<?xml version="1.0"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>Smallmo - CISRT Member</title><link>http://smallmo.reallifelog.com/</link><description><![CDATA[Personal Security Weblog]]></description><image><url>http://www.reallifelog.com/members/images/3aa67a7dc899880cd3cb1e2a4058d44b.jpg</url><title>Real Life Log - smallmo</title><link>http://smallmo.reallifelog.com</link><width>125</width><height>93</height></image><pubDate>Wed, 28 Feb 07 15:57:46 +0100</pubDate><generator>http://www.reallifelog.com/?feed=rss2</generator><item><title>Fake Webshop Bestellung spams in Germany</title><link>http://smallmo.reallifelog.com/archive/40161/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/40161/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/40161/#comments</comments><pubDate>Wed, 28 Feb 07 15:57:46 +0100</pubDate><category>Virus News</category><description><![CDATA[<p>
<strong>CISRT Lab</strong>&#160;received&#160;some spams about Webshop Bestellung tonight,and these spams are spreading in Germany now.German users should be careful of this kind of&#160;spams.<br />
<br />
In the spams,there is a malicious web page which contained <strong>MS06-014</strong> vulnerability.The spams are as the following:<br />
<br />
=======<br />
<strong>From</strong>: (as the following)<br />
Angelita@tms-logistik.de<br />
Nicholas@tms-logistik.de<br />
Julius@tms-logistik.de<br />
Lionel@tms-logistik.de 
</p>
<p>
<br />
<strong>Subject</strong>: (as the following)<br />
KD 86778 Webshop Bestellung 27.02.2007<br />
KD 07843 Webshop Bestellung 27.02.2007<br />
KD 79360 Webshop Bestellung 27.02.2007<br />
KD 27822 Webshop Bestellung 27.02.2007 
</p>
<p>
<br />
<strong>Body</strong>: (as the following)<br />
Guten Tag, 
</p>
<p>
Vielen Dank fur Ihre Bestellung! 
</p>
<p>
Die von Ihnen bestellten Waren sind vollstandig am Lager und werden umgehend<br />
durch die Logistikabteilung an Sie versandt. 
</p>
<p>
<br />
(a link which contained a malicious url) 
</p>
<p>
<br />
Um eine schnellstmogliche Bearbeitung Ihre Ruckfragen gewahrleisten zu<br />
konnen,<br />
bitten wir Sie bei Ruckfragen immer Ihre Kundennummer 86778 und<br />
Belegnummer [3816712] anzugeben. 
</p>
<p>
<br />
Vielen Dank 
</p>
<p>
Mit freundlichem Grub 
</p>
<p>
Eberhard Schmidt 
</p>
<p>
TMS Logistik GmbH 
</p>
<p>
Call Center:<br />
tel (0180) 31 57 16 21 - 0,09 EUR/min aus dem dt. Festnetz/T-Com<br />
fax (030) 90 16 - 29 19<br />
web www.tms-logistik.de 
</p>
<p>
Niederlassung Berlin<br />
Albrechstrasse 117<br />
D-01271 Berlin 
</p>
<p>
----------------------------------------------------------------------------<br />
------------------ 
</p>
<p>
&#160; Auf den Punkt gebracht - Ihre Vorteile als TMS Logistik Kunde<br />
----------------------------------------------------------------------------<br />
------------------ 
</p>
<p>
<br />
&#160; o 14 Tage Ruckgaberecht fur originalverpackte Neuware<br />
&#160; o Beratung durch unsere Fachverkaufer<br />
&#160; o Transparente Preisgestaltung und Verfugbarkeitsanzeige<br />
&#160; o Rundumschutz durch optionales Servicepaket<br />
&#160; o Kostenfreie Parkplatze<br />
&#160; o Bequeme Zusendung durch uns oder DHL moglich<br />
&#160; o Kostenfreier 80-seitiger Gesamtkatalog - auch per Post nach Hause 
</p>
<p>
----------------------------------------------------------------------------<br />
------------------ 
</p>
<p>
&#160; TMS Logistik - seit 12 Jahren erfolgreich in Berlin<br />
----------------------------------------------------------------------------<br />
------------------<br />
<br />
