<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Barracuda Labs Internet Security Blog &#187; Email Security</title>
	<atom:link href="http://www.barracudalabs.com/wordpress/index.php/category/email-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barracudalabs.com/wordpress</link>
	<description></description>
	<lastBuildDate>Fri, 27 Aug 2010 23:16:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>3 resumes you don&#8217;t want to open</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/08/27/3-resumes-you-dont-want-to-open/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/08/27/3-resumes-you-dont-want-to-open/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 18:13:24 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=666</guid>
		<description><![CDATA[If you&#8217;re in any kind of business there&#8217;s a good chance you have to deal with resumes on a daily basis, especially if you&#8217;re a manager or Human Resources professional.  While you probably delete that Viagra ad and ignore the promise of Nigerian riches, when a resume hits your inbox, you read it.
Spammers know this [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re in any kind of business there&#8217;s a good chance you have to deal with resumes on a daily basis, especially if you&#8217;re a manager or Human Resources professional.  While you probably delete that Viagra ad and ignore the promise of Nigerian riches, when a resume hits your inbox, you read it.</p>
<p>Spammers know this and have been increasingly presenting malware as if it were a resume, hoping that the recipient will be so curious about a potential applicant that they open or run something that they shouldn&#8217;t.</p>
<p>The Barracuda Labs spam monitoring center has detected a recent increase in the amount of this fake resume spam from multiple sources.  While the messages are similar, the threats they carry are all different.  Here are three cautionary examples&#8230;</p>
<p><br style="”height: 4em”;" /><br />
<br style="”height: 4em”;" /></p>
<hr />
<h5>HTML attachment</h5>
<p>One common feature of these fake resumes is that the spammer keeps the  message short and sweet, hoping you&#8217;ll open the attachment to see if this is that one resume they&#8217;ve been waiting for.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_email.jpg"><img class="alignnone size-full wp-image-668" title="Resume1_email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_email.jpg" alt="" width="450" height="309" /></a></p>
<p>Of course in this case better grammar would help make the sale.   This particular message contains an HTML attachment, something our honeypots have seen a great deal of in the past week.    HTML attachments are less likely to be filtered by email scanning software that might otherwise reject binary attachments by default, and even end users who are conditioned not to open and run programs might look at a HTML file and think that it is harmless.</p>
<p>Except that this HTML is anything but harmless.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_html.jpg"><img class="alignnone size-full wp-image-669" title="Resume1_html" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_html.jpg" alt="" width="450" height="310" /></a></p>
<p>The attachment is 100% obfuscated malicious JavaScript.   Opening it in a browser (which is the default action when clicked) raises an alert</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_malware1.jpg"><img class="alignnone size-full wp-image-673" title="Resume1_malware1" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_malware1.jpg" alt="" width="450" height="319" /></a></p>
<p>and sends you off to a bogus antivirus site.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_malware2.jpg"><img class="alignnone size-full wp-image-683" title="Resume1_malware2" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume1_malware2.jpg" alt="" width="450" height="338" /></a></p>
<p>Don&#8217;t open suspicious HTML attachments.   Email the sender and ask for the information in a different format, such as a Word document or text file. <br style="”height: 4em”;" /><br />
<br style="”height: 4em”;" /></p>
<hr />
<h5>RTF attachment</h5>
<p>Since the Rich Text Format (RTF) is handled by Windows Wordpad and Microsoft Word, you wouldn&#8217;t necessarily be surprised to get an email with a resume in that format</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_email.jpg"><img class="alignnone size-full wp-image-686" title="Resume2_email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_email.jpg" alt="" width="450" height="309" /></a></p>
