<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>Latest Alerts From Websense Security Labs</title>
    <link>http://websense.com/securitylabs/</link>
    <description>This is the Alert Rss Feed from Websense Security Labs</description>
    <language>en-us</language>

<pubDate>Mon, 8 Feb 2010 GMT</pubDate>

    <generator>RedDot</generator>

<item><title>Malicious Web Site / Malicious Code: Bollywood Hungama Web Site Compromised</title><link>http://securitylabs.websense.com/content/Alerts/3548.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has detected that the the Web site of Bollywood Hungama (Bollywoodhungama.com) has been compromised and injected with malicious code. The malicious code was identified to be part of the Gumblar mass injections, and there are multiple injections at the site's path level. While the main page was injected, the malicious code has been removed. A number of pages at the path level, however, still remain injected. The injected code leads to a site that has also been compromised by Gumblar. At this time, the malicious code isn't available or reachable, but this could change at any time. &lt;/P&gt;
&lt;P&gt;Bollywood Hungama is a leading entertainment Web site (Alexa rank 1,592). The site provides news related to the Indian film industry, emphasizing Bollywood, film reviews, and box office reports. &lt;/P&gt;
&lt;P&gt;Screenshot of the Web site: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Alert_bollywoodhungama_1.JPG&quot;&gt;&lt;/P&gt;
&lt;P&gt;Screenshot of injected code in one of the pages: &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Alert_bollywoodhungama_2.JPG&quot;&gt;&lt;/P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. 
&lt;P&gt;&lt;/P&gt;</description><pubDate>Mon, 8 Feb 2010 12:00:00 AM GMT</pubDate><guid>5984D9954F974ED7A9E77BF859FD4486</guid></item><item><title>Malicious Web Site / Malicious Code: Zeus Campaign Targeted Government Departments</title><link>http://securitylabs.websense.com/content/Alerts/3546.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered a new Zeus campaign (a banking data stealing Trojan) which is now targeting government departments. Our research shows that the campaign has especially targeted workers from government and military departments in the UK and US: we found most victims' email addresses end with .gov.&lt;/P&gt;&lt;BR&gt;&lt;BR&gt;Figure 1 - Zeus Campaign:&amp;nbsp;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_Campaign_Targeted_Goverment_Department_1.png&quot;&gt;&amp;nbsp;&lt;BR&gt;
&lt;P&gt;Our ThreatSeeker&#8482; Network has seen thousands of emails which pretend to be from the National Intelligence Council (see Figure 2). The email subjects include: &quot;National Intelligence Council&quot;&lt;BR&gt;&quot;RE: National Intelligence Council&quot;&lt;BR&gt;&quot;Report of the National Intelligence Council&quot; &lt;/P&gt;Figure 2 - Content of the email:&amp;nbsp;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Zeus_Campaign_Targeted_Goverment_Department_2.png&quot;&gt;&amp;nbsp;&lt;BR&gt;
&lt;P&gt;The spoofed emails lure victims to download a document about the &quot;2020 project&quot;; this is actually a Zeus bot. The Web sites which host the bot look very trustworthy: one of them is a compromised organization Web site and the other is located on a popular file hosting service. The bot has rootkit capabilities and connects to C&amp;amp;C servers at update*snip*.com and pack*snip*.com to report back on a successful infection and to download some archives with DLLs, it also modifies the hosts file to prevent updates from popular anti-virus vendors.&lt;/P&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack, however the anti-virus detection rate for this bot is currently at &lt;A href=&quot;http://www.virustotal.com/analisis/82d10922cc1365a79b43a16502211ae610f56b01cd36a18db67d8a0c81c434c4-1265615954&quot;&gt;26/40&lt;/A&gt;. &lt;/P&gt;</description><pubDate>Mon, 8 Feb 2010 12:00:00 AM GMT</pubDate><guid>6EE2BA9B159646C6A965B8E196A5C7C1</guid></item><item><title>Malicious Web Site / Malicious Code: Malicious Google Job Application Response</title><link>http://securitylabs.websense.com/content/Alerts/3543.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered a new malicious spam campaign that spoofs Google job application responses. The messages look very well written and are so believable that they are probably scrapes from actual Google job application responses. Typically, spam has grammatical errors or spelling mistakes that make the messages obviously unofficial and act as red flags. The text of these messages, however, has no such mistakes, making them much more believable--especially if the target really has applied for a job with Google. &lt;BR&gt;&lt;BR&gt;The &lt;B&gt;From:&lt;/B&gt; address is even spoofed to fool victims into believing the message was sent by Google. The messages have an attached file called CV-20100120-112.zip that contains a malicious payload. This is where the message gets suspicious, because the contents of the .zip file have a double extension ending with .exe. The attackers attempt to hide the .exe extension by preceding it with .html or .pdf, followed by a number of spaces and then the .exe extension. The .exe file (SHA1:80366cde71b84606ce8ecf62b5bd2e459c54942e) has &lt;A href=&quot;http://www.virustotal.com/analisis/d5fd8e098054a5f1b570de5d31241c1428a79fb25ec6a477261f6efaaf3d7440-1265043648&quot;&gt;little AV&lt;/A&gt; coverage at the moment.&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/MalGoogMessage.png&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;Websense Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;</description><pubDate>Mon, 1 Feb 2010 12:00:00 AM GMT</pubDate><guid>AD3010F65E62497ABC3A849914C87820</guid></item><item><title>Malicious Web Site / Malicious Code: Oklahoma Tax Commission Site Compromised</title><link>http://securitylabs.websense.com/content/Alerts/3540.aspx</link><description>&lt;P&gt;
