<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Barracuda Labs Internet Security Blog &#187; Email Security</title>
	<atom:link href="http://www.barracudalabs.com/wordpress/index.php/category/email-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.barracudalabs.com/wordpress</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 14:24:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Personal Safety: Two Rules For Dealing With Spam</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/12/06/our-two-rules-for-dealing-with-spam/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/12/06/our-two-rules-for-dealing-with-spam/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 01:17:34 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=2142</guid>
		<description><![CDATA[by Dave Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers The Barracuda Labs spam traps recently received a burst of phishing emails targeting Bank of America customers. These particularly well-crafted messages underscore two important rules when dealing with spam. Rule # 1:  Never click on a link in an email, no matter how authentic it might [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Dave Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers</em></span></p>
<p><span style="color: #808080;"><em><br />
</em></span></p>
<p style="text-align: center;"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_clip.jpg"><img class="aligncenter size-full wp-image-2143" style="border: 1px solid black;" title="bofa_clip" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_clip.jpg" alt="" width="451" height="200" /></a></p>
<p>The Barracuda Labs spam traps recently received a burst of phishing emails targeting Bank of America customers. These particularly well-crafted messages underscore two important rules when dealing with spam.</p>
<p style="padding-left: 30px;"><span style="text-decoration: underline;">Rule # 1</span>:  <strong><em>Never </em></strong>click on a link in an email, no matter how authentic it might appear.</p>
<p style="padding-left: 30px;"><span style="text-decoration: underline;">Rule # 2</span>:  If a dialog asks you if you want to RUN something, <strong><em>don&#8217;t</em>.</strong></p>
<p>Many people think they can effectively spot spam by looking for the tell-tale clues such as poor grammar or misspellings. Modern spam campaigns render this approach ineffective.</p>
<p>Take a look at this very convincing email&#8230;</p>
<div id="attachment_2144" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_eml.jpg" target="_blank"><img class="size-full wp-image-2144 " title="Bank of America spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_eml.jpg" alt="Bank of America spam" width="450" height="766" /></a><p class="wp-caption-text">(click for full-size image)</p></div>
<p>There is nothing in this email that initially seems suspicious &#8211; except that the email offers a link to an &#8220;online statement&#8221;, which is actually a malware executable.</p>
<p>This involves rule number one &#8211; <strong><em>never </em></strong>click on a link, even if it might appear to be legitimate, indeed even if it is legitimate.  Such links are so frequently malicious that trying to determine which are and which are not is simply too risky.  It is much safer to directly visit the website of the institution within your web browser.</p>
<p>In the most simple cases, clicking on a malicious link downloads the malware executable and attempts to run it.  Before running it, Windows will prompt you and ask you if you really want to run the file, like so&#8230;</p>
<div id="attachment_2150" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_warn.jpg" target="_blank"><img class="size-full wp-image-2150 " title="Windows warning" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_warn.jpg" alt="Windows Warning" width="450" height="383" /></a><p class="wp-caption-text">(click for full size image)</p></div>
<p>&nbsp;</p>
<p>This triggers rule number two &#8211; <strong><em>never </em></strong>select Run when this dialog is presented.  No reputable, unsolicited, email will contain, or link, to something that needs to be run on your local computer; even if the email is from a trusted or known organization.</p>
<p>What can happen if you ignore these two rules?</p>
<p>In this case, you would have downloaded and executed a <a href="http://www.virustotal.com/file-scan/report.html?id=5f00869d04a2f4a746dd522963f546d87499e578b24add1fa4c06ddfd4f33a59-1321282780" target="_blank">bank password stealer</a>.   One of the first things this Trojan horse does is update itself with a list of banking sites that it should monitor for transmitted usernames and passwords.</p>
<div id="attachment_2152" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_post.jpg" target="_blank"><img class="size-full wp-image-2152 " title="Password Stealer update" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_post.jpg" alt="Password Stealer update" width="450" height="487" /></a><p class="wp-caption-text">(click for full size image)</p></div>
<p>Once this step is complete the Trojan checks-in with a command and control server in Russia, updating it with any banking credentials it finds.</p>
<div id="attachment_2154" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_pcap.jpg" target="_blank"><img class="size-full wp-image-2154 " title="Trojan Traffic" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/11/bofa_pcap.jpg" alt="Trojan Traffic" width="450" height="381" /></a><p class="wp-caption-text">(click for full size image)</p></div>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F12%2F06%2Four-two-rules-for-dealing-with-spam%2F&amp;title=Personal%20Safety%3A%20Two%20Rules%20For%20Dealing%20With%20Spam" id="wpa2a_2"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/12/06/our-two-rules-for-dealing-with-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mommar Gaddafi &#8211; 419 spam&#8217;s new favorite subject</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/10/21/mommar-gaddafi-419-spams-new-favorite-subject/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/10/21/mommar-gaddafi-419-spams-new-favorite-subject/#comments</comments>
		<pubDate>Fri, 21 Oct 2011 21:12:35 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=2022</guid>
		<description><![CDATA[by Dave Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers When you are engaged in direct marketing, your first order of business is to get the attention of your customer.  This is just as true for Nigerian 419 spammers as it is for everyone else, and widespread news coverage of the recent death of Mommar Gaddafi [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by Dave Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers</em></span></p>