<p>However, it is possible to completely embed an executable program within an RTF document, and that&#8217;s what we have here.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_rtf.jpg"><img class="alignnone size-full wp-image-687" title="Resume2_rtf" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_rtf.jpg" alt="" width="450" height="300" /></a></p>
<p>When first opened the filename of this embedded object only partly displays.   Still, clicking on it does display a security warning that should make you think twice.   After all, a resume doesn&#8217;t normally need to be &#8220;Run&#8221;.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_rundlg.jpg"><img class="alignnone size-full wp-image-688" title="Resume2_rundlg" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_rundlg.jpg" alt="" width="450" height="470" /></a></p>
<p>If you do click run, nothing seems to happen.   However, if you&#8217;re watching your internet traffic you&#8217;ll see the telltale signs of a <a href="http://en.wikipedia.org/wiki/Zeus_%28trojan_horse%29" target="_blank">Zeus Trojan</a> infection.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_pcap.jpg"><img class="alignnone size-full wp-image-689" title="Resume2_pcap" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume2_pcap.jpg" alt="" width="450" height="450" /></a></p>
<p>A Zeus trojan will quietly examine your internet traffic looking for usernames and passwords, and then send them back to criminals who use them to take over online accounts.  Many cases of online banking fraud involve passwords stolen by this malware family.</p>
<p><br style="”height: 4em”;" /><br />
<br style="”height: 4em”;" /></p>
<hr />
<h5>ZIP attachment</h5>
<p>The last example has the most convincing message text, and the file name of the attachment includes a persons name, making it look less threatening</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume3_email.jpg"><img class="alignnone size-full wp-image-692" title="Resume3_email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume3_email.jpg" alt="" width="450" height="446" /></a></p>
<p>But once you&#8217;ve opened the .zip attachment the alarm bells should be ringing.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume3_zipinfo.jpg"><img class="alignnone size-full wp-image-693" title="Resume3_zipinfo" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume3_zipinfo.jpg" alt="" width="426" height="530" /></a></p>
<p>A careful check of the properties of the file inside shows it is an executable, and clicking on it would run it.  As we said above, resumes do not normally need to be &#8220;Run&#8221;.   Doing so just installs a fake antimalware named SecurityTool onto your computer.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume3_malware.jpg"><img class="alignnone size-full wp-image-694" title="Resume3_malware" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Resume3_malware.jpg" alt="" width="450" height="338" /></a></p>
<p><br style="”height: 4em”;" /><br />
<br style="”height: 4em”;" /><br />
If you or your colleagues handle resumes be careful of unsolicited or unanticipated resume emails.  Examine any resume attachments carefully before opening them, and as we repeatedly stress, <em>never</em> press the “Run” button unless you are certain that is appropriate &#8211; it rarely is.</p>
<p><a title="Barracuda Spam &amp; Virus Firewall" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.barracudanetworks.com');" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> customers are protected from these attacks.</p>
<p><br style="”height: 4em”;" /></p>
<p><br style="”height: 4em”;" /></p>
<p><em>Dave Michmerhuizen &#8211; Barracuda Labs</em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F08%2F27%2F3-resumes-you-dont-want-to-open%2F&amp;linkname=3%20resumes%20you%20don%26%238217%3Bt%20want%20to%20open"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/08/27/3-resumes-you-dont-want-to-open/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wedding Bells Ringing in Malware</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/08/18/wedding-bells-ringing-in-malware/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/08/18/wedding-bells-ringing-in-malware/#comments</comments>
		<pubDate>Wed, 18 Aug 2010 15:05:42 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=628</guid>
		<description><![CDATA[by Barracuda Labs
Weddings are joyous affairs, happy occasions for celebration. When friends find a soulmate and announce their intentions to the world, it&#8217;s exciting.  We&#8217;re thrilled for them and we want the details right away.
Well, not so fast.
