<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>Latest Alerts From Websense Security Labs</title>
    <link>http://websense.com/securitylabs/</link>
    <description>This is the Alert Rss Feed from Websense Security Labs</description>
    <language>en-us</language>

<pubDate>Sat, 13 Mar 2010 GMT</pubDate>

    <generator>RedDot</generator>

<item><title>Malicious Web Site / Malicious Code: Searching for Corey Haim Leads to Rogue AV</title><link>http://securitylabs.websense.com/content/Alerts/3580.aspx</link><description>&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered that search terms related to Corey Haim have become the latest target for Blackhat SEO poisoning attacks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;A href=&quot;http://en.wikipedia.org/wiki/Corey_Haim&quot;&gt;Corey Haim&lt;/A&gt;, 1980s teen idol actor and a star of such famous movies as &quot;The Lost Boys&quot; and &quot;License to Drive&quot;, was found dead in his Los Angeles apartment at the age of only 38 on Wednesday.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;Whether it's a&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href=&quot;http://securitylabs.websense.com/content/Alerts/3568.aspx&quot;&gt;natural disaster&lt;/A&gt;&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;or a death, Blackhats monitor and adapt to popular search trends. Not long after the sad news emerged, the search phrase &quot;Corey Haim&quot; became one of the hottest topics in Google trends.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;Screenshot of the Google trend:&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/Images/Corey_Haim_Death_Leads_to_Rogue_AV_1.jpg&quot;&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;Cybercriminals again jump at a chance to spread their rogue AVs. When users enter keywords such as &quot;Corey Haim death&quot; in Google, some of the results will lead them to download fake security software. The downloading FakeAV file has only&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href=&quot;http://www.virustotal.com/analisis/6c835981a6fd2f866f6200dfd5384240fab14149ddc8c162721305c11533d984-1268277978&quot;&gt;17%&lt;/A&gt;&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;coverage from antivirus products.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;Google searching results of &quot;Corey Haim death&quot; that lead to rogue AVs:&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/Images/Corey_Haim_Death_Leads_to_Rogue_AV_2.jpg&quot;&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium 'Times New Roman'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;Websense Messaging and Websense Web Security customers are protected against this attack.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description><pubDate>Thu, 11 Mar 2010 12:00:00 AM GMT</pubDate><guid>2F07B9BB3E2A4B8181315053C109C6F3</guid></item><item><title>Malicious Web Site / Malicious Code: BBS of Sougou Compromised</title><link>http://securitylabs.websense.com/content/Alerts/3574.aspx</link><description>&lt;P&gt;Websense&#174; Security Labs&#8482; ThreatSeeker&#8482; Network has discovered that the BBS of Sougou has been compromised.&lt;/P&gt;

&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The Sougou BBS home page and other pages on the site have been injected with a malicious script. The script creates an IFrame that redirects users to an exploit site: a 5-day old domain at [snip]ow.info. The latter performs some checks before delivering the exploits, in order to subvert any analysis attempts. &lt;/P&gt;
&lt;P&gt;At the time of writing this alert, the BBS of Sougou is still injected with the malicious script, but the exploit site is down. This could change at any moment. &lt;/P&gt;
