<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.com/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.com/enblog/read.php?259</link>
<title><![CDATA[Fake iTunes Gift Certificate]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Fri, 07 May 2010 08:32:29 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?259</guid> 
<description>
<![CDATA[ 
	We recevied spams about fake <strong>iTunes Gift Certificate</strong>. Be careful of these spams.<br/><br/><strong>Subject</strong>:Thank you for buying iTunes Gift Certificate!<br/><br/><strong>Body</strong>:<br/>Hello! <br/>You have received an iTunes Gift Certificate in the amount of $50.00 You can find your certificate code in attachment below. <br/><br/>Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video right away. <br/><br/>iTunes Store. <br/><br/><strong>Attachment</strong>: iTunes_certificate_447.zip<br/><br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=itunes_certificate_447.zip" rel="tag">itunes certificate 447.zip</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?254</link>
<title><![CDATA[Spams with Hello Darling]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 03 Nov 2009 11:37:52 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?254</guid> 
<description>
<![CDATA[ 
	The spams had been sent with the subject &quot;<strong>Hello Darling</strong>&quot; and attchment &quot;<strong>photo.zip</strong>&quot;.<br/><br/><strong>Subject</strong>: Hello Darling<br/><strong>Mail body</strong>:<br/>Hi, how are you? My photos Which I promised in attached file<br/><br/><strong>Attchment</strong>: photo.zip<br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=hello_darling" rel="tag">hello darling</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=photo.zip" rel="tag">photo.zip</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=photo.exe" rel="tag">photo.exe</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?253</link>
<title><![CDATA[Get Back to My Office for More Details Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sun, 01 Nov 2009 10:55:09 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?253</guid> 
<description>
<![CDATA[ 
	I saw lots of spams which contained subject &quot;<strong>get back to my office for more details</strong>&quot; and attchment &quot;<strong>info.zip</strong>&quot; in recent two days. Be careful of them.<br/><br/><strong>From</strong>: boss &lt;&quot;boss&quot;&gt; <br/><strong>Subject</strong>: get back to my office for more details<br/><strong>Mail body</strong>:<br/>Please read the attached letter and get back to my office for more details to proceed further. <br/><br/>Thanks and have a very nice day. <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=info.zip" rel="tag">info.zip</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=get_back_to_my_office_for_more_details" rel="tag">get back to my office for more details</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?252</link>
<title><![CDATA[Facebook Password Reset Confirmation Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 27 Oct 2009 01:10:07 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?252</guid> 
<description>
<![CDATA[ 
	Be careful of the new round of spams about <strong>Facebook Password Reset Confirmation</strong>. <br/><br/><strong>From</strong>: The Facebook Team &lt;service@facebook.com&gt;<br/><strong>Subject</strong>: Facebook Password Reset Confirmation.<br/><strong>Mail body</strong>:<br/>Hey gt , <br/><br/>Because of the measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document. <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=facebook_password_6ff26.zip" rel="tag">facebook password 6ff26.zip</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=facebook_password_c92dd.zip" rel="tag">facebook password c92dd.zip</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=facebook_password_reset_confirmation" rel="tag">facebook password reset confirmation</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?251</link>
<title><![CDATA[Contract of Settlements Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sat, 24 Oct 2009 10:53:50 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?251</guid> 
<description>
<![CDATA[ 
	There is a new round of spams, which contained the subject titles as &quot;<strong>Contract of Settlements</strong>&quot; and the attachments as &quot;<strong>contract_1.zip</strong>&quot;.<br/><br/>Be careful.<br/><br/><strong>Subjects</strong>: Contract of Settlements<br/><br/><strong>Mail body</strong>:<br/>Greetings, <br/>We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree all the provisions we are ready to make the payment on Friday for the first consignment, We are enclosing the file with prepared contract. Password: 34**** <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=contract_1.zip" rel="tag">contract 1.zip</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=contract_of_settlements" rel="tag">contract of settlements</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?250</link>
<title><![CDATA[Conflicker.B Infection Alert Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 20 Oct 2009 02:30:55 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?250</guid> 
<description>
<![CDATA[ 
	Be careful of spams about Conflicker.B Infection Alert.<br/><br/>They are the same gang as i mentioned <a href="http://www.cisrt.org/enblog/read.php?249" target="_blank"><u>before</u></a>.<br/><br/><strong>Subject</strong>:Conflicker.B Infection Alert<br/><strong>Mail body</strong>:<br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=conflicker.b" rel="tag">conflicker.b</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=install.zip" rel="tag">install.zip</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?249</link>