Barracuda Labs spam honeypots have recently detected spammers sending multiple wedding-themed emails, hoping to catch people with [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><span style="color: #888888;"><em>by Barracuda Labs</em></span></p>
<p style="text-align: left;">Weddings are joyous affairs, happy occasions for celebration. When friends find a soulmate and announce their intentions to the world, it&#8217;s exciting.  We&#8217;re thrilled for them and we want the details right away.</p>
<p style="text-align: left;">Well, not so fast.</p>
<p style="text-align: left;">Barracuda Labs spam honeypots have recently detected spammers sending multiple wedding-themed emails, hoping to catch people with their guards down.  The messages can be quite convincing, but there is no &#8220;happily ever after&#8221; in the malware that is attached to them.</p>
<p style="text-align: left;">Consider this wedding invitation:</p>
<div id="attachment_637" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/wedding1_email1.jpg"><img class="size-full wp-image-637 " title="wedding1_email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/wedding1_email1.jpg" alt="" width="450" height="789" /></a><p class="wp-caption-text">&quot;Wedding Invitation&quot; email</p></div>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">If the attached &#8220;Wedding Card&#8221; is opened, it launches a fake antivirus &#8211; SecurityTool:</p>
<div class="mceTemp" style="text-align: left;">
<dl id="attachment_631" class="wp-caption alignnone" style="width: 460px;">
<dt class="wp-caption-dt"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/wedding1_fakeav.jpg"><img class="size-full wp-image-631 " title="wedding1_fakeav" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/wedding1_fakeav.jpg" alt="Wedding Card results" width="450" height="338" /></a></dt>
<dd class="wp-caption-dd">Result of opening the &#8220;Wedding Card&#8221;</dd>
</dl>
</div>
<p style="text-align: left;">
<p style="text-align: left;">In addition to dropping SecurityTool on the system, the Wedding Card also downloads Trojan.Fitmu.A:</p>
<div id="attachment_633" class="wp-caption alignnone" style="width: 469px"><a title="Download of password stealer" href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/wedding1_pcap.jpg"><img class="size-full wp-image-633" title="wedding1_pcap" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/wedding1_pcap.jpg" alt="" width="459" height="164" /></a><p class="wp-caption-text">Download of password stealer</p></div>
<p style="text-align: left;">
<p style="text-align: left;">This program quietly runs in the background looking for usernames and passwords to steal.  In particular it steals FTP passwords, and stolen FTP passwords are the most common way that sites are hacked.</p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
<hr />The spammers are casting a broad net, even targeting users who might be planning their own wedding. Say you are busy trying to arrange a venue, finalize a contract for catering, find music and a photographer, and then receive an email such as this:</p>
<div id="attachment_642" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Wedding2_email.jpg"><img class="size-full wp-image-642" title="Wedding2_email" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Wedding2_email.jpg" alt="" width="450" height="682" /></a><p class="wp-caption-text">&quot;Wedding Contract&quot; email</p></div>
<p style="text-align: left;">
<p style="text-align: left;">Upon first glance and a quick scan, it could appear as your legitimate contract (of course, hopefully the users will notice if the venue is not one they have been reviewing!). If the attachment is opened, it does not appear to do anything at all.  Nothing displays.  However, more is going on behind the scenes.</p>
<p style="text-align: left;"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Wedding2_pcap1.jpg"><img class="alignnone size-full wp-image-660" title="Wedding2_pcap" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/08/Wedding2_pcap1.jpg" alt="" width="450" height="183" /></a></p>
<p style="text-align: left;">The attachment is actually a Zeus Trojan, a password stealer that specializes in online banking passwords.  The traffic here shows the Trojan retrieving its configuration and checking in with its command and control server.</p>
<p style="text-align: left;">The bottom line? Stay alert, scrutinize emails carefully and spread the word to your friends and co-workers.  Being aware of these spam attacks helps prevent their success.</p>
<p style="text-align: left;">
<p style="text-align: left;"><a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a>, <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filter</a> and <a title="SaaS Web Security" href="http://www.barracudanetworks.com/ns/products/purewire_web_security_service_overview.php" target="_blank">Barracuda Web Filtering Service</a> customers are protected from this attack.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F08%2F18%2Fwedding-bells-ringing-in-malware%2F&amp;linkname=Wedding%20Bells%20Ringing%20in%20Malware"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/08/18/wedding-bells-ringing-in-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Spam Pretends to be Xerox Scanner Output</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/07/16/new-spam-pretends-to-be-xerox-scanner-output/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/07/16/new-spam-pretends-to-be-xerox-scanner-output/#comments</comments>
		<pubDate>Sat, 17 Jul 2010 02:46:49 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=536</guid>
		<description><![CDATA[by Barracuda Labs
Barracuda Labs spam monitoring systems have picked up a massive new spam campaign whose messages pretend to be output files from a popular Xerox office copier.