<p style="text-align: center;"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/10/gaddafi_snip.jpg" target="_blank"><img class="aligncenter size-full wp-image-2023" style="border: 1px solid black;" title="Spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/10/gaddafi_snip.jpg" alt="" width="410" height="156" /></a></p>
<p>When you are engaged in direct marketing, your first order of business is to get the attention of your customer.  This is just as true for Nigerian 419 spammers as it is for everyone else, and widespread news coverage of the recent death of Mommar Gaddafi is a gift for the <a href="http://www.scamorama.com" target="_blank">Lads from Lagos</a>.</p>
<p>The spam monitors at Barracuda Labs have been detecting a steady stream of these spams, where the family of a dead African prince has been hastily replaced by the son of the dead Libyan dictator.</p>
<div id="attachment_2024" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/10/gaddafi_eml.jpg" target="_blank"><img class="size-full wp-image-2024" title="Gaddafi-themed spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/10/gaddafi_eml.jpg" alt="Gaddafi-themed spam" width="450" height="343" /></a><p class="wp-caption-text">(Click for larger image)</p></div>
<p>&nbsp;</p>
<p>Of course, by now, we hope that all email users recognize this sort of spam as an attempt to perpetrate <a href="http://www.sec.gov/answers/nigerianadvancefeefraud.htm" target="_blank">Advance Fee Fraud</a>. The spammers pump any respondent for personal financial information and then string them along with promises of millions of dollars once a few paltry &#8216;fees&#8217; are paid in advance &#8211; thus the name, Advance Fee Fraud.</p>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F10%2F21%2Fmommar-gaddafi-419-spams-new-favorite-subject%2F&amp;title=Mommar%20Gaddafi%20%26%238211%3B%20419%20spam%26%238217%3Bs%20new%20favorite%20subject" id="wpa2a_4"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/10/21/mommar-gaddafi-419-spams-new-favorite-subject/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers exploit Steve Jobs death</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/10/07/spammers-exploit-steve-jobs-death/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/10/07/spammers-exploit-steve-jobs-death/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 22:30:28 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Current Events]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1978</guid>
		<description><![CDATA[By Dave Michmerhuizen – Security Researcher Apple Chairman Steve Jobs passed away on October 5, 2011. We all share in the sadness of losing such a technology leader, visionary and innovator. Steve impacted our lives in a multitude of positive ways, through his spirit, his creativity and the word-class products he brought to market. Apple&#8217;s offerings [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #999999;"><em>By Dave Michmerhuizen – Security Researcher</em></span></p>
<p>Apple Chairman Steve Jobs passed away on October 5, 2011. We  all share in the sadness of losing such a technology leader, visionary and innovator. Steve impacted our lives in a multitude of positive ways, through his spirit, his creativity and the word-class products he brought to market. Apple&#8217;s offerings are both mainstream tools and sources of joy &#8211; solving problems and brightening lives everyday, all over the world.  We wish for peace for Steve Jobs and his family.</p>
<p>Unfortunately while many are mourning, others are trying to take advantage of them. Only 24 hours after Jobs&#8217; death spammers began sending insensitive emails claiming otherwise.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/10/stevejobs_emls1.jpg"><img class="alignnone size-full wp-image-1981" title="Steve Jobs spams" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/10/stevejobs_emls1.jpg" alt="Steve Jobs spams" width="450" height="425" /></a></p>
<p>Spams like these capitalize on their shock value. The senders hope that you will be curious just long enough to let down your guard and click on the link.</p>
<p>By now we should all know that these links lead to no good.  Merely clicking on the link in one of these emails leads to a compromised website which redirects the browser multiple times, in some cases finally delivering it to a host serving up the <a href="http://www.enigmasoftware.com/blackhole-exploit-kit-available-free-hackers/" target="_blank">BlackHole exploit kit</a>.</p>
<p>Barracuda Labs is seeing more and more instances of spam linking to servers hosting these exploit kits.   They are increasingly popular with malware distributors because a link has been clicked no further user interaction is required to install their payload.</p>
<p>It saddens us to see these  emails in our honeypots.   Don&#8217;t let the amoral scum who send these things take advantage of you.  If you  see them, delete them right away.</p>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails, while customers using <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> or <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> are protected from the payload.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F10%2F07%2Fspammers-exploit-steve-jobs-death%2F&amp;title=Spammers%20exploit%20Steve%20Jobs%20death" id="wpa2a_6"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/10/07/spammers-exploit-steve-jobs-death/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers exploit confusion over DigiNotar certificate forgeries</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/09/15/spammers-exploit-confusion-over-diginotar-certificate-forgeries/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/09/15/spammers-exploit-confusion-over-diginotar-certificate-forgeries/#comments</comments>
		<pubDate>Thu, 15 Sep 2011 18:45:43 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1946</guid>
		<description><![CDATA[By Dave Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers &#160; Recently Dutch certificate authority DigiNotar suffered a compromise that resulted in the issuance of over 200 forged certificates for a variety of well known web domains including Google, Yahoo and Mozilla. The certificates have been revoked and certificate users have been quick to update their [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>By Dave Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers </em></span></p>
<p>&nbsp;</p>
<p>Recently Dutch certificate authority DigiNotar suffered a compromise that resulted in the issuance of over 200 forged certificates for a variety of well known web domains including Google, Yahoo and Mozilla.</p>