=======<br />
<br />
We got two different links in the spams:<br />
<strong>h**p://tanknk.dothome.co.kr<br />
h**p://bluerain.co.kr</strong><br />
<br />
<a href="http://vfs.reallifelog.com/2007/02/28/464fa809ac0f1ac3a70d29453631b6b2.jpg"><img src="http://vfs.reallifelog.com/2007/02/28/c92d1ec9699d9d3ebdf6d722e0fb96cb.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/02/28/464fa809ac0f1ac3a70d29453631b6b2.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/02/28/ca1a16497bf7e2e684594f47670806c7.jpg### ###ID:37499###" width="460" height="169" /></a><br />
<br />
<a href="http://vfs.reallifelog.com/2007/02/28/36a23a0828944803a22da27a4565447d.jpg"><img src="http://vfs.reallifelog.com/2007/02/28/05e78c6317e0ff75cf788298a5382793.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/02/28/36a23a0828944803a22da27a4565447d.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/02/28/30603f361ea3167a68f620427dc2cc8a.jpg### ###ID:37500###" width="460" height="169" /></a><br />
<br />
In these links,they are include a malicious url which contained MS06-014 vulnerability:<br />
<br />
<a href="http://vfs.reallifelog.com/2007/02/28/23d3ccb9f1026a26e44df6e7f5b7bd53.jpg"><img src="http://vfs.reallifelog.com/2007/02/28/b173750c7539fc92d82d429670c4ea65.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/02/28/23d3ccb9f1026a26e44df6e7f5b7bd53.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/02/28/0492d1672ceb9e47dee5cad59f2c9113.jpg### ###ID:37501###" width="460" height="104" /></a><br />
<br />
<a href="http://vfs.reallifelog.com/2007/02/28/618356a73500c91043f56f0b8f59d95a.jpg"><img src="http://vfs.reallifelog.com/2007/02/28/0e0a5c261e4a20092b0fda459176330a.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/02/28/618356a73500c91043f56f0b8f59d95a.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/02/28/50316f2b0af2013ec68d472c206645e0.jpg### ###ID:37502###" width="460" height="109" /></a><br />
<br />
When users&#160;click the link in these spams,a file named as &quot;update.exe&quot; will be downloaded. The size is 87,673 bytes,packed with FSG2.0,it&#39;s a new variant. Test it on Virustotal,the result:<br />
<br />
<a href="http://vfs.reallifelog.com/2007/02/28/c3eff80f68dec1365fb8508788069668.jpg"><img src="http://vfs.reallifelog.com/2007/02/28/583f993e2e30ebc9c096fa74e5c807d7.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/02/28/c3eff80f68dec1365fb8508788069668.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/02/28/0512f701730ad7e4ca35d1cc96f2da43.jpg### ###ID:37503###" width="460" height="297" /></a><br />
<br />
The sample&#39;s information:<br />
<strong>MD5</strong>: 83dc1e8e6deb85088a6a3cc29eb6558f <br />
<strong>SHA1</strong>: 91122a1461917de318b914851ec840002d46d2b8 <br />
<br />
<strong>Update</strong> 17:35,March 1st,2007(GMT+0800):<br />
The latest database of Kaspersky detects it as Trojan-Spy.Win32.BZub.ic<br />
<br />
</p>
]]></description></item><item><title>The OS of webserver down</title><link>http://smallmo.reallifelog.com/archive/39914/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/39914/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/39914/#comments</comments><pubDate>Tue, 27 Feb 07 10:53:16 +0100</pubDate><category>Others</category><description><![CDATA[Our CISRT webserver has been downed for two days because the Operate System of webserver was damaged.The service provider is repairing new system now,but i don&#39;t know when the webserver can be repaired.So&#160;CISRT can&#39;t update new information about the latest malwares now.I hope it can be repaired as soon as possible.