Hundreds of thousands of these messages are circulating around the globe, titled Scan from a Xerox WorkCentre Pro and containing a single .zip file attachment tagged with a [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #888888;">by Barracuda Labs</span></em></p>
<p><a title="Internet Security Data" href="http://www.barracudalabs.com" target="_blank">Barracuda Labs</a> spam monitoring systems have picked up a massive new spam campaign whose messages pretend to be output files from a popular Xerox office copier.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_Workcentre.jpg"><img class="alignnone size-full wp-image-538" title="XS_Workcentre" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_Workcentre.jpg" alt="" width="339" border="0" /></a></p>
<p>Hundreds of thousands of these messages are circulating around the globe, titled <strong>Scan from a Xerox WorkCentre Pro</strong> and containing a single .zip file attachment tagged with a random number that helps them avoid detection by anti-spam technology. In fact, <a title="Xerox Scanner Spam Detection" href="http://www.virustotal.com/analisis/bbe4ef632f3a8043b8adac6bb03b8a8b4ba6842154a018075644c16265a19176-1279282082" target="_blank">Virus Total</a> calculates detection rates at around 19.5% as referenced by certain <a title="Xerox Scanner Spam- Tech Herald" href="http://www.thetechherald.com/article.php/201028/5899/Criminals-pushing-Rogue-anti-Virus-disguised-as-scanned-documents?page=1" target="_blank">TechHerald</a> employees today.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_EMAIL.jpg"><img class="alignnone size-full wp-image-537" title="XS_EMAIL" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_EMAIL.jpg" alt="" width="450" border="0" /></a></p>
<p>The message format closely mimics the one used by a real Xerox WorkCentre Pro, except for one detail &#8211; Xerox scanners do not email their outputs using the .zip format. The WorkCentre Pro from Xerox typically scans documents to PDF, email or FTP accounts.</p>
<p>The message text claims that the attachment is a zipped .doc file, and the .zip file itself hides the true extension of the file contained within.  It is not until you go to open the file that you see its true nature.  It is an executable and it is not scanner output &#8211; it is a variant of <a href="http://www.virustotal.com/analisis/b35db0f382b0e9dbdcd5f287867593ea2ca8fbde65b65a9414f3e51c4c6f67eb-1279315371" target="_blank">Trojan Oficla</a>.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_RunDialog.jpg"><img class="alignnone size-full wp-image-544" title="XS_RunDialog" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_RunDialog.jpg" alt="" width="450" border="0" /></a></p>
<p>Choosing  <span style="text-decoration: underline;">R</span>un (which you should not do) seems to do nothing at all &#8211; the Trojan runs but does not display any decoy image.  Rather, it simply installs itself and gets to work in the background downloading other malware.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_Pcap1.jpg"><img class="alignnone size-full wp-image-546" title="XS_Pcap" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/07/XS_Pcap1.jpg" alt="" width="450" border="0" /></a></p>
<p>Samples executed at <a title="Internet Security Data" href="http://www.barracudalabs.com" target="_blank">Barracuda Labs</a> quickly start up a Spambot which sends out more copies of the same message.</p>
<p>As always, never trust unexpected emails, and in particular, <em>never</em> press the &#8220;<span style="text-decoration: underline;">R</span>un&#8221; button unless you are 100% certain of what you are doing.  Word documents are &#8220;opened&#8221; and they are not &#8220;run&#8221; at any time. And, of course, always keep your security software updated on your system. If this message lands in your inbox, please delete and make sure to spread this message with your friends and colleagues.</p>
<p><a title="Barracuda Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> customers are protected from this attack.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F07%2F16%2Fnew-spam-pretends-to-be-xerox-scanner-output%2F&amp;linkname=New%20Spam%20Pretends%20to%20be%20Xerox%20Scanner%20Output"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/07/16/new-spam-pretends-to-be-xerox-scanner-output/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Spam Poses as Spam Fighting Email</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/06/30/new-spam-poses-as-spam-fighting-email/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/06/30/new-spam-poses-as-spam-fighting-email/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 18:32:53 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=473</guid>