<p>The certificates have been revoked and certificate users have been quick to update their products. Spammers and malware distributors have been just as quick to take advantage of the confusing stories about SSL certificates that have been appearing in the mainstream media.</p>
<p>Consider this spam that we recently started seeing at Barracuda Labs. The message, pitched directly to business customers of the Royal Bank of Canada tries to convince them that their SSL certificate has expired.</p>
<div id="attachment_1952" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/09/royalbank_eml21.jpg" target="_blank"><img class="size-full wp-image-1952  " title="Spam impersonating Royal Bank" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/09/royalbank_eml21.jpg" alt="Spam impersonating Royal Bank" width="450" height="354" /></a><p class="wp-caption-text">(Click for larger image)</p></div>
<p>While it may look like  garden variety phishing spam, this message is much more dangerous. The spammers try to create a sense of urgency with the hope that you will click one of the links to see what happens; which, in this case, is a particularly bad idea because the second link in the message directs the browser to a server hosting an exploit kit. Once the browser visits that site a series of attacks begin which can result in the download of Trojan.Buzus. This nasty payload steals login credentials and opens a backdoor allowing remote control of the now-infected computer.</p>
<div id="attachment_1953" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/09/royalbank_pcap3.jpg" target="_blank"><img class="size-full wp-image-1953 " title="Network traffic of exploit attacks" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/09/royalbank_pcap3.jpg" alt="Network traffic of exploit attacks" width="450" height="249" /></a><p class="wp-caption-text">(Click for larger image)</p></div>
<p>&nbsp;</p>
<p>Ever since the blackhole exploit kit <a href="http://threatpost.com/en_us/blogs/black-hole-exploit-kit-available-free-052311" target="_blank">became widely available</a> earlier this year, the Barracuda Networks Real Time Protection System has been seeing more and more overtly malicious spam directing users to sites such as these which attempt to force malware onto users computers.  All it takes is one initial click on a link to set off a chain of exploits which require no further interaction to infect a computer. As always, we recommend you treat spam messages with great care.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F09%2F15%2Fspammers-exploit-confusion-over-diginotar-certificate-forgeries%2F&amp;title=Spammers%20exploit%20confusion%20over%20DigiNotar%20certificate%20forgeries" id="wpa2a_8"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/09/15/spammers-exploit-confusion-over-diginotar-certificate-forgeries/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How a LinkedIn notice could empty your bank account</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/08/27/how-a-linkedin-notice-could-empty-your-bank-account/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/08/27/how-a-linkedin-notice-could-empty-your-bank-account/#comments</comments>
		<pubDate>Sat, 27 Aug 2011 17:55:30 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1899</guid>
		<description><![CDATA[By Dave Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers We see a lot of spam at Barracuda Labs.  Sometimes they&#8217;re as simple and straightforward as a Viagra ad, but just as often they can be as serious and as devastating as an urban mugging.  We&#8217;ve been watching one of those muggings play out over the [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>By Dave Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers</em></span></p>
<p><span style="color: #808080;"><em><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_b.jpg"><img class="size-full wp-image-1900 alignnone" style="border: 1px solid black;" title="Banks" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_b.jpg" alt="Banks" width="450" height="197" /></a></em></span></p>
<p style="text-align: left;">We see a lot of spam at Barracuda Labs.  Sometimes they&#8217;re as simple and straightforward as a Viagra ad, but just as often they can be as serious and as devastating as an urban mugging.  We&#8217;ve been watching one of those muggings play out over the past few days, and it has reminded us that spam is nothing to take lightly.</p>
<p>Early on the morning of August 23 the spam monitors at Barracuda Labs started detecting a large number of emails claiming to be from <a href="http://www.linkedin.com" target="_blank">LinkedIn</a>.  The quantities were significant, tens of thousands an hour, and these were pretty convincing messages.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_eml1.jpg"><img class="alignnone size-full wp-image-1902" title="Linkedin spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_eml1.jpg" alt="Linkedin spam" width="450" height="427" /></a></p>
<p>As convincing as they may be these emails have nothing to do with LinkedIn.  The from address is fake and the &#8220;Follow this link&#8221; hyperlink leads to one of a set of recently registered domains deliberately set up to serve malicious content</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_eml2.jpg"><img class="alignnone size-full wp-image-1905" title="LinkedIn spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_eml2.jpg" alt="LinkedIn spam" width="450" height="427" /></a></p>
<p>&nbsp;</p>
<p>Most of these sorts of spam attacks simply link to a malware file which the browser then downloads and offers to run. If an antivirus doesn&#8217;t intercept such a file then Windows will ask for permission to run it and it is easy enough to say no.</p>
<p>But this attack is different and much more serious. Each of the malicious domains such as linkedin-reports.com or linkedin-alert.com hosts an exploit kit, a set of malicious payloads that quietly attempt to take advantage of weaknesses in the Web browser and its helper applications.</p>
<p>Clicking on the &#8220;follow this link&#8221; hyperlink in the message doesn&#8217;t appear to have any effect. Nothing seems to happen; however there is a lot going on behind the scenes.</p>
<p>Below is what the behind-the-scenes network traffic looked like.</p>
<div id="attachment_1908" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_pcap2.jpg" target="_blank"><img class="size-full wp-image-1908 " title="Network traffic of exploits" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_pcap2.jpg" alt="Network traffic of exploits" width="450" height="336" /></a><p class="wp-caption-text">(Click for larger image)</p></div>