]]></description></item><item><title>Spams: Australia's Prime Minister</title><link>http://smallmo.reallifelog.com/archive/38935/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/38935/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/38935/#comments</comments><pubDate>Wed, 21 Feb 07 13:00:40 +0100</pubDate><category>Virus News</category><description><![CDATA[Hello,everyone.Happy Chinese New year!<br />
I haven&#39;t updated my weblog for a long time because i just finished enjoying my holidays.<br />
<br />
<strong>CISRT Lab</strong> just released an alert for a new spam appoint to <strong>John Howard</strong>, Australia&#39;s Prime Minister two hours ago.<br />
<br />
More details: <a href="http://www.cisrt.org/enblog/read.php?34">Spams about Australia&#39;s Prime Minister</a>
]]></description></item><item><title>Happy Valentine's Day </title><link>http://smallmo.reallifelog.com/archive/37068/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/37068/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/37068/#comments</comments><pubDate>Wed, 14 Feb 07 16:01:18 +0100</pubDate><category>Virus News</category><description><![CDATA[<p>
Happy Valentine&#39;s Day everyone.<br />
<br />
But with Valentine Day coming,new variants of Email-Worm.Win32.Zhelatin and Email-Worm.Win32.Warezov come,too.&#160;<strong>CISRT Lab</strong>&#160;received <strong>Email-Worm.Win32.Zhelatin.ab</strong> and <strong>Email-Worm.Win32.Warezov.lc</strong> today.This Zhelatin variant uses the Valentine Day in mail subjects such as &quot;<span style="color: #0000ff">Valentines Day Dance</span>&quot;, &quot;<span style="color: #0000ff">The Valentines Angel</span>&quot;, &quot;<span style="color: #0000ff">Valentine Letter</span>&quot;, &quot;<span style="color: #0000ff">Valentine&#8217;s Love</span>&quot;, etc . Everyone should be careful! <br />
<br />
More details: <a href="http://www.cisrt.org/enblog/read.php?31">Valentine Day with Zhelatin and Warezov variants</a>
</p>
]]></description></item><item><title>Multiple Zhelatin variants</title><link>http://smallmo.reallifelog.com/archive/36362/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/36362/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/36362/#comments</comments><pubDate>Sun, 11 Feb 07 12:02:05 +0100</pubDate><category>Virus News</category><description><![CDATA[These days,more Email-Worm.Win32.Zhelatin variants have been found. Kaspersky has given an alert for these variants.<br />
CISRT Lab also has posted informations about <strong>Email-Worm.Win32.Zhelatin.t</strong>, <strong>Email-Worm.Win32.Zhelatin.u</strong>, <strong>Email-Worm.Win32.Zhelatin.x</strong>.<br />
New variant begins spreading via Instant Messenger now.<br />
<br />
More details,you can visit <strong>CISRT</strong> English weblog: <a href="http://www.cisrt.org/enblog/" target="_blank">http://www.cisrt.org/enblog/</a>
]]></description></item><item><title>Worm,trojan and ircbot</title><link>http://smallmo.reallifelog.com/archive/35508/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/35508/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/35508/#comments</comments><pubDate>Wed, 07 Feb 07 17:10:00 +0100</pubDate><category>Virus News</category><description><![CDATA[CISRT Lab reports three malwares contained worm,trojan and ircbot today.They are Email-Worm.Win32.Zhelatin.r, Trojan-Downloader.Win32.Agent.bgd and Backdoor.Win32.IRCBot.yc.<br />
<br />
Backdoor.Win32.IRCBot.yc is spreading via MSN in HongKong,Taiwan with &quot;viotagallery.com&quot; and &quot;modelosunica.com&quot; domains.<br />
<br />
More details:<br />
1. <a href="http://www.cisrt.org/enblog/read.php?20">Zhelatin.r variant update</a><br />
<br />
2. <a href="http://www.cisrt.org/enblog/read.php?21">Top cigarettes offer trojan spam</a><br />
<br />
3. <a href="http://www.cisrt.org/enblog/read.php?22">Fake picture on MSN</a>
]]></description></item><item><title>Trojan-Downloader.Win32.Tibs variants</title><link>http://smallmo.reallifelog.com/archive/35132/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/35132/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/35132/#comments</comments><pubDate>Tue, 06 Feb 07 16:40:59 +0100</pubDate><category>Virus News</category><description><![CDATA[CISRT Lab received some variants of Trojan-Downloader.Win32.Tibs family,they are similar to Email-Worm.Win32.Zhelatin family,also spreads via email,uses the filename as &quot;Greeting_Postcard.exe&quot;,&quot;Greeting_Card.exe&quot;,&quot;greeting card.exe&quot;,etc.<br />
<br />
