<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.com/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.com/enblog/read.php?260</link>
<title><![CDATA[IM-Worm.Win32.Zeroll.a]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 24 Aug 2010 01:27:03 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?260</guid> 
<description>
<![CDATA[ 
	Kaspersky <a href="http://www.securelist.com/en/blog/2262/New_IM_Worm_Squirming_in_Latin_America" target="_blank"><u>reported</u></a> a new IM-Worm &quot;<strong>IM-Worm.Win32.Zeroll.a</strong>&quot; was spreading in Latin America.<br/><br/>According to Kaspersky&#039;s description:<br/><div class="quote"><div class="quote-title">Quotation</div><div class="quote-content">On Aug 21, we (Kaspersky Lab) detected a new instant messenger worm that spreads through almost all well-known IM programs, including Skype, GTalk, Yahoo Messenger and Live MSN Messenger. The name of the threat is “IM-Worm.Win32.Zeroll.a”<br/><br/>It “speaks” 13 different languages (including Spanish and Portuguese) according to the local language of the infected Windows computer.&nbsp;&nbsp;There are some characteristics that show the worm originated Mexico. It is written in VB and the C&amp;C is located on an IRC channel (an old botnet technique recycled by the Mexican coders). </div></div><br/><br/>So all the IM users should be careful of this worm.<br/><br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=im-worm.win32.zeroll.a" rel="tag">im-worm.win32.zeroll.a</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?255</link>
<title><![CDATA[First iPhone Worm Ikee]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 09 Nov 2009 00:43:26 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?255</guid> 
<description>
<![CDATA[ 
	There are lots of reports about first iPhone worm &quot;<strong>Ikee</strong>&quot; today.<br/><br/>F-Secure: <a href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank"><u>First iPhone worm found</u></a><br/><br/>Sophos: <a href="http://www.sophos.com/pressoffice/news/articles/2009/11/iphone-worm.html" target="_blank"><u>First iPhone worm spreading in the wild</u></a><br/><br/>ISC: <a href="http://isc.sans.org/diary.html?storyid=7549" target="_blank"><u>iPhone worm in the wild</u></a><br/><br/><br/><br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=ikee" rel="tag">ikee</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=iphone" rel="tag">iphone</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?248</link>
<title><![CDATA[Renren.com XSS Worm]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 25 Aug 2009 01:44:19 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?248</guid> 
<description>
<![CDATA[ 
	I noticed <a href="http://www.sophos.com/blogs/sophoslabs/v/post/6208" target="_blank"><u>Sophos</u></a> and <a href="http://isc.sans.org/diary.html?storyid=7015" target="_blank"><u>ISC</u></a> reported a Chinese social web site - <strong>renren.com</strong>(aka xiaonei.com), was attacked by a flash XSS worm.<br/><br/>If you can read Chinese, you may read more details written by <strong>KnownSec Team</strong> <a href="http://www.scanw.com/blog/archives/1133" target="_blank"><u>here</u></a>.<br/><br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=renren" rel="tag">renren</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=xiaonei" rel="tag">xiaonei</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=xss" rel="tag">xss</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?242</link>
<title><![CDATA[Really No Storm Codec on Your PC?]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Wed, 09 Apr 2008 12:13:44 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?242</guid> 
<description>
<![CDATA[ 
	Zhelatin gang has updated its tactic again today. We&#039;ve received its new spams. In the latest spams, a malicious domain &quot;<strong>sup&lt;removed&gt;eas.com</strong>&quot; was contained. Besides spams, we also found this malicious domain was posted on lots of blogs.<br/><br/>Two files, &quot;<strong>StormCodec.exe</strong>&quot; and &quot;<strong>StormCodec8.exe</strong>&quot;, will be downloaded. Kaspersky detects them as Email-Worm.Win32.Zhelatin.wt.<br/><br/>Here is the screenshot of this malicious site: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=stormcodec.exe" rel="tag">stormcodec.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=stormcodec8.exe" rel="tag">stormcodec8.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=zhelatin.wt" rel="tag">zhelatin.wt</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?239</link>
<title><![CDATA[Storm Worm, Blogspot.com]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 07 Apr 2008 11:41:22 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?239</guid> 
<description>
<![CDATA[ 
	Storm Worm changed its tactic again. It began using Blog tactic now.<br/><br/>We received its latest spams which contained the links that point to <strong>Blogspot.com</strong>.<br/><br/>Here is the sample of spams body:<br/><br/><a href="http://www.cisrt.com/enblog/attachment/200804/zhelatin_ww-080407a.png" target="_blank"><img src="http://www.cisrt.com/enblog/attachment/200804/zhelatin_ww-080407a.png" class="insertimage" alt="Open in new window" title="Open in new window" border="0"/></a><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=withlove.exe" rel="tag">withlove.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=love.exe" rel="tag">love.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=zhelatin.ww" rel="tag">zhelatin.ww</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?238</link>