		<description><![CDATA[by Barracuda Labs
This week a new sort of spam started showing up in the Barracuda Labs Spam Honeypots &#8211; fake sender verification emails such as the one below:

Sender Verification emails ask users to verify that they sent a particular email to someone, usually by responding with another email, or as in this case, by clicking [...]]]></description>
			<content:encoded><![CDATA[<p><em>by Barracuda Labs</em></p>
<p>This week a new sort of spam started showing up in the Barracuda Labs Spam Honeypots &#8211; fake sender verification emails such as the one below:</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/06/SenderVerification2.jpg"><img class="alignnone size-full wp-image-487" title="SenderVerification" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/06/SenderVerification2.jpg" border="0" alt="" width="450" /></a></p>
<p><strong>Sender Verification</strong> emails ask users to <em>verify </em>that they <em>sent</em> a particular email to someone, usually by responding with another email, or as in this case, by clicking on an embedded link.</p>
<p>Under normal circumstances, these emails come from an email server that has been enhanced with  sender verification software as a spam-fighting measure.  While this software is not as common as it once was, these systems still are used by some businesses and ISPs.</p>
<p>However, the example above merely <em>pretends</em> to be one of these verification emails and is not from an email server at all.  Instead, it is cleverly constructed spam whose included link can take the recipient to suspicious Websites, or even offer up executable malware.</p>
<p>This spam appears plausible and easily can trick the unwary email user.</p>
<p>Close examination does reveal several tell-all signs that this email is suspicious. For starters, the name of the person supposedly emailed is missing.  Second, the domain that the email purports to come from is the same domain as that of the user, which makes no sense since the user should not need to verify himself to his own mail server.</p>
<p>Indeed,  one aspect of this campaign is that each spam is carefully tailored to  reference the email domain of the recipient, most likely because that domain is one the recipient knows and trusts.</p>
<p>The message is sent only in HTML format, and the link has varied over time. In some cases, it redirects to Canadian Pharmacy Viagra sites.  In others, the link presents the user with a Windows .EXE to run, which is a variant of the rapidly spreading TDSS rootkit.</p>
<p>While it is easy enough to hover over the link and see that it does not go back to the organization shown as having sent the email, many users will not question the name of the domain in the verification link.</p>
<p>Barracuda Spam &amp; Virus Firewalls block these emails.  We suggest users take note and warn other email users of this new social engineering tactic.  These emails do not <em>fight</em> spam; they <strong>ARE</strong> spam.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F06%2F30%2Fnew-spam-poses-as-spam-fighting-email%2F&amp;linkname=New%20Spam%20Poses%20as%20Spam%20Fighting%20Email"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/06/30/new-spam-poses-as-spam-fighting-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eminem still isn&#8217;t dead</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/06/24/eminem-still-isnt-dead/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/06/24/eminem-still-isnt-dead/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 23:43:31 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=404</guid>
		<description><![CDATA[by Barracuda Labs
Eminem still isn&#8217;t dead&#8230; at least not as of June 2010. Barracuda Labs honeypots have received thousands of copies of a new spam that is trying to take advantage of a venerable hoax that rap artist Eminem has died in a car crash, this time according to CBS news.