More deteails:<a href="http://www.cisrt.org/enblog/read.php?18">New sample like Zhelatin worm variant</a>&#160;<br />
&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; <a href="http://www.cisrt.org/enblog/read.php?19">Another Trojan-Downloader.Tibs variant</a>
]]></description></item><item><title>Email-Worm.Win32.Zhelatin.o</title><link>http://smallmo.reallifelog.com/archive/34718/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/34718/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/34718/#comments</comments><pubDate>Sun, 04 Feb 07 15:10:09 +0100</pubDate><category>Virus News</category><description><![CDATA[<strong>CISRT Lab</strong> received new variant of Email-Worm.Win32.Zhelatin&#8212;&#8212;<strong>Email-Worm.Win32.Zhelatin.o</strong>.<br />
<br />
More details: <a href="http://www.cisrt.org/enblog/read.php?16">Zhelatin.o variants come</a>
]]></description></item><item><title>Dolphin Stadium website hacked and Zhelatin.m worm</title><link>http://smallmo.reallifelog.com/archive/34438/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/34438/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/34438/#comments</comments><pubDate>Sat, 03 Feb 07 15:34:19 +0100</pubDate><category>Virus News</category><description><![CDATA[Two messages from&#160;CISRT Lab:<br />
<br />
One is that the official website of&#160;<strong>Dolphin Stadium </strong>which&#160;will be held with&#160;<strong>Super Bowl XLI</strong> was hacked on Feb.2.<br />
<br />
Another is that Email-Worm.Win32.Zhelatin.m is coming.<br />
<br />
More details:<br />
<a href="http://www.cisrt.org/enblog/read.php?14">Dolphin Stadium website</a>&#160;<br />
<a href="http://www.cisrt.org/enblog/read.php?15">Zhelatin worm continues updating</a>
]]></description></item><item><title>IM-Worm.Win32.Sohanad.u</title><link>http://smallmo.reallifelog.com/archive/34028/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/34028/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/34028/#comments</comments><pubDate>Fri, 02 Feb 07 11:44:40 +0100</pubDate><category>Virus News</category><description><![CDATA[<strong>CISRT Lab</strong> received a new variant of IM-Worm.Win32.Sohanad,it is spreading via IM software.It sends out message about Microsoft Windows Vista. CISRT Lab has declared an alert for this new worm.<br />
<br />
More details:<a href="http://www.cisrt.org/enblog/read.php?12">Sohanad.u worm spreading</a>
]]></description></item><item><title>Email-Worm.Win32.Zhelatin.k</title><link>http://smallmo.reallifelog.com/archive/33341/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/33341/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/33341/#comments</comments><pubDate>Wed, 31 Jan 07 15:23:29 +0100</pubDate><category>Virus News</category><description><![CDATA[<strong>CISRT Lab</strong> received a new variant&#8212;&#8212;Email-Worm.Win32.Zhelatin.k<br />
<br />
Be careful please.<br />
<br />
More details:<a href="http://www.cisrt.org/enblog/read.php?11">Zhelatin.k worm come</a> 
]]></description></item><item><title>Email-Worm.Win32.Zhelatin.h</title><link>http://smallmo.reallifelog.com/archive/32921/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/32921/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/32921/#comments</comments><pubDate>Tue, 30 Jan 07 15:11:00 +0100</pubDate><category>Virus News</category><description><![CDATA[<strong>CISRT Lab</strong> received many variants about Email-Worm.Win32.Zhelatin.h.The author seems to update the worm frequently,to prevent itself to be detected by AV vendors.<strong>CISRT Lab</strong>&#160;advises everyone should keep your antivirus database to the latest.<br />
<br />
More details: <a href="http://www.cisrt.org/enblog/read.php?10">More Zhelatin.h Worm</a><br />
]]></description></item><item><title>Alert for Banwarum.l</title><link>http://smallmo.reallifelog.com/archive/32353/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/32353/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/32353/#comments</comments><pubDate>Sun, 28 Jan 07 15:08:07 +0100</pubDate><category>Virus News</category><description><![CDATA[Three hours ago,CISRT Lab declared an alert for new variant of Email-Worm.Win32.Banwarum.If you received the attachment contained the following names,you should be careful.<br />
<strong>Flash Postcard.exe <br />
Greeting Card.exe <br />
Greeting Postcard.exe <br />
Postcard.exe<br />
greeting_postcard.exe<br />
Greeting_Postcard.exe<br />
<br />
</strong>Kaspersky detected them&#160;as&#160;<strong>Email-Worm.Win32.Banwarum.l</strong>,Trend Micro detects&#160;them as <strong>WORM_NUWAR.EL</strong>.<br />
<br />