<p>This traffic capture shows a series of attacks <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_exploit1.jpg" target="_blank">against Internet Explorer</a> (1), <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_exploit2.jpg" target="_blank">against the Adobe PDF reader plug-in</a> (2) and finally <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_exploit3.jpg" target="_blank">against Windows Media Player</a> (3).  Eventually these exploits result in the <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_exploit4.jpg" target="_blank">download </a>of Trojan.Jorik (4).</p>
<p>Trojan.Jorik is a password stealer which gets right to work, periodically checking in with its command and control server (5).</p>
<p>After contacting the control server the Trojan contacts another server (6) for an interesting &#8211; and somewhat scary &#8211; configuration file.</p>
<div id="attachment_1909" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_update.jpg" target="_blank"><img class="size-full wp-image-1909" title="Update with phishing HTML" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/linkedin_update.jpg" alt="Update with phishing HTML" width="450" height="528" /></a><p class="wp-caption-text">(Click for larger image)</p></div>
<p>&nbsp;</p>
<p>These password-stealing Trojans are programmed to insert themselves into the browser stack and can intercept login pages even before they are encrypted by HTTPS.  The list above shows the services that the Trojan is being configured to monitor.  There is more configuration that is not shown in this graphic &#8211; pages of HTML code snippets to be injected into login pages. When a login page for one of the monitored sites is displayed, the corresponding code snippet is added to the page. These code snippets ask for additional security questions or special passwords, information the password thieves want but questions that the legitimate login page does not ask.</p>
<p>Having your online banking credentials stolen is serious stuff, especially if the credentials belong to an organization or business with a hefty bank balance.  Consider the most recent story from Brian Krebs about the <a href="http://krebsonsecurity.com/2011/08/ethieves-steal-217k-from-arena-firm/" target="_blank">Cyber Theft of $217,000 from a nonprofit in Nebraska</a>.</p>
<p>&nbsp;</p>
<p>With so much spam circulating through email servers worldwide, it is easy to become insensitive to the very real danger that  truly malicious spam poses.  Never let down your guard, and never ever follow links in emails even if they appear to be official looking. As you can see from this example, one click can be all it takes.</p>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F08%2F27%2Fhow-a-linkedin-notice-could-empty-your-bank-account%2F&amp;title=How%20a%20LinkedIn%20notice%20could%20empty%20your%20bank%20account" id="wpa2a_10"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/08/27/how-a-linkedin-notice-could-empty-your-bank-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do you ever worry about police impersonations?</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/08/18/do-you-ever-worry-about-police-impersonations/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/08/18/do-you-ever-worry-about-police-impersonations/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 15:49:37 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1886</guid>
		<description><![CDATA[by Shawn Anderson &#8211; Security Researcher Have you ever driven down the road with a police vehicle right behind you? Do your nerves heighten and your stomach drop? This happens to a lot of people, and when the flashing lights turn on there is one thing to do. Pull over, right? The pure adrenaline rush [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #999999;"><em>by Shawn Anderson &#8211; Security Researcher</em></span></p>
<p>Have  you ever driven down the road with a police vehicle right behind you? Do your  nerves heighten and your stomach drop? This happens to a lot of people, and when  the flashing lights turn on there is one thing to do. Pull over, right? The pure  adrenaline rush from thinking, &#8220;What did  I do wrong?&#8221; masks the paranoia of whether or  not the person is really a police officer.</p>
<p>What  would  happen if you received an email from the police department stating that you were  in violation of the law? Would your stomach drop and your nerves kick in as  though the police vehicle just turned on its lights behind you? Would you stop  to think whether the email is legit or not? Unfortunately, impersonating the police can  be very effective for spammers who are  trying to persuade recipients to click on a link or open an attachment. Forcing the recipients to consider their  possible guilt can distract them from questioning the legitimacy of the email  itself.</p>
<p>At  Barracuda Networks, we  are witnessing a large spam outbreak with malicious attachments that impersonates (spoofs) the New York State  police. The email states that the recipient was in violation of the law, and  contains a description of the traffic violation. It also claims to contain the actual ticket  as an attachment with instructions to open it, print it and send it to &#8216;Town  Court&#8217; in some small town somewhere in New York state</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/Traffic-Ticket.jpg" target="_blank"><img class="alignnone size-full wp-image-1887" style="border: 1px solid black;" title="Traffic Ticket spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/08/Traffic-Ticket.jpg" alt="" width="449" height="265" /></a></p>
<p>The  attachment is actually malware, a variant of Trojan.Downloader. If run, it downloads Trojan.Fakealert which further  compromises the computer.</p>
<p>Emails  like these teach a very important lesson.  Many malicious spam messages go to great lengths to appear to be sent  from some official government agency or other large organization. Unfortunately the contents of email messages  are very easy to fake. The sad truth is  that you should never assume that an email message is legitimate. Instead, if an email raises  concerns you should verify the contents by phone or postal mail, and never run  emailed attachments like the one in the message above.</p>
<p>Tips  for configuring your spam firewall to block this attack:</p>
<p>Currently,  the malicious spam is spoofing the “From” address domain of “nyc.gov”. Since  “nyc.gov” has a Hardfail SPF record set up in its DNS txt record, most conventional filters  will block these spoofed messages. Enabling SPF on your spam filter will help  block these spoofed emails.</p>