The entire poorly written story is contained [...]]]></description>
			<content:encoded><![CDATA[<p><em>by Barracuda Labs</em></p>
<p>Eminem still isn&#8217;t dead&#8230; at least not as of June 2010. Barracuda Labs honeypots have received thousands of copies of a new spam that is trying to take advantage of a venerable <a href="http://urbanlegends.about.com/od/celebrities/a/eminem_dead.htm">hoax</a> that rap artist Eminem has died in a car crash, this time according to CBS news.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/06/EminemDead1.jpg"><img class="size-full wp-image-407 alignnone" title="EminemDead" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/06/EminemDead1.jpg" alt="Eminem Dead hoax email" width="450" border="0" /></a></p>
<p>The entire poorly written story is contained in an image that links to a file, outlined in red above.  The victims are led to believe they are clicking on a CBS story, but actually the file downloads EminemDead.exe.  Running this file installs a backdoor on the victim&#8217;s computer which has very low detection rates &#8211; <a href="http://www.virustotal.com/analisis/7a23ca28ed140478e52c8f2de33a46aaf77ff14029f39f88007a2c52ad45e5df-1277416147">VirusTotal results</a>.</p>
<p>This once again reiterates the importance of never running anything distributed in an email unless the source is known.</p>
<p>Barracuda Spam &amp; Virus Firewalls intercept these emails, and Barracuda Web Filters block the payload.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F06%2F24%2Feminem-still-isnt-dead%2F&amp;linkname=Eminem%20still%20isn%26%238217%3Bt%20dead"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/06/24/eminem-still-isnt-dead/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Who can you trust?</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2010/05/20/who-can-you-trust/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2010/05/20/who-can-you-trust/#comments</comments>
		<pubDate>Thu, 20 May 2010 09:30:03 +0000</pubDate>
		<dc:creator>Barracuda Labs</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spear-phishing]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=370</guid>
		<description><![CDATA[by Barracuda Labs
In slasher movies, there&#8217;s often a scene where terrified teenagers try to trace the phone calls of a homicidal maniac only to discover that the phone calls are coming from inside the building.
A recent spam case that was referred to the Lab reminded us of one of those scenes and underscored the fact [...]]]></description>
			<content:encoded><![CDATA[<p><em>by Barracuda Labs</em></p>
<p>In slasher movies, there&#8217;s often a scene where terrified teenagers try to trace the phone calls of a homicidal maniac only to discover that the phone calls are coming from inside the building.</p>
<p>A recent spam case that was referred to the Lab reminded us of one of those scenes and underscored the fact that everyone should be suspicious of unsolicited emails. This is especially true of unsolicited emails that ask you to run something on your computer, no matter WHO they come from at any time.</p>
<p>In this particular case, the spam emails were sent to users within a medium-sized professional firm.  They were carefully crafted to appear to be an Adobe security update originally sent to the Assistant Director of Information Technology and then individually forwarded from her.   (Names and domains in the message have been changed.)</p>
<p>The bulk of the message looks like a security update from Adobe regarding vulnerability CVE-2010-0193. The linked executable actually is a malicious file that installs a Trojan backdoor program. The linked .PDF also contains a clickable link to the Trojan.  Adobe already has reported this spam campaign here:</p>
<p>http://blogs.adobe.com/psirt/2010/05/alert_adobe_security_update_em.html</p>
<p>What&#8217;s particularly interesting is just above the forwarded message.  The information about the sender of the email &#8211; Jane Doe, Assistant Director of Information Technology, JaneDoe@phished.com &#8211; is &#8216;real&#8217; data, most likely harvested from elsewhere on the Internet, and would appear to be normal to co-workers within her company.  Her email address is used in the body of the forwarded message as well, making it appear that it really was sent directly to Jane and then she is forwarding it along. Except that she isn&#8217;t.</p>
<p>The &#8216;From&#8217; field of the email has been spoofed (i.e., faked), something spammers easily can do. Instead, examination of the internal email headers reveals that the entire message was sent from a compromised computer in West Virginia.</p>
<p>It is common for spam to be sent with faked &#8216;From&#8217; data; however, this case takes that even a step further. The &#8216;From&#8217; name was chosen specifically in order to gain the trust of the users at phished.com who received the messages. This was a deliberate and targeted batch of spam, sometimes called &#8220;spear” phishing, which demonstrates just how clever the bad guys are and just how cautious we as users have to be.</p>