More details,you can see here: <a href="http://www.cisrt.org/enblog/read.php?8"><strong><font color="#356080">Banwarum.l begins spreading</font></strong></a>
]]></description></item><item><title>Some malware information</title><link>http://smallmo.reallifelog.com/archive/32058/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/32058/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/32058/#comments</comments><pubDate>Sat, 27 Jan 07 15:24:31 +0100</pubDate><category>Virus News</category><description><![CDATA[<strong>CISRT Lab</strong> has reported some new malware information these two days.<br />
You can see:<br />
1. <a href="http://www.cisrt.org/enblog/read.php?3">Storm worm new variant</a><br />
<br />
2. <a href="http://www.cisrt.org/enblog/read.php?4">foto via MSN</a><br />
<br />
3. <a href="http://www.cisrt.org/enblog/read.php?7">Foto email spread in Brazil</a>
]]></description></item><item><title>Another Rechnung spam</title><link>http://smallmo.reallifelog.com/archive/32054/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/32054/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/32054/#comments</comments><pubDate>Sat, 27 Jan 07 15:18:23 +0100</pubDate><category>Virus News</category><description><![CDATA[Another Rechnung spam,More details can see here:<a href="http://www.cisrt.org/enblog/read.php?2" target="_blank">http://www.cisrt.org/enblog/read.php?2</a> 
]]></description></item><item><title>Rechnung spam </title><link>http://smallmo.reallifelog.com/archive/31456/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/31456/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/31456/#comments</comments><pubDate>Thu, 25 Jan 07 16:21:42 +0100</pubDate><category>Virus News</category><description><![CDATA[CISRT Lab detected&#160;that a trojan spam was spreading in Germany.Kaspersky detected it as Trojan-Downloader.Win32.Agent.ann,and Trend Micro detected it as TROJ_YABE.AV.<br />
<br />
More details,you can see here:<a href="http://www.cisrt.org/enblog/read.php?1"><strong><font color="#356080">Rechnung spam come</font></strong></a>
]]></description></item><item><title>Europen Spam Storm</title><link>http://smallmo.reallifelog.com/archive/29446/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/29446/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/29446/#comments</comments><pubDate>Sat, 20 Jan 07 16:43:55 +0100</pubDate><category>Virus News</category><description><![CDATA[Two&#160;trojan spams&#160;are now spreading very quickly in Europe.I think most of Europen friends have&#160;received these spams.Most AV vendors have already updated their database such as Symantec,Trendmicro,Mcafee,F-Secure,Panda,Sophos,Kaspersky.Of course,our team also declared an alert on our Chinese blog at 14:29,Jan.20,2007(+0800).<br />
<br />
More details about this two trojan,you can see on the&#160;webs of&#160;most AV vendors.<br />
Kaspersky detected them as&#160;Trojan-Downloader.Win32.Small.dam and Trojan-Downloader.Win32.Agent.bet.
]]></description></item><item><title>MS07-002 for Asia Users Re-released</title><link>http://smallmo.reallifelog.com/archive/29066/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/29066/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/29066/#comments</comments><pubDate>Fri, 19 Jan 07 11:36:26 +0100</pubDate><category>Vulnerbility News</category><description><![CDATA[<p>
Microsoft re-released MS07-002 to re-offer the security update to customers with Microsoft Excel 2000 today.The security update previously did not correctly process the phonetic information that is embedded in files that are created by using Excel in the Korean, Chinese, or Japanese executable mode.<br />
<br />
MS07-002: <strong><a href="http://www.microsoft.com/technet/security/Bulletin/MS07-002.mspx" target="_blank">Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (927198)</a></strong> 
</p>
]]></description></item><item><title>Phishing email: Hsbc Bank</title><link>http://smallmo.reallifelog.com/archive/28743/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/28743/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/28743/#comments</comments><pubDate>Thu, 18 Jan 07 11:28:30 +0100</pubDate><category>Phising News</category><description><![CDATA[<p>
A phishing email which pretended to be <strong>Hsbc Bank</strong> was found today.The uses of <strong>Hsbc Bank</strong> should be careful.<br />
<br />
The phishing email is like the following:<br />
<br />
<strong>Subject</strong>: Warning: Instant Update Required<br />
<strong>Body</strong>:<br />
Security
</p>
<p>
<br />
Get.Safe.Online!