&lt;P&gt;This is the injected code in the home page and its contents:&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/BBS_of_Sougou_Compromised_1.png&quot;&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/BBS_of_Sougou_Compromised_2.png&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;Here is the exploit page:&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/BBS_of_Sougou_Compromised_3.png&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;Websense Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description><pubDate>Tue, 2 Mar 2010 12:00:00 AM GMT</pubDate><guid>F385206B1D2D4F92A8B35531CB7B8278</guid></item><item><title>Malicious Web Site / Malicious Code: Blackhat SEO turns to PDF with Chile and Hawaii disasters</title><link>http://securitylabs.websense.com/content/Alerts/3568.aspx</link><description>&lt;P&gt;Over &lt;A href=&quot;http://community.websense.com/blogs/websense-features/archive/2010/02/04/websense-security-labs-report-state-of-internet-security-q3-q4-2009.aspx&quot;&gt;13% of all searches&lt;/A&gt; on Google looking for popular and trending topics will lead to malicious links and searching for the latest news on the earthquake in Chile and the tsunami hitting Hawaii are no exception. Both are now used to lure people into downloading fake antivirus products.&lt;/P&gt;
&lt;P&gt;Usually the links in the search results look like ordinary links pointing to regular web pages. This time the bad guys have changed tactics to make their search results look even more convincing, by tricking Google into thinking it's a PDF file. &lt;/P&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/google_search_pdf.png&quot;&gt; &lt;BR&gt;
&lt;P&gt;As you can see above Google tells you the file format is PDF and not HTML. That's not true, it is infact a regular HTML page that when visited will redirect the user to a page that looks like this - just another rogue AV fake scanning page. This one, just like the majority or rogue AV sites we have seen this week, is in the .IN TLD which is the top-level domain for India. &lt;/P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/hawaii_rogue_av.png&quot;&gt; 
&lt;P&gt;By making the search result look like a PDF it gives the link more authenticity. Perhaps it's a research paper or at least a more well written article. The likelihood that a user will click on these type of links is probably higher than if it were just another random web link. &lt;/P&gt;
&lt;P&gt;This is the first time we've seen the attackers use this approach but considering how aggressive the rogue AV gangs are, it's not a surprise that they continue to refine their techniques to get people to &quot;buy&quot; their products. &lt;/P&gt;
&lt;P&gt;The Rogue AV file itself is currently detected by &lt;A href=&quot;http://www.virustotal.com/analisis/fabca4efdaf5c89d36e153637fbe92bc130f62812d6261833b073a23240260c8-1267321093&quot;&gt;26.20%&lt;/A&gt; of the antivirus engines used by VirusTotal. &lt;/P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack.</description><pubDate>Sun, 28 Feb 2010 12:00:00 AM GMT</pubDate><guid>6E5552216C3944598AC0E6971B2D1E70</guid></item><item><title>Malicious Web Site / Malicious Code: Searching For Joannie Rochette Leads To Rogue AV</title><link>http://securitylabs.websense.com/content/Alerts/3561.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has detected that the black hat Search Engine Optimization (SEO) techniques are abusing the name of an Olympic figure skater who is very popular in recent news.&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://sports.yahoo.com/olympics/vancouver/CAN/Joannie+Rochette/1012611&quot;&gt;Joannie Rochette &lt;/A&gt;is a Canadian figure skater and the 2009 world silver medallist. In the 2010 Winter Olympics in Vancouver, despite the loss of her mother just 48 hours before her competition, she delivered a sensational &lt;A href=&quot;http://www.nbcolympics.com/video/assetid=df674667-721b-4991-9d12-0066cefb8696.html&quot;&gt;performance&lt;/A&gt; and qualified to compete for gold. &lt;BR&gt;&lt;BR&gt;The bad guys still took advantage of this tragic incident and used it in the infamous Black SEO poisoning attacks. Searching for Joannie Rochette in reputable search engines leads to rogue AV.&lt;/P&gt;
&lt;P&gt;This use of the Black SEO technique is even more pertinent now that the results have been announced, with Rochette receiving a &lt;A href=&quot;http://sports.espn.go.com/olympics/winter/2010/figureskating/columns/story?columnist=ford_bonnie_d&amp;id=4947971&quot;&gt;bronze medal&lt;/A&gt; for her performance. &lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_joannie_rochette_1.png&quot;&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_joannie_rochette_2.png&quot;&gt;&lt;/P&gt;