<p>It  is common, however, that these types of malicious outbreaks will rotate their  sender domains, and it is likely that they’ll spoof other state domains. SPF  records are not always set up or set up properly in DNS for domains that are  commonly spoofed, so relying solely on the SPF filter is not recommended. Other content scanning techniques  are required to block these attacks as they rotate sender domains. Customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> should make sure their Energize Updates are up to date and that they  are on the latest version to help block these types of malicious  emails.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F08%2F18%2Fdo-you-ever-worry-about-police-impersonations%2F&amp;title=Do%20you%20ever%20worry%20about%20police%20impersonations%3F" id="wpa2a_12"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/08/18/do-you-ever-worry-about-police-impersonations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam targeting tax professionals automatically installs malware</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/06/29/spam-targeting-tax-professionals-automatically-installs-malware/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/06/29/spam-targeting-tax-professionals-automatically-installs-malware/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 18:42:09 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1676</guid>
		<description><![CDATA[by David Michmerhuizen &#38; Luis Chapetti &#8211; security researchers &#160; &#160; The criminal gangs that distribute the password stealing Trojan.Zeus have altered their spam campaigns in a frightening new direction.  Already seen targeting their emails at credit point-of-sale users and wire transfer users, their latest spams are now crafted to appeal to tax preparation professionals [...]]]></description>
			<content:encoded><![CDATA[<p><em><span style="color: #808080;">by David Michmerhuizen &amp; Luis Chapetti &#8211; security researchers </span></em></p>
<p>&nbsp;</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_top.jpg" target="_blank"><img class="alignnone size-full wp-image-1677" style="border: 1px solid black;" title="Tax forum spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_top.jpg" alt="Tax forum spam" width="451" height="121" /></a></p>
<p>&nbsp;</p>
<p>The criminal gangs that distribute the password stealing <a href="http://en.wikipedia.org/wiki/Zeus_%28trojan_horse%29" target="_blank">Trojan.Zeus</a> have altered their spam campaigns in a frightening new direction.  Already seen targeting their emails at <a href="http://www.barracudalabs.com/wordpress/index.php/2011/06/17/fake-chase-bank-invite-delivers-password-stealer/" target="_blank">credit point-of-sale users</a> and <a href="http://www.barracudalabs.com/wordpress/index.php/2011/06/21/huge-amounts-of-federal-reserve-spam-delivering-zeus-password-stealer/" target="_blank">wire transfer users</a>, their latest spams are now crafted to appeal to tax preparation professionals by posing as an official IRS communication.  What&#8217;s even worse is that their payload isn&#8217;t an attachment or a link to a download. Rather, the payload is a link to a Web site hosting an exploit kit that probes your computer&#8217;s software and automatically installs the Zeus password stealer.</p>
<p>The messages don&#8217;t give you much to be suspicious about at first.  They come from a generic looking name and use the email-id of the recipient as the subject.</p>
<div id="attachment_1678" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_eml.jpg" target="_blank"><img class="size-full wp-image-1678 " title="Tax Forum Spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_eml.jpg" alt="Tax Forum Spam" width="450" height="413" /></a><p class="wp-caption-text">Tax Forum Spam</p></div>
<p>The text itself is very well written, as well it should be.  It is an almost exact cut and paste of an IRS announcement from 2004.  To be precise,  <a href="http://www.irs.gov/newsroom/article/0,,id=123219,00.html" target="_blank">IR-2004-67</a>.</p>
<p>The item to examine closely is the link embedded near the bottom of the message.  Although it says irs.gov, this link actually points to a set of malicious domains with vaguely official sounding names.  In this case it&#8217;s irsgovnews.com  (warning: do not visit that domain in your Web browser!)</p>
<p>The job of these domains is to send Javascript to your browser to accomplish two things.  First it displays a pop-up message saying that your browser <em>cannot </em>reach the site.</p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_1.jpg" target="_blank"><img class="size-full wp-image-1681  alignnone" title="Fake alert" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_1.jpg" alt="Fake alert" width="450" height="263" /></a></p>
<p>&nbsp;</p>
<p>&#8230;which is <em>not </em>true.  The alert <em>comes from</em> the site itself!  This is to keep you from suspecting what comes next.</p>
<p>What comes next is that the Javascript directs the browser off to another domain that hosts the Blackhole exploit kit.  This kit sends specially crafted messages to the browser that try to take advantage of unpatched weaknesses in browser helpers such as <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_2.jpg" target="_blank">Java</a> or <a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_3.jpg" target="_blank">Windows Media Player</a>.</p>
<p>If any weakness is found then Zeus is downloaded and installed automatically behind the scenes.</p>
<div id="attachment_1684" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_pcap.jpg" target="_blank"><img class="size-full wp-image-1684 " title="Exploit and Zeus network traffic" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/irs3_pcap.jpg" alt="Exploit and Zeus network traffic" width="450" height="225" /></a><p class="wp-caption-text">Exploit and Zeus network traffic</p></div>
<p><a href="http://www.barracudalabs.com/wordpress/index.php/2011/06/21/huge-amounts-of-federal-reserve-spam-delivering-zeus-password-stealer/" target="_blank">Previous spam efforts</a> required you to click &#8220;Run&#8221; in order to install the malware payload.  The use of an exploit kit in this case means that Zeus is installed without user interaction.   Once you click the link in the email, it&#8217;s game over.</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails, while customers using <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> or <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> are protected from the payload.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F06%2F29%2Fspam-targeting-tax-professionals-automatically-installs-malware%2F&amp;title=Spam%20targeting%20tax%20professionals%20automatically%20installs%20malware" id="wpa2a_14"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/06/29/spam-targeting-tax-professionals-automatically-installs-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Huge amounts of Federal Reserve spam delivering Zeus password stealer</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/06/21/huge-amounts-of-federal-reserve-spam-delivering-zeus-password-stealer/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/06/21/huge-amounts-of-federal-reserve-spam-delivering-zeus-password-stealer/#comments</comments>
