis.de/default.html<br />
hxxp://grupoestudio.com/default.html<br />
hxxp://ebberov.homepage.dk/default.html<br />
hxxp://madosma.com/default.html<br />
hxxp://warinsa.com/default.html<br />
hxxp://www.czareksu.pl/default.html<br />
hxxp://heimerpara.de/default.html</p>
<p>Read more for the email subjects and bodies we&#8217;ve received.<br />
<span id="more-68"></span><strong>Subject:</strong> Steve Jobs admits recurrence of pancreatic cancer<br />
<strong>Body:</strong> Invest and get 100% returns</p>
<p><strong>Subject:</strong> So you think you can dance<br />
<strong>Body:</strong> Boy eats cats daily</p>
<p><strong>Subject:</strong> Explosion rock Israel, Gulf war imminent<br />
<strong>Body:</strong> Bear attack kills 3 in Atlanta zoo</p>
<p><strong>Subject:</strong> Top tips for an accessible home<br />
<strong>Body:</strong> Bear attack kills 3 in Atlanta zoo</p>
<p><strong>Subject:</strong> Arnold Schwarzenegger quits as Governer<br />
<strong>Body:</strong> Girl bites brother&#8217;s finger off</p>
<p><strong>Subject: </strong>You are living in the worst city<br />
<strong>Body:</strong> citibank files for bankruptcy protection</p>
<p><strong>Subject:</strong> Girl kicks brother to death<br />
<strong>Body:</strong> Win a free trip to Vegas</p>
<p><strong>Subject:</strong> Sex change operation went wrong<br />
<strong>Body:</strong> Obama denies wrongdoing in Presidential debate</p>
<p><strong>Subject:</strong> Swedish princess slaps town florist<br />
<strong>Body:</strong> Suicide blasts in Iraq kill hundreds</p>
<p><strong>Subject:</strong> Win a free trip to Vegas<br />
<strong>Body:</strong> Italy charges Google for espionage</p>
<p><strong>Subject:</strong> Kidnapper at large in NY, dangerous<br />
<strong>Body:</strong> Afghan rebels kill 102 US soldiers</p>
<p><strong>Subject:</strong> Afghan rebels kill 102 US soldiers<br />
<strong>Body:</strong> Man kills wife in accidental gas explosion</p>
<p><strong>Subject:</strong> Shark attack off Australia, 2 dead<br />
<strong>Body:</strong> Swedish princess slaps town florist</p>
<p><strong>Subject: </strong>Fire threatens Hollywood<br />
<strong>Body:</strong> Bullies face huge health risk</p>
<p><strong>Subject:</strong> Girl gang rapes fellow male classmate<br />
<strong>Body: </strong>Unknown person stabs Christian Bale</p>
<p><strong>Subject:</strong> Google charged by European Union for espionage<br />
<strong>Body:</strong> Incredible college parties</p>
<p><strong>Subject:</strong> Killer dogs tear intruder apart<br />
<strong>Body:</strong> Shia LaBeouf refused bail after arrest</p>
<p><strong>Subject: </strong>Girl bites brother&#8217;s finger off<br />
<strong>Body: </strong>Incredible college parties</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/07/29/malspam-campaign-still-going-strong/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