&lt;P&gt;Once the victim clicks on the poisoned search results, he/she is redirected to the rogue AV page, and a &lt;A href=&quot;http://www.virustotal.com/analisis/fad707f2f6c7b49a287516907b0bdace0a881e9ed3cc723935b36bccd1d673f9-1267157888&quot;&gt;fake Anti-virus&lt;/A&gt; executable asks for the victim's confirmation before being downloaded. &lt;BR&gt;&lt;BR&gt;Related topics are 4th and 7th on Google's Hot Trends USA list. Joannie Rochette is currently the most popular search term on Google Canada at the time of writing:&lt;/P&gt;

&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_joannie_rochette_3.png&quot;&gt;&lt;/P&gt;

&lt;P&gt;This isn't the first time Black SEO attacks &lt;A href=&quot;http://isc.sans.org/diary.html?storyid=8239&quot;&gt;target&lt;/A&gt; events and figures related to the olympics this year. &lt;BR&gt;&lt;BR&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;</description><pubDate>Fri, 26 Feb 2010 12:00:00 AM GMT</pubDate><guid>2F04C8E6063F41CBABF0D9F5DDE47001</guid></item><item><title>Malicious Web Site / Malicious Code: Bloom Box Black SEO</title><link>http://securitylabs.websense.com/content/Alerts/3554.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has detected that search terms related to the Bloom Energy and its Bloombox Fuel Cell have become the latest target for Blackhat SEO poisoning attacks. &lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.breakingglobalnews.com/bloom-energys-bloombox-fuel-cell/1222998&quot;&gt;Bloom Box&lt;/A&gt; is a breakthrough technology in the energy sector that could revolutionize the way electricity is generated today. As people become interested in finding more information on this technology, related search terms are currently gaining momentum, and as they do so Blackhat SEO attacks are starting to climb up the search result listings. &lt;/P&gt;
&lt;P&gt;At the moment, according to the &lt;A href=&quot;http://www.virustotal.com/analisis/d49fa46aee47bd5b69e9f0d716e1fa662eff7090a22e8fc0db03d5c12b859f9c-1266851237&quot;&gt;VirusTotal report&lt;/A&gt; only 10% of antivirus products are detecting the threat. &lt;/P&gt;
&lt;P&gt;Video of the Bloom Box SEO in action: &lt;/P&gt;
&lt;OBJECT width=560 height=340&gt;&lt;PARAM NAME=&quot;movie&quot; VALUE=&quot;http://www.youtube.com/v/RNe74da4ADs&amp;amp;hl=en_GB&amp;amp;fs=1&amp;amp;&quot;&gt;&lt;PARAM NAME=&quot;allowFullScreen&quot; VALUE=&quot;true&quot;&gt;&lt;PARAM NAME=&quot;allowscriptaccess&quot; VALUE=&quot;always&quot;&gt;
&lt;embed src=&quot;http://www.youtube.com/v/RNe74da4ADs&amp;hl=en_GB&amp;fs=1&amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;560&quot; height=&quot;340&quot;&gt;&lt;/embed&gt;&lt;/OBJECT&gt;
&lt;P&gt;&lt;BR&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;</description><pubDate>Mon, 22 Feb 2010 12:00:00 AM GMT</pubDate><guid>61AC76DAE048479297B82EBF6C5716CF</guid></item><item><title>Malicious Web Site / Malicious Code: Microsoft's Ninemsn Australia Web Site Compromised</title><link>http://securitylabs.websense.com/content/Alerts/3552.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has detected that the ninemsn support Web site (ninemsn.com.au) has been compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections, and the injected code is hidden deep within the ninemsn ad engine, served on request. The injected code leads to a site that has also been compromised by Gumblar. The compromised code is hidden specifically within the &quot;Women's Weekly&quot; banner script. Other ad banners are not affected.&lt;/P&gt;
&lt;P&gt;Screenshot of the Web site:&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Ninemsn_Australia_Web_Site_Compromised_1.png&quot;&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Screenshot of the ad element:&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Ninemsn_Australia_Web_Site_Compromised_2.png&quot;&gt;&lt;/P&gt;
&lt;P&gt;At this time, the malicious code isn't available or reachable, but this could change at any time. An interesting implication is that this ad can be dynamically served on multiple Web pages within ninemsn. This is unlike a typical injection where Web sites are compromised in a single static page; in this case, the infected banner ad can be pulled to various locations within the site, serving its malicious purpose silently.&lt;/P&gt;
&lt;P&gt;Ninemsn, a joint venture between PBL Media and Microsoft, is one of the most visited portal Web sites (Alexa traffic rank 573) delivering online and mobile content, news, information, entertainment, and social networking capabilities.&lt;/P&gt;