		<pubDate>Tue, 21 Jun 2011 23:10:49 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[Internet Security Tips]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1608</guid>
		<description><![CDATA[by David Michmerhuizen &#38; Luis Chapetti – Security Researchers Our spam monitoring systems at Barracuda Labs are following a very large spam campaign carrying Trojan.Zeus.   The spam amounts are approaching many hundreds of thousands a day and although they are being delivered to a wide cross-section of Internet users, the content of the spams is [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em>by David Michmerhuizen &amp; Luis Chapetti – Security Researchers</em></span></p>
<p>Our spam monitoring systems at Barracuda Labs are following a very large spam campaign carrying <a href="http://en.wikipedia.org/wiki/Zeus_%28trojan_horse%29" target="_blank">Trojan.Zeus</a>.   The spam amounts are approaching many hundreds of thousands a day and although they are being delivered to a wide cross-section of Internet users, the content of the spams is aimed at users of online banking services.</p>
<p>When spam delivers malware, one of the most common strains it carries is the password-stealing <a href="http://en.wikipedia.org/wiki/Zeus_%28trojan_horse%29" target="_blank">Zeus Trojan</a>.  Zeus specifically targets banking passwords, and the gangs that distribute variants of this malware are especially interested in banking credentials belonging to small businesses and government agencies.  Compared to the average consumer, these entities often have more money in their accounts and set higher limits on wire transfers.   One thing small organizations don&#8217;t always realize is that they do not enjoy the same protections against fraudulent transactions that consumers do.</p>
<p>The spams use graphics hosted by the Federal Reserve and pose as notices of a failed wire transfer:</p>
<div id="attachment_1610" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/fedreserve_eml.jpg" target="_blank"><img class="size-full wp-image-1610 " title="Fake wire transfer spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/fedreserve_eml.jpg" alt="Fake wire transfer spam" width="450" height="317" /></a><p class="wp-caption-text">Fake wire transfer spam</p></div>
<p>Much like last weeks <a href="http://www.barracudalabs.com/wordpress/index.php/2011/06/17/fake-chase-bank-invite-delivers-password-stealer/" target="_blank">Chase Paymentech</a> spam campaign, these notices are of particular interest to financial professionals.  Unlike the more sophisticated Chase emails, these are a simple affair with poorly constructed text and no attempt at hiding the executable nature of the linked payload.</p>
<p>Still, there&#8217;s the possibility that a busy executive might just skim the spam and click on the attachment, resulting in a Windows security warning:</p>
<div id="attachment_1612" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/fedreserve_run2.jpg" target="_blank"><img class="size-full wp-image-1612 " title="Windows security warning" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/fedreserve_run2.jpg" alt="Windows security warning" width="450" height="272" /></a><p class="wp-caption-text">Windows security warning</p></div>
<p>While the spammers try to hide behind a double extension of .pdf.exe, this is no PDF.  This is an executable program, and the Federal Reserve is not going to send you any vital information coded into a program.   <span style="text-decoration: underline;">Don&#8217;t run it</span>.</p>
<p>If you do, you&#8217;ve installed Zeus:</p>
<div id="attachment_1613" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-1613 " title="Zeus network traffic" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/fedreseserve_pcap.jpg" alt="Zeus network traffic" width="450" height="187" /><p class="wp-caption-text">Zeus network traffic</p></div>
<p>It will run quietly in the background, intercepting browser traffic, watching for credentials and sending any it finds off to its command and control server.</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails, while customers using <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> or <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> are protected from the payload.</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F06%2F21%2Fhuge-amounts-of-federal-reserve-spam-delivering-zeus-password-stealer%2F&amp;title=Huge%20amounts%20of%20Federal%20Reserve%20spam%20delivering%20Zeus%20password%20stealer" id="wpa2a_16"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/06/21/huge-amounts-of-federal-reserve-spam-delivering-zeus-password-stealer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Chase Bank invite delivers password stealer</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/06/17/fake-chase-bank-invite-delivers-password-stealer/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/06/17/fake-chase-bank-invite-delivers-password-stealer/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 23:19:52 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[ID Theft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[Internet Security]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1585</guid>
		<description><![CDATA[by David Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers The spam monitoring systems at Barracuda Labs have uncovered an especially objectionable spam campaign that poses as a sign-up email from the Chase Bank credit card processing service Chase Paymentech. We see lots and lots of spam at Barracuda Labs.&#160; Even if the sender isn&#8217;t suspect, [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;" _mce_style="color: #808080;"><em>by David Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers</em></span></p>
<p><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_logo.jpg" _mce_href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_logo.jpg" target="_blank"><img class="size-full wp-image-1586  alignnone" style="border: 1px solid black;" _mce_style="border: 1px solid black;" title="Chase Paymentech logo" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_logo.jpg" _mce_src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_logo.jpg" alt="Chase Paymentech logo" height="159" width="450"></a><br _mce_bogus="1"></p>
<p>The spam monitoring systems at Barracuda Labs have uncovered an especially objectionable spam campaign that poses as a sign-up email from the Chase Bank credit card processing service <a href="http://www.chasepaymentech.com/" _mce_href="http://www.chasepaymentech.com/" target="_blank">Chase Paymentech</a>.</p>