<p>Barracuda Spam Firewalls block these emails.</p>
<p>Below are various screenshots of the targeted attack in action.</p>
<div id="attachment_361" class="wp-caption alignleft" style="width: 288px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf1.jpg"><img class="size-medium wp-image-361" title="The targeted email seemingly coming from inside the organization." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf1-278x300.jpg" alt="spam email message" width="278" height="300" /></a><p class="wp-caption-text">The targeted email seemingly coming from inside the organization. </p></div>
<div id="attachment_362" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf2.jpg"><img class="size-medium wp-image-362" title="The spoofed &quot;from&quot; address." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf2-300x252.jpg" alt="The spoofed &quot;from&quot; address." width="300" height="252" /></a><p class="wp-caption-text">The spoofed &quot;from&quot; address, which appears to be correct.</p></div>
<div id="attachment_363" class="wp-caption alignleft" style="width: 296px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf3.jpg"><img class="size-medium wp-image-363" title="The .PDF mentioned in the email message that contains a malicious link." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf3-286x300.jpg" alt="The .PDF mentioned in the email message that contains a malicious link." width="286" height="300" /></a><p class="wp-caption-text">The .PDF mentioned in the email message that contains a malicious link.</p></div>
<div id="attachment_364" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf4.jpg"><img class="size-medium wp-image-364" title="Malicious file in action: the presumed software license agreement." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf4-300x281.jpg" alt="Malicious file in action: the presumed software license agreement." width="300" height="281" /></a><p class="wp-caption-text">Malicious file in action: the presumed software license agreement.</p></div>
<div id="attachment_365" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf5.jpg"><img class="size-medium wp-image-365" title="Malicious file in action: setup wizard." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf5-300x233.jpg" alt="Malicious file in action: setup wizard." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: setup wizard.</p></div>
<div id="attachment_366" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf6.jpg"><img class="size-medium wp-image-366" title="Malicious file in action: accepting terms of the license agreement." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf6-300x233.jpg" alt="Malicious file in action: accepting terms of the license agreement." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: accepting terms of the license agreement.</p></div>
<div id="attachment_367" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf7.jpg"><img class="size-medium wp-image-367" title="Malicious file in action: ready to install." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf7-300x233.jpg" alt="Malicious file in action: ready to install." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: ready to install.</p></div>
<div id="attachment_368" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf8.jpg"><img class="size-medium wp-image-368" title="Malicious file in action: prompt to reboot." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf8-300x233.jpg" alt="Malicious file in action: prompt to reboot." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: prompt to reboot.</p></div>
<div id="attachment_369" class="wp-caption alignleft" style="width: 310px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf9.jpg"><img class="size-medium wp-image-369" title="Malicious file in action: execution complete." src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2010/05/adobepdf9-300x233.jpg" alt="Malicious file in action: execution complete." width="300" height="233" /></a><p class="wp-caption-text">Malicious file in action: execution complete.</p></div>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2010%2F05%2F20%2Fwho-can-you-trust%2F&amp;linkname=Who%20can%20you%20trust%3F"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2010/05/20/who-can-you-trust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Safety: Tips to Protect Your Information</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2009/12/21/online-safety-tips-to-protect-your-information/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2009/12/21/online-safety-tips-to-protect-your-information/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 11:41:47 +0000</pubDate>
		<dc:creator>vives</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://cs.barracudalabs.net/wordpress/?p=126</guid>
		<description><![CDATA[Posted by: Barracuda Labs
With the increased awareness and attention around incidents of identity theft, consumers are becoming more vigilant in how they provide personal information online. At the same time, businesses that require such information to complete a transaction also must evaluate how they collect that information online from consumers.