<title><![CDATA[April Fools Day, Storm Worm Comes Back ]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 01 Apr 2008 11:00:43 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?238</guid> 
<description>
<![CDATA[ 
	Today is the April Fool&#039;s Day. More friends like joking on this day. The Storm Worm gang also like this day, and they come back after being inactive for a long time.<br/><br/>The new spams began being spread earlier today. We&#039;ve received lots of spams in our mailbox. The subject lines are as the following:<br/><div class="code">April Fools&#039; Day <br/>Happy All Fools! <br/>Doh! April&#039;s Fool. <br/>I am a Fool for your Love<br/>Gotcha! All Fool!<br/>Happy April Fool&#039;s Day. </div><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=funny.exe" rel="tag">funny.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=kickme.exe" rel="tag">kickme.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=foolsday.exe" rel="tag">foolsday.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=foolday" rel="tag">foolday</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.win32.zhelatin.wt" rel="tag">email-worm.win32.zhelatin.wt</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?237</link>
<title><![CDATA[Storm Worm Began Reactive]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 03 Mar 2008 12:19:03 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?237</guid> 
<description>
<![CDATA[ 
	The last time Storm Worm active was <a href="http://www.cisrt.org/enblog/read.php?232" target="_blank"><u>Valentine Day</u></a>.<br/><br/>Today, we monitored the Storm Worm gang began reactive. The file &quot;<strong>postcard.exe</strong>&quot; or &quot;<strong>e-card.exe</strong>&quot; will be downloaded automatically in a few seconds after users visit these websites.<br/><br/>The spams are like the following: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=postcard.exe" rel="tag">postcard.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=e-card.exe" rel="tag">e-card.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=zhelatin.vg" rel="tag">zhelatin.vg</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?232</link>
<title><![CDATA[Valentine.exe, Zhelatin New Filename]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 12 Feb 2008 09:44:40 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?232</guid> 
<description>
<![CDATA[ 
	Zhelatin gang began acitve again with new pictures and titles of its malicious websites. <br/><br/>When the users visit these websites, the file &quot;<strong>valentine.exe</strong>&quot; will be downloaded automatically after five seconds.<br/><br/>The following are the pictures on these malicious websites: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=valentine.exe" rel="tag">valentine.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?225</link>
<title><![CDATA[Beselo, New Symbian Worm in the Wild]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 22 Jan 2008 12:41:10 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?225</guid> 
<description>
<![CDATA[ 
	F-Secure has <a href="http://www.f-secure.com/weblog/archives/00001368.html" target="_blank"><u>reported</u></a> a new symbian worm -- <strong>SymbOS/Beselo</strong> in the wild.<br/><br/>It affects S60 2nd Edition phones.<br/><br/>F-Secure said:<br/><div class="quote"><div class="quote-title">Quotation</div><div class="quote-content">The <strong>SymbOS/Beselo</strong> family of worms is very similar to <strong>Commwarrior</strong>. In fact at first we actually misidentified Beselo.A as Commwarrior.Y. Like Commwarrior, Beselo worms spread via MMS and Bluetooth using social engineering to trick users into installing an incoming SIS application installation file. </div></div><br/><br/>We also found the similar cases in China via Search Engine: Google and Baidu. The users received one of the following files via MMS: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=symbos%252Fbeselo" rel="tag">symbos/beselo</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=beauty.jpg" rel="tag">beauty.jpg</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=love.rm" rel="tag">love.rm</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=sex.mp3" rel="tag">sex.mp3</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=symbian" rel="tag">symbian</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=symbos%252Fbeselo.b" rel="tag">symbos/beselo.b</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?222</link>
<title><![CDATA[Storm Worm with Love Theme]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Wed, 16 Jan 2008 07:49:53 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?222</guid> 
<description>
<![CDATA[ 
	New variant of Storm Worm began active now. The latest theme is about <strong>Love</strong>. The filenames are &quot;<strong>withlove.exe</strong>&quot; and &quot;<strong>with_love.exe</strong>&quot; this time, and the files on these websites are changing every 15-30 minutes, so keep being careful please.<br/><br/>The subjectlines may be as the following:<br/><div class="code">A Dream is a Wish<br/>A Kiss So Gentle<br/>For You....My Love<br/>Love Is...<br/>Memories of You<br/>Our Love Will Last </div><br/><br/>The screenshot of spams: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=withlove.exe" rel="tag">withlove.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=with_love.exe" rel="tag">with love.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a>
]]>
</description>
</item>
</channel>
</rss>