<p>We see lots and lots of spam at Barracuda Labs.&nbsp; Even if the sender  isn&#8217;t suspect, it is still generally easy to spot either because of the  subject matter or flaws in the content.</p>
<p>What makes this spam dangerous is a combination of convincing content and deceptive payload.&nbsp; Examining this spam highlights the risk that comes with assuming one can always judge spam by its appearance alone.</p>
<p>These spams are particularly well done.&nbsp; The only suspicious element is that the From: address is not Chase bank,  an unusual failure given how easy it is to fake the From: field in an  email.</p>
<div class="mceTemp" draggable="">
<dl id="attachment_1587" class="wp-caption alignnone" style="width: 460px" _mce_style="width: 460px;">
<dt class="wp-caption-dt"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_eml.jpg" _mce_href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_eml.jpg" target="_blank"><img class="size-full wp-image-1587  " title="Chase Paymentech spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_eml.jpg" _mce_src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_eml.jpg" alt="Chase Paymentech spam" height="985" width="450"></a><br _mce_bogus="1"></dt>
<dd class="wp-caption-dd">Fake Chase Paymentech email</dd>
</dl>
</div>
<p>The email invites you to activate a credit card payment account and tells you that your first step is to find your merchant ID and user ID in the attached Microsoft Word document.&nbsp;&nbsp; That Word document is what indirectly delivers the malware payload.</p>
<p>Vulnerabilities in Microsoft Word have mostly been patched or mitigated, and it&#8217;s been years since Word document attachments were something most users had to worry about. While users have become more suspicious of programs that must be downloaded and run, they&#8217;re more likely to open a document which is &#8220;just something you read.&#8221;</p>
<p>Unfortunately, malware distributors have recently discovered that common <a href="http://www.adobe.com/support/security/advisories/apsa11-02.html" _mce_href="http://www.adobe.com/support/security/advisories/apsa11-02.html" target="_blank">vulnerabilities</a> in Adobe&#8217;s Flash player can be exploited by embedding the malicious Flash file into a Word document.&nbsp; This takes users who aren&#8217;t likely to suspect a Word document of malicious intent and puts them at risk if they open it.</p>
<p>That&#8217;s what happens here.&nbsp; If you open the attached merchant_info.doc, you can&#8217;t see the Flash control embedded in the document.&nbsp; You really don&#8217;t see much of anything for the minute or two that it takes the Flash code to download and install malware on your Windows computer.</p>
<div class="mceTemp" draggable="">
<dl id="attachment_1593" class="wp-caption alignnone" style="width: 460px" _mce_style="width: 460px;">
<dt class="wp-caption-dt"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_word.jpg" _mce_href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_word.jpg" target="_blank"><img class="size-full wp-image-1593 " title="Word document" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_word.jpg" _mce_src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_word.jpg" alt="Word document" height="321" width="450"></a><br _mce_bogus="1"></dt>
<dd class="wp-caption-dd">Word document</dd>
</dl>
</div>
<p>Once the infection is accomplished, this Word document closes and you&#8217;re back to staring at the email and wondering what went wrong.&nbsp;&nbsp; Meanwhile your computer is running <a href="http://en.wikipedia.org/wiki/Zeus_%28trojan_horse%29" _mce_href="http://en.wikipedia.org/wiki/Zeus_%28trojan_horse%29" target="_blank">Trojan.Zeus</a> in the background.</p>
<div class="mceTemp" draggable="">
<dl id="attachment_1594" class="wp-caption alignnone" style="width: 460px" _mce_style="width: 460px;">
<dt class="wp-caption-dt"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_pcap.jpg" _mce_href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_pcap.jpg" target="_blank"><img class="size-full wp-image-1594 " title="Trojan.Zeus network traffic" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_pcap.jpg" _mce_src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/chase1_pcap.jpg" alt="Trojan.Zeus network traffic" height="199" width="450"></a><br _mce_bogus="1"></dt>
<dd class="wp-caption-dd">Trojan.Zeus network traffic</dd>
</dl>
</div>
<p>Zeus quietly <a href="http://krebsonsecurity.com/2011/03/zeus-innovations-no-h-reports/" _mce_href="http://krebsonsecurity.com/2011/03/zeus-innovations-no-h-reports/" target="_blank">monitors your Internet traffic</a> looking for username and password data.&nbsp; It saves them and periodically sends them off to control servers elsewhere on the Internet.</p>
<p>The content of this spam is of particular interest to financial professionals, making the installation of a password stealer that much worse.&nbsp; Trojan.Zeus has been implicated in many instances of online theft from small business accounts, especially since small business banking involves higher dollar amounts and does not carry the same level of theft protection as consumer accounts do.</p>
<p>The Adobe vulnerabilities that allow this to succeed have been used in a number of recent email attacks.&nbsp; We strongly recommend you upgrade all of your Flash installations by visiting <a href="http://get.adobe.com/flashplayer/" _mce_href="http://get.adobe.com/flashplayer/" target="_blank">http://get.adobe.com/flashplayer</a>.</p>
<p></p>
<p><a href="http://www.barracudanetworks.com/" _mce_href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" _mce_href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails, while customers using <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" _mce_href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> or <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" _mce_href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> are protected from the payload.</p>
<p></p>
<p></p>
<p></p>
<p></p>
<p></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F06%2F17%2Ffake-chase-bank-invite-delivers-password-stealer%2F&amp;title=Fake%20Chase%20Bank%20invite%20delivers%20password%20stealer" id="wpa2a_18"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/06/17/fake-chase-bank-invite-delivers-password-stealer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers dangle Windows 8 as bait</title>
		<link>http://www.barracudalabs.com/wordpress/index.php/2011/06/10/spammers-dangle-windows-8-as-bait/</link>
		<comments>http://www.barracudalabs.com/wordpress/index.php/2011/06/10/spammers-dangle-windows-8-as-bait/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 18:51:38 +0000</pubDate>
		<dc:creator>Dave Michmerhuizen</dc:creator>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.barracudalabs.com/wordpress/?p=1559</guid>
