<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>NoVirusThanks Blog</title>
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Thu, 16 Feb 2012 14:17:15 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.2.1" -->

	<item>
		<title>Phishing: Skype Incident Updating Your Information To the new security</title>
		<description><![CDATA[New phishing email used to steal Skype login details: The A HREF link: Please click here to verify your identity Redirects users to the malicious URL: hxxp://login.skype.com.kad-s .com/]]></description>
		<link>http://blog.novirusthanks.org/2012/02/phishing-skype-incident-updating-your-information-to-the-new-security/</link>
			</item>
	<item>
		<title>Find out who visits your Facebook profile: it is a fake, the link redirects to malicious websites</title>
		<description><![CDATA[We have noted recently various messages posted by Facebook users that promote few methods to find out who visits your Facebook profile. At the end of the message there is a link to a Bit.ly shortened URL, as you can see from this image: The shortened URL redirects the users to a malicious URL: HTTP/1.1 [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/02/find-out-who-visits-your-facebook-profile-it-is-a-fake-the-link-redirects-to-malicious-websites/</link>
			</item>
	<item>
		<title>Malware: Cotacao solicitada (relatorio.scr)</title>
		<description><![CDATA[We have received a suspicious email: Received: from unknown (HELO userb) (***@globaltires.es@177.0.120.119) Subject: Cotacao solicitada. MIME-Version: 1.0 Date: Sat, 11 Feb 2012 17:56:37 -0300 Email message is in HTML and the page source looks like: As you can see, from this code: &#60;A href=&#34;hxxp://groupnetvect .co.de&#34;&#62;relatorio1379-pdf.&#60;/A&#62; (63kb)&#60;BR&#62; The A HREF link redirects the user to an [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/02/malware-cotacao-solicitada/</link>
			</item>
	<item>
		<title>New Malicious Iframe Code, Trojan.Java.Downloader and VBScript</title>
		<description><![CDATA[Honeypots have reported another case of malicious iframe code that is generally added after the end of the HTML tag, at the end of the website page, as you can see from the image below: We have also noted another website that redirects users to a fake porn video streaming website with the main objective [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/02/new-malicious-iframe-code-trojan-java-downloader-and-vbscript/</link>
			</item>
	<item>
		<title>JavaScript Code Hidden in Image</title>
		<description><![CDATA[We noted few websites infected with the following code (Gumblar-style?): Extracted malicious URL: hxxp://vohfakai .co.cc/1584179.jpg URLVoid report: http://www.urlvoid.com/scan/vohfakai.co.cc Unfortunately (fortunately) the malicious URL is not online, but I am sure it was used to spread malicious javascript code or iframe code, that would have redirected the users to an exploit kit.]]></description>
		<link>http://blog.novirusthanks.org/2012/02/javascript-code-hidden-in-image/</link>
			</item>
	<item>
		<title>Iframe Alias(dot)jjbworks(dot)com Mass Infection</title>
		<description><![CDATA[Another hidden and malicious iframe is spreading by infecting websites: The iframe code is added before the BODY tag of the HTML page and is obfuscated: The extracted malicious link is: hxxp://alias .jjbworks .com/analytics.php Details about the malicious domain: Website: alias .jjbworks .com Domain Hash: 2f8f518cb5d452fca78b8c11b3a53913 IP Address: 68.68.20.114 [SCAN] IP Hostname: 68.68.20.114.customer.bluemilenetworks.com IP Country: [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/01/iframe-aliasdotjjbworksdotcom-mass-infection/</link>
			</item>
	<item>
		<title>Iframe Bigdeal777(dot)com Mass Infection</title>
		<description><![CDATA[Internal honeypots have reported a lot of websites infected with a hidden and malicious iframe code that is added at the end of the HTML tag or before the BODY tag of the page, the malicious iframe looks like this: Download the iframe code (pass is novirusthanks.org): iframe.zip / 1 KB Here is a small [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/01/iframe-bigdeal777dotcom-mass-infection/</link>
			</item>
	<item>
		<title>Preventsweating.com infected by Incognito Exploit Kit</title>
		<description><![CDATA[Our honeypot has logged an infected website: hxxp://www.preventsweating .com The malicious javascript code is at the end of the page: Download dumped content (pass is novirusthanks.org): exploit.zip / 1 KB We have analyzed the infected website with our sandbox and we can see from the network traffic that the obfuscated javascript code redirects users to [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/01/preventsweating-com-infected-by-incognito-exploit-kit/</link>
			</item>
	<item>
		<title>Phishing: Update your PayPal account Information</title>
		<description><![CDATA[We have detected new phishing emails with subject &#8220;Update your PayPal account Information&#8221; that contain fake PayPal link that redirects to a phishing page used to steal PayPal account details of users that type their credentials. Email header: Subject: Update your PayPal account Information Date: Mon, 16 Jan 2012 00:43:26 +0100 Received: from WIN-QJ6LOAE77N1 (unknown [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/01/phishing-update-your-paypal-account-information/</link>
			</item>
	<item>
		<title>Block malicious PDF files with Socket Sentinel Pro</title>
		<description><![CDATA[We will use Socket Sentinel Pro to block the download of malicious PDF files that contain javascript code. With this method we can block web exploit kits that spread PDF files containing malicious javascript code, example: Blackhole Exploit Kit. NoVirusThanks Socket Sentinel Pro is an advanced, yet user-friendly, bi-directional TCP traffic filtering software application which [...]]]></description>
		<link>http://blog.novirusthanks.org/2012/01/block-malicious-pdf-files-with-socket-sentinel-pro/</link>
			</item>
</channel>
</rss>