&lt;P&gt;We contacted Microsoft when we discovered the attack and the ad banner has now been removed from the ninemsn support Web site.&lt;/P&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;</description><pubDate>Tue, 16 Feb 2010 12:00:00 AM GMT</pubDate><guid>BFD0B486D0B94414BA1FAE3915EC13A8</guid></item><item><title>Malicious Web Site / Malicious Code: Spammers already using Google Buzz</title><link>http://securitylabs.websense.com/content/Alerts/3551.aspx</link><description>&lt;P&gt;With all the &lt;A href=&quot;http://gmailblog.blogspot.com/2010/02/google-buzz-in-gmail.html&quot;&gt;buzz&lt;/A&gt; this week about Google Buzz, we were just waiting for malicious activity to show up on the newly launched service. We didn't quite expect it to happen this fast. Today we saw the first spam using Google Buzz to spread a message about smoking: &lt;BR&gt;&lt;BR&gt;&lt;A title=&quot;buzz by securitylabs, on Flickr&quot; href=&quot;http://www.flickr.com/photos/47434642@N02/4349170543/&quot;&gt;&lt;IMG alt=buzz src=&quot;http://farm5.static.flickr.com/4061/4349170543_f972fa3cc3.jpg&quot; width=500 height=322&gt;&lt;/A&gt;&amp;nbsp; &lt;BR&gt;&lt;BR&gt;The spammer is already following 237 people, and we can only imagine that he or she has sent similar messages to all of them. This particular message leads to a site hosted on a free Web hosting service talking about how to quit smoking. &lt;BR&gt;&lt;BR&gt;When Twitter was launched, it took a while before it was used to send spam and other malicious messages. In this case, it only took two days. It's clear that the bad guys have learned from their experience using social networks to distribute these type of messages. &lt;BR&gt;&lt;BR&gt;We hope that Google is geared up for dealing with the volume of spam it's bound to see on the new service. Until then, we advise users to be careful, as usual, when clicking on unknown links. &lt;/P&gt;</description><pubDate>Thu, 11 Feb 2010 12:00:00 AM GMT</pubDate><guid>0709192FEAB542EDA9DC1770A517AFBB</guid></item><item><title>Malicious Web Site / Malicious Code: Zeus targeted attacks continue</title><link>http://securitylabs.websense.com/content/Alerts/3550.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered a follow up attack on &lt;A href=&quot;http://securitylabs.websense.com/content/Alerts/3546.aspx&quot;&gt;Zeus campaign targeting government departments&lt;/A&gt;. Its research shows that once again the campaign is targeting workers from government and military departments globally. &lt;/P&gt;
&lt;P&gt;Figure 1 - Zeus Campaign: &lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_targeted_attacks_continue_1.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;The Websense ThreatSeeker Network has seen thousands of emails pretending to be from a reputable figure within the Central Intelligence Agency (see Figure 2). The email subject is: &quot;Russian spear phishing attack against .mil and .gov employees&quot;&lt;/P&gt;
&lt;P&gt;Figure 2 - Content of the email: &lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_targeted_attacks_continue_2.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;Jeffery Carr, the spoofed victim himself, has published a comment regarding this attack: &lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_targeted_attacks_continue_3.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;The spoofed emails capitalize on the last Zeus attack, and claim that installing the Windows update via the links provided will aid protection against Zeus attacks. The binary file downloaded from these links is identified as a Zeus bot and holds &lt;A href=&quot;http://www.virustotal.com/analisis/696196fcc2d7803a0ebc4bdca53f03c9e1e55b15669658f9218d246d49e8c476-1265856371&quot;&gt;35% AV detection rate&lt;/A&gt;. Once again URLs in the email messages lead to a malicious file hosted on a compromised host, and also on a popular file hosting service. Once installed, the bot has identical functionality to the one mentioned in the previous alert. After The Zeus Rootkit component is installed the C&amp;C server at update[removed].com is contacted to download an encrypted configuration file. Another data stealing component gets downloaded and installed from the same C&amp;C in the shape of a Win32 Perl script compiled with &lt;A href=&quot;http://www.indigostar.com/perl2exe.php&quot;&gt;Perl2Exe&lt;/A&gt; - this data-stealing component has only a &lt;A href=&quot;http://www.virustotal.com/analisis/1336bca82ba370c8cf0967ed192cb1865e4f943fbb4ea4e2f6c2c9b98eb43723-1265905508&quot;&gt;5% AV detection rate&lt;/A&gt;. Then the bot starts to connect with a credential-based FTP server at pack[removed].com to upload stolen data. The Zeus bot is normally designed to steal banking credentials; however it has also been seen in targeted attacks to steal other sensitive data. &lt;/P&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack.&lt;/P&gt;</description><pubDate>Thu, 11 Feb 2010 12:00:00 AM GMT</pubDate><guid>62FDA40F66CA4ADDA5554CD3E35ED5DE</guid></item><item><title>Malicious Web Site / Malicious Code: Bollywood Hungama Web Site Compromised</title><link>http://securitylabs.websense.com/content/Alerts/3548.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has detected that the Web site of Bollywood Hungama (Bollywoodhungama.com) has been compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections, and there are multiple injections at the site's path level. While the main page was injected, the malicious code has been removed. A number of pages at the path level, however, still remain injected. The injected code leads to a site that has also been compromised by Gumblar. At this time, the malicious code isn't available or reachable, but this could change at any time. &lt;/P&gt;
&lt;P&gt;Bollywood Hungama is a leading entertainment Web site (Alexa rank 1,592). The site provides news related to the Indian film industry, emphasizing Bollywood, film reviews, and box office reports. &lt;/P&gt;
&lt;P&gt;Screenshot of the Web site: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Alert_bollywoodhungama_1.JPG&quot;&gt;&lt;/P&gt;
&lt;P&gt;Screenshot of injected code in one of the pages: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Alert_bollywoodhungama_2.JPG&quot;&gt;&lt;/P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. 
&lt;P&gt;&lt;/P&gt;</description><pubDate>Mon, 8 Feb 2010 12:00:00 AM GMT</pubDate><guid>5984D9954F974ED7A9E77BF859FD4486</guid></item><item><title>Malicious Web Site / Malicious Code: Zeus Campaign Targeted Government Departments</title><link>http://securitylabs.websense.com/content/Alerts/3546.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered a new Zeus campaign (a banking data stealing Trojan) which is now targeting government departments. Our research shows that the campaign has especially targeted workers from government and military departments in the UK and US: we found most victims' email addresses end with .gov.&lt;/P&gt;&lt;BR&gt;&lt;BR&gt;Figure 1 - Zeus Campaign:&amp;nbsp;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_Campaign_Targeted_Goverment_Department_1.png&quot;&gt;&amp;nbsp;&lt;BR&gt;
&lt;P&gt;Our ThreatSeeker&#8482; Network has seen thousands of emails which pretend to be from the National Intelligence Council (see Figure 2). The email subjects include: &quot;National Intelligence Council&quot;&lt;BR&gt;&quot;RE: National Intelligence Council&quot;&lt;BR&gt;&quot;Report of the National Intelligence Council&quot; &lt;/P&gt;Figure 2 - Content of the email:&amp;nbsp;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_Campaign_Targeted_Goverment_Department_2.png&quot;&gt;&amp;nbsp;&lt;BR&gt;
&lt;P&gt;The spoofed emails lure victims to download a document about the &quot;2020 project&quot;; this is actually a Zeus bot. The Web sites which host the bot look very trustworthy: one of them is a compromised organization Web site and the other is located on a popular file hosting service. The bot has rootkit capabilities and connects to C&amp;amp;C servers at update[removed].com and pack[removed].com to report back on a successful infection and to download some archives with DLLs, it also modifies the hosts file to prevent updates from popular anti-virus vendors.&lt;/P&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack, however the anti-virus detection rate for this bot is currently at &lt;A href=&quot;http://www.virustotal.com/analisis/82d10922cc1365a79b43a16502211ae610f56b01cd36a18db67d8a0c81c434c4-1265615954&quot;&gt;26/40&lt;/A&gt;. &lt;/P&gt;</description><pubDate>Mon, 8 Feb 2010 12:00:00 AM GMT</pubDate><guid>6EE2BA9B159646C6A965B8E196A5C7C1</guid></item>

</channel>
</rss>