		<description><![CDATA[by David Michmerhuizen &#38; Luis Chapetti &#8211; Security Researchers &#160; Version 8 of Microsoft Windows is under active development and is tentatively scheduled to be released sometime in 2012.   Screen shots have already leaked to the internet, and some opportunistic spammers are already using the promise of a Windows 8 download to lure unsuspecting users [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #808080;"><em> </em><em>by David Michmerhuizen &amp; Luis Chapetti &#8211; Security Researchers</em></span></p>
<p>&nbsp;</p>
<p style="text-align: justify;"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_0.jpg" target="_blank"><img class="aligncenter size-full wp-image-1560" title="windows 8" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_0.jpg" alt="" width="280" height="195" /></a><span style="color: #000000;">Version 8 of Microsoft Windows is under active development and is tentatively scheduled to be released sometime in 2012.   Screen shots have already leaked to the internet, and some opportunistic spammers are already using the promise of a Windows 8 download to lure unsuspecting users into swallowing a malware payload.</span></p>
<p style="text-align: justify;"><span style="color: #000000;"><br />
</span></p>
<p style="text-align: justify;"><span style="color: #000000;">The spam itself is short and simple.  Spammers often make tell-tale spelling and grammar goofs, so keeping the text short is a good way to reduce mistakes.<br />
</span></p>
<div id="attachment_1562" class="wp-caption alignnone" style="width: 459px"><em><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_1.jpg"><img class="size-full wp-image-1562" title="Windows 8 Spam" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_1.jpg" alt="Windows 8 Spam" width="449" height="280" /></a></em><p class="wp-caption-text">Windows 8 Spam</p></div>
<p>Even though it&#8217;s only two sentences, they&#8217;ve still managed to introduce a stray question mark in the name.   If that doesn&#8217;t make you suspicious, a quick check of the link destination should</p>
<div id="attachment_1564" class="wp-caption alignnone" style="width: 459px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_2.jpg"><img class="size-full wp-image-1564" title="Revealing the details of the spam link" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_2.jpg" alt="Revealing the details of the spam link" width="449" height="280" /></a><p class="wp-caption-text">Revealing the details of the spam link</p></div>
<p>The double extension of .gif.exe is used to make the file appear to be a .gif file on Windows systems that are not configured to display program extensions.</p>
<p>Even if the type of file is partly obscured by the filename there shouldn&#8217;t be any confusion once you click on the link.  Windows asks you if you are sure you want to run <em><span style="text-decoration: underline;">this software</span></em>.</p>
<div id="attachment_1567" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_4.jpg" target="_blank"><img class="size-full wp-image-1567 " title="Are you sure you want to do this?" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_4.jpg" alt="Are you sure you want to do this?" width="450" height="374" /></a><p class="wp-caption-text">Are you sure you want to do this?</p></div>
<p>Of course, you don&#8217;t typically run a program in order to &#8220;get more details&#8221; about some topic.   At this point what you want to do is to press &#8220;Don&#8217;t Run&#8221; and back away.</p>
<p>But let&#8217;s suppose your defenses were down and your overwhelming curiosity about Windows 8 had you pushing that &#8220;Run&#8221; button.  Here&#8217;s what happens</p>
<div id="attachment_1570" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_6.jpg" target="_blank"><img class="size-full wp-image-1570 " title="Running 8final.gif.exe" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_6.jpg" alt="Running 8final.gif.exe" width="450" height="338" /></a><p class="wp-caption-text">Running 8final.gif.exe</p></div>
<p>The program opens up a spiffy Windows graphic.   That&#8217;s it.  Those are your details.</p>
<p>&nbsp;</p>
<p>Except not quite.  The program is a variant of Trojan.Zapchast.   After it opens the graphic it gets to work installing an Internet Relay Chat client &#8211; mIRC, along with special scripts that turn the client into a backdoor.</p>
<p>This Zapchast isn&#8217;t all that sneaky though.  If you look at the screen shot above you&#8217;ll see a blank spot in the notification bar, just to the left of the speaker icon.   Hovering over it ever reveals an &#8220;mIRC Daemon Tools&#8221; tooltip.    You can actually open it and watch the bot-herder at work.</p>
<div id="attachment_1573" class="wp-caption alignnone" style="width: 460px"><a href="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_8.jpg" target="_blank"><img class="size-full wp-image-1573 " title="A glimpse of the backdoor in action" src="http://www.barracudalabs.com/wordpress/wp-content/uploads/2011/06/win8_8.jpg" alt="A glimpse of the backdoor in action" width="450" height="321" /></a><p class="wp-caption-text">A glimpse of the backdoor in action</p></div>
<p>This IRC controlled backdoor is set to start whenever the computer is started.   It monitors the channel (in this case, #drones) for messages that it interprets as commands and then carries them out.   Once infected, the host computer can be directed to download and run other malware,  search for personal information, send spam &#8211; in short, your computer belongs to the bot-herder.</p>
<p>&nbsp;</p>
<p><a href="http://www.barracudanetworks.com/">Barracuda Networks</a> customers using the <a title="Spam &amp; Virus Firewall" href="http://www.barracudanetworks.com/ns/products/spam_overview.php" target="_blank">Barracuda Spam &amp; Virus Firewall</a> are protected from these emails, while customers using <a title="Web Filter" href="http://www.barracudanetworks.com/ns/products/web-filter-overview.php" target="_blank">Barracuda Web Filters</a> or <a title="Cloud-based Web Security" href="http://www.barracudanetworks.com/ns/products/web_security_flex_overview.php" target="_blank">Barracuda Web Security <em>Flex</em></a> are protected from the payload.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.barracudalabs.com%2Fwordpress%2Findex.php%2F2011%2F06%2F10%2Fspammers-dangle-windows-8-as-bait%2F&amp;title=Spammers%20dangle%20Windows%208%20as%20bait" id="wpa2a_20"><img src="http://www.barracudalabs.com/wordpress/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.barracudalabs.com/wordpress/index.php/2011/06/10/spammers-dangle-windows-8-as-bait/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