For example, a colleague recently forwarded [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #888888;">Posted by: Barracuda Labs</span></p>
<p>With the increased awareness and attention around incidents of identity theft, consumers are becoming more vigilant in how they provide personal information online. At the same time, businesses that require such information to complete a transaction also must evaluate how they collect that information online from consumers.</p>
<p>For example, a colleague recently forwarded the email below from Southwest requesting personal information to complete the Transportation Security Administration’s (TSA) Secure Flight verification. Because the email was sent after the flight reservation was booked, it was unclear to the recipient whether or not the email was legitimate. Upon examination, it is clear that this is a legitimate email from Southwest; however, it is one that could easily be forged by a spammer or hacker attempting to collect a user’s personal information.</p>
<p>As people are making final travel arrangements and gift purchases online in this last week leading up to the holidays, Barracuda Networks has compiled a number of tips to help consumers discern legitimate emails and Web sites from malicious attempts, as well as recommendations for businesses to better serve their consumers online.</p>
<p>Online consumer safety:</p>
<p>1. Real or fake? Do not click on links included in an email. Instead, type the address directly into your Internet browser.</p>
<p>2. Email security and anti-virus solutions up-and-running. Make sure you have a strong email security solution in place that can block spam and phishing emails as well as detect and block viruses and other malware (including malicious Web links) contained in the email. As an extra precaution, make sure your desktop anti-virus protection is up-to-date and running. This will keep any viruses/malware not sent over email from infecting your computer or adding you to a larger botnet.</p>
<p>3. Strong Web filtering. Having a strong Web filter in place will allow you to block access to potentially dangerous Web sites. Web filters can block downloads by file type and applications that access the Internet (i.e. IM, music services, etc.) that are often used by hackers as a means of transporting malware onto your computer.</p>
<p>4. When in doubt, check it out. If you receive an email from a business that you recently have done an online transaction with – retail, bank, airline, etc. – and are not sure of its authenticity, check it out. Call or email the business to verify that the request is legitimate. Also, you can go directly to that company’s Web site to look for warnings listed of recent Web scams that have targeted the business.</p>
<p>Helping businesses serve customers:<br />
1. On-site, at-once. Request all necessary customer information at the time of purchase, while the consumer is on the Web site. In the case of the Southwest email, if the consumer had been directed to the “MySouthwest Account” to provide this information at the time of flight reservation and purchase, it would have expedited the process for the consumer and eliminated the need to send a follow up email that raised the suspicion of the recipient.</p>
<p>2. Avoid follow up email. Consumers are likely to be more suspicious of emails requesting that they log back into – or create – an account to provide personal information.</p>
<p>3. Provide clear instructions. If sending a follow up email to complete the transaction is unavoidable, provide a clear message to the consumer at the end of the initial online transaction – before they leave the Web site – so that they know to expect an email that will require additional information and what that required information will be.</p>
<p>4. Privacy Policy. Be sure to provide a privacy policy that’s easy to find and is clear on what the Web site will and won’t do with the information entered.</p>
<p>5. Protect customer information on your site. Businesses are responsible for ensuring that the customer information that it collects online is protected from those with malicious intent. Implementing a strong Web application firewall protects the business Web site from being hacked and customer information from being stolen.</p>
<p>The underlying goal here is to enure that businesses that legitimately require user information receive it in a timely and secure fashion. That will keep the bad guys out of consumer’s wallets and bank accounts, and from stealing their identities.</p>
<p><a href="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/TSAemail_.gif"><img class="alignnone size-full wp-image-131" title="TSAemail_" src="http://cs.barracudalabs.net/wordpress/wp-content/uploads/2009/12/TSAemail_.gif" border="0" alt="" width="600" /></a></p>
<p>If you look at the email you will see that we have identified the hyperlinks take you to a legitimate Southwest domain. We know it is a legitimate Web site because the URL contains the Southwest domain.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2009%2F12%2F21%2Fonline-safety-tips-to-protect-your-information%2F&amp;linkname=Online%20Safety%3A%20Tips%20to%20Protect%20Your%20Information"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2009/12/21/online-safety-tips-to-protect-your-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