<title><![CDATA[More Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Thu, 15 Oct 2009 07:44:19 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?249</guid> 
<description>
<![CDATA[ 
	Numerous spams had been sent these days. The name of attchments are like &quot;DHL_package_label_1f553.zip&quot; , &quot;DHL_print_label_433a6.zip&quot; , &quot;DHL_Label_a4f79.zip&quot; , &quot;DHL_Package_ac42d.zip&quot; , &quot;install.zip&quot;, etc. <br/><br/>Be careful of these spams.<br/><br/>I listed some spams&#039; content:<br/><div class="quote"><div class="quote-title">Quotation</div><div class="quote-content"><strong>Subject</strong>: DHL service. You should get the parcel! Delivery NR.6445<br/><strong>Mail body</strong>:<br/>Hello! <br/><br/>The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. <br/><br/>You may pickup the parcel at our post office personaly! <br/><br/>Please note! <br/>The shipping label is attached to this e-mail. Please print this label to get this package at our post office. <br/><br/>Thank you for attention. <br/>DHL Delivery Services. </div></div><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=dhl_label" rel="tag">dhl label</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=dhl_package" rel="tag">dhl package</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=dhl_print_label" rel="tag">dhl print label</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=dhl_package_label" rel="tag">dhl package label</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=install.zip" rel="tag">install.zip</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=trojan.win32.inject" rel="tag">trojan.win32.inject</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?235</link>
<title><![CDATA[Fake Hizer Mills Video]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sat, 16 Feb 2008 11:20:05 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?235</guid> 
<description>
<![CDATA[ 
	In recent two days, we found similar spams to <a href="http://www.cisrt.org/enblog/read.php?234" target="_blank"><u>the Hillary Clinton video spams</u></a>. The following malicious URLs are inaccessable now:<br/><div class="code">http://bibber.bi.funpic.de/test/bild&lt;removed&gt;/images/gallery/susy/rdown.php?ugeih<br/>http://www.neufeld-media.de/Neufeld-Media/Re&lt;removed&gt;/news/rdown.php?lEtEmwn<br/>http://bibo1981.bi.funpic.de/b&lt;removed&gt;/movie/rdown.php?ojfbG</div><br/><br/>We received another spam about <strong>Hizer Mills video</strong> today. The subject lines are such as &quot;<strong>Sensation.Video New - make haste to look!!!</strong>&quot;.<br/><br/>The screenshot of spams: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=pousadarecantonatureza.com.br" rel="tag">pousadarecantonatureza.com.br</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=news_m.exe" rel="tag">news m.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=vshost.exe" rel="tag">vshost.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=loca.exe" rel="tag">loca.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=trojan.win32.agent.exq" rel="tag">trojan.win32.agent.exq</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=trojan.win32.agent.epo" rel="tag">trojan.win32.agent.epo</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?234</link>
<title><![CDATA[Hillary Clinton Full Video?]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Wed, 13 Feb 2008 06:57:11 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?234</guid> 
<description>
<![CDATA[ 
	<strong>The United States 2008 presidential election</strong> is underway. Hillary Clinton and Barack Obama already eyeing another Super Tuesday - March 4,2008.<br/><br/>As while, the bad guys also eyeing the United States 2008 presidential election. We received a new trojan spam about it today. The subject lines of these spams are such as &quot;<strong>Hillary Clinton Full Video !!!</strong>&quot;. <br/><br/>The screenshot of spams body: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=mpg.exe" rel="tag">mpg.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=inst526.exe" rel="tag">inst526.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=hillary_clinton" rel="tag">hillary clinton</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=barack_obama" rel="tag">barack obama</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=trojan.win32.agent.epo" rel="tag">trojan.win32.agent.epo</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=canotajetrilly.com" rel="tag">canotajetrilly.com</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/enblog/read.php?231</link>
<title><![CDATA[Fake Video of Britney Spears]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Fri, 08 Feb 2008 08:09:02 +0000</pubDate> 
<guid>http://www.cisrt.com/enblog/read.php?231</guid> 
<description>
<![CDATA[ 
	Bad guys seem liking Paris Hilton and Britney Spears. They always use Paris Hilton and Britney Spears as bait.<br/><br/>Today we received another spam spreading as fake video of Britney Spears.<br/><br/>The subjects are such as: <strong>Crazy Britney does it again!</strong><br/><br/>The screenshot of spam body: <br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/enblog/tag.php?tag=play.exe" rel="tag">play.exe</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=7sa2" rel="tag">7sa2</a> , <a href="http://www.cisrt.com/enblog/tag.php?tag=hahne.id.au" rel="tag">hahne.id.au</a>
]]>
</description>
</item>
</channel>
</rss>