</p>
<p>
Due to our early system updates and server upgrades today from 11 PM till 12 Am,
</p>
<p>
May not work.
</p>
<p>
Also we are verifying all user information, so help us to speed up proccess by
</p>
<p>
Submitting Your information
</p>
<p>
Verification link:
</p>
<p>
http://www.hsbc.co.uk/1/2/pib/2007
</p>
<p>
<br />
Verifications like these happens like 3-4 times in ayear.
</p>
<p>
<br />
Thank You for submitting Your information,
</p>
<p>
Best Regards,
</p>
<p>
HSBC Online Service<br />
------<br />
The link in the email redicts to a phishing web.The web is as the following:<br />
http://www.fungamesforu.com/banner/www.hsbc.co.uk/instant-update/2007/index.html<br />
<br />
PS:I also found another phishing web of <strong>Bank of America</strong>,the web&#39;s url is as the following:<br />
http://www.bksdisco.de/boa/
</p>
]]></description></item><item><title>Phishing email: Nationwide's Internet Banking</title><link>http://smallmo.reallifelog.com/archive/28543/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/28543/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/28543/#comments</comments><pubDate>Wed, 17 Jan 07 17:18:56 +0100</pubDate><category>Phising News</category><description><![CDATA[I also received a phishing email about <strong>Nationwide&#39;s Internet Banking</strong>. Nationwide&#39;s users should be careful.<br />
<br />
The email is like the following:<br />
<br />
Subject:&#160; Attention!! Your Nationwide Account Has Been Violated!! <br />
Body:<br />
<a href="http://vfs.reallifelog.com/2007/01/17/2dc9af0f464893d6da3ae724bf9439f6.jpg"><img src="http://vfs.reallifelog.com/2007/01/17/1d28d7c92951064f6b59dbd9b25e80e0.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/01/17/2dc9af0f464893d6da3ae724bf9439f6.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/01/17/b51c704dc850de548ae86318014e82b3.jpg### ###ID:24657###" width="460" height="215" /></a><br />
<br />
When clicked the link in the email,it will visit a phishing web:<br />
<a href="h*p://krovla.net/modules/exmenu/util/cgi/PageNamehhpayusafuserhgadssecuressl7r2vbd7d888PageNamehhpayusafuserhgadssecuressl7r2vbd7d888PageNamehhpayusafuserhgadssecuressl7r2vbd7d888PageNamehhpayusafuserhgadssecuressl7r2vbd7d888/olb2.nationet.comdefault2.aspID=3c0bb2e15f32dd074f90eb6239b866ae3eb.html" target="_blank">ht tp://krovla.net</a>
]]></description></item><item><title>Phishing email: Citibank</title><link>http://smallmo.reallifelog.com/archive/28530/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/28530/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/28530/#comments</comments><pubDate>Wed, 17 Jan 07 16:37:24 +0100</pubDate><category>Phising News</category><description><![CDATA[I received&#160;two phishing emails about Citibank today.It was&#160;written by Germany.Germany Citibank users should be careful.<br />
<br />
The email is like the following:<br />
<br />
<strong>Subject</strong>: Citibank - Neues Online-Banking-Schutzsystem im Jahre 2007<br />
<strong>Body</strong>:<a href="http://vfs.reallifelog.com/2007/01/17/b050f663021ad530633f6e440dfef214.jpg"><br />
<img src="http://vfs.reallifelog.com/2007/01/17/32d1d49fc84e5f5833bc1825b2ec0cfa.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/01/17/b050f663021ad530633f6e440dfef214.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/01/17/a5bc9c0856b9ef958f9a81b75b060c62.jpg### ###ID:24648###" width="460" height="278" /></a><br />
<br />
Translate the body into English by Google:<br />
----<br />
<div id="result_box" dir="ltr">
Very honoured visitors, <br />
since unauthorized access attempts are made ever more frequent bank accounts, our bank line seized the resolution over the transition of the whole on-line Banking system to platform of a new generation, which ensures our customer as well as its accounts 100% security and confidentialness. A singular virus and fraud protection! They need to confirm only the account registration on this platform. Click here and indicate you your password and Login. There is not further mA? took necessarily!! We ask because of possible incommodities for apology. We hope for your amplifier? ndnis and our further co-operation:<br />
http://mirror.citibank.de/security/iol/update.do<br />
<br />
Support Team.<br />
----<br />
When the users clicked this link,it will vist two phishing web:<br />
h*p://210.74.232.53:8246/citibank.de/applogin/confirm/index.php<br />
h*p://210.201.211.241:8246/citibank.de/applogin/confirm/index.php<br />
</div>
]]></description></item><item><title>MS07-004 VML integer overflow exploit</title><link>http://smallmo.reallifelog.com/archive/28455/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/28455/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/28455/#comments</comments><pubDate>Wed, 17 Jan 07 11:48:40 +0100</pubDate><category>Vulnerbility News</category><description><![CDATA[Hello,everyone.I want to tell you a&#160;message that MS07-004 VML integer overflow exploit is now published on internet.The poc is tested on WinXP SP2 Korean version.<br />
TrendMicro&#160;also reported this exploit,detected it as <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=EXPL%5FEXECOD%2EC&#38;VSect=T" target="_blank">EXPL_EXECOD.C</a>.<br />
Kaspersky detected it as Exploit.HTML.IframeBof.<br />
<br />
I also found a Chinese Poc of this exploit today.It can run on XP SP2 pro.I think it will be used widely soon.<br />
<br />
Have&#160;you fixed this vulnerbility?If not,please fixed now:<a href="http://www.microsoft.com/technet/security/bulletin/ms07-004.mspx" target="_blank">Microsoft Security Bulletin MS07-004</a> 
]]></description></item><item><title>Phising Email: ANZ bank</title><link>http://smallmo.reallifelog.com/archive/27609/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/27609/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/27609/#comments</comments><pubDate>Sun, 14 Jan 07 16:38:42 +0100</pubDate><category>Phising News</category><description><![CDATA[I received a phishing email today.It&#39;s about <strong>ANZ bank</strong>.Like other phishing bank email,it steal the account of the customer of <strong>ANZ bank</strong>.<br />
<br />
The phishing email is like the following:<br />
<br />
<strong>Subject</strong>: ANZ Bank Customers Verification<br />
<strong>Body</strong>:<a href="http://vfs.reallifelog.com/2007/01/14/72027c7a6847dffd1d0bfa934227933c.jpg"><br />
<img src="http://vfs.reallifelog.com/2007/01/14/b6787022d4787484c87c903a69d81644.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/01/14/72027c7a6847dffd1d0bfa934227933c.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/01/14/6b85481bdbaad11d6c6aafbb59b33241.jpg### ###ID:24019###" width="419" height="440" /></a><br />
<br />
When you click the link in mail,you will visit a phishing web(ht tp://www.anz-au.com/).The real link of ANZ bank is &quot;http://www.anz.com&quot;.So you should&#160;be careful.
]]></description></item><item><title>Phising email: Mysurf365 account</title><link>http://smallmo.reallifelog.com/archive/26907/</link><dc:creator>Smallmo</dc:creator><guid isPermaLink="true">http://smallmo.reallifelog.com/archive/26907/#permalink</guid><comments>http://smallmo.reallifelog.com/archive/26907/#comments</comments><pubDate>Fri, 12 Jan 07 18:04:22 +0100</pubDate><category>Phising News</category><description><![CDATA[Today,i recevied a phishing email.It&#39;s something about Mysurf365 account.<br />
<br />
The email is following:<br />
<br />
<strong>Subject</strong>: Your mysurf365 accounte is deactivate!<br />
<strong>Body</strong>:<a href="http://vfs.reallifelog.com/2007/01/12/49174086ba79769febb35a4d5e12364f.jpg"><br />
<img src="http://vfs.reallifelog.com/2007/01/12/12dbde797af317a65f04f67311417958.jpg" border="0" alt="###FULLSIZE:http://vfs.reallifelog.com/2007/01/12/49174086ba79769febb35a4d5e12364f.jpg### ###THUMBNAIL:http://vfs.reallifelog.com/2007/01/12/c81aad362bb624d723c9f46053f593a0.jpg### ###ID:23123###" width="460" height="215" /></a><br />
If you click the link in email,it will redict to another phishing web(ht tp://mysurf365.ke0.eu).It will steal your mysurf365 account.Please be careful.
]]></description></item></channel></rss>