&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered that the home page of the Oklahoma Tax Commission Web site has been compromised with malicious script code. The heavily obfuscated code has been injected at the bottom of the page. &lt;BR&gt;&lt;BR&gt;
&lt;OBJECT width=425 height=344&gt;&lt;PARAM NAME=&quot;movie&quot; VALUE=&quot;http://www.youtube.com/v/2wTxi8bc9mc&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;&quot;&gt;&lt;PARAM NAME=&quot;allowFullScreen&quot; VALUE=&quot;true&quot;&gt;&lt;PARAM NAME=&quot;allowscriptaccess&quot; VALUE=&quot;always&quot;&gt;
&lt;embed src=&quot;http://www.youtube.com/v/2wTxi8bc9mc&amp;hl=en_US&amp;fs=1&amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;425&quot; height=&quot;344&quot;&gt;&lt;/embed&gt;&lt;/OBJECT&gt;&lt;BR&gt;&lt;BR&gt;Here is what site visitors see when they visit the Oklahoma Tax Commission home page:&lt;/P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/OTCHomepage(1).png&quot;&gt; &lt;BR&gt;&lt;BR&gt;After the page is loaded, the browser executes the injected script in the background. 
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below is a screen shot of the injected code:&amp;nbsp;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/OTCInjectedScript.png&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;The injected script code goes through a series of deobfuscation techniques that ultimately take the victim computer to an attack Web site without the victim's consent or knowledge. &lt;/P&gt;
&lt;P&gt;At the time of this posting, the attack Web site is down, but it could come back up at anytime to carry out attacks against visitors to the Oklahoma Tax Commission home page. &lt;BR&gt;&lt;BR&gt;Websense Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description><pubDate>Fri, 29 Jan 2010 12:00:00 AM GMT</pubDate><guid>2190E818DB05489F82DD9F386DC024E7</guid></item><item><title>Malicious Web Site / Malicious Code: Apple Tablet Announcement Black SEO</title><link>http://securitylabs.websense.com/content/Alerts/3538.aspx</link><description>&lt;P&gt;
&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered that search terms related to the forthcoming Apple Tablet announcment have already become the latest target for Blackhat SEO poisoning attacks.&lt;/P&gt;
&lt;P&gt;In the lead up to&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;A href=&quot;http://www.glgroup.com/Council-Events/Teleconference--The-Apple-Tablet-Announcement-(3-00-PM-EST-12-00-PM-PST-20-00-GMT)-7935795.html&quot;&gt;Apple's official announcement&lt;/A&gt;&amp;nbsp;which is scheduled to happen today, there has been a great deal of anticipation and speculation over the Internet. As people become interested in finding more information on the product, related search terms are currently gaining momentum, and as they do so Blackhat SEO attacks are starting to climb up the search result listings.&lt;/P&gt;
&lt;P size=&quot;3&quot;&gt;Below is a screenshot from Google Trends showing how one of the targeted phrases by Black SEO &quot;apple tablet announcement&quot; is starting to gain momentum:&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Apple_Tablet_Alert_1.jpg&quot;&gt;&lt;/P&gt;
&lt;P size=&quot;3&quot;&gt;Black SEO attacks start climbing up in search ranks, clicking on such result leads to a Rogue Antivirus site:&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Apple_Tablet_Alert_2.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Apple_Tablet_Alert_3.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;The file in the rogue AV site has&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;A href=&quot;http://www.virustotal.com/analisis/a2554d34db4ab9b672f20e0609cad88a27b27b12e94dfac413e43f50afeba769-1264543491&quot;&gt;30% detection rate&lt;/A&gt;. If the file is installed it reports non-existent infections and disturbs the user with on going pop-ups. In order to &quot;clean&quot; the system the rogue program is offered for a price:&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Apple_Tablet_Alert_4.jpg&quot;&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Apple_Tablet_Alert_5.jpg&quot;&gt;&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;</description><pubDate>Wed, 27 Jan 2010 12:00:00 AM GMT</pubDate><guid>B7B7AB51228B48EA842957B2B264AA07</guid></item><item><title>Malicious Web Site / Malicious Code: Targeted Email Examples Relating to Microsoft Internet Explorer 0-day CVE-2010-0249 </title><link>http://securitylabs.websense.com/content/Alerts/3536.aspx</link><description>&lt;P&gt;
&lt;P&gt;Websense&#174; Security Labs&#8482; has reports that emails linking to malicious web-based exploit code that utilizes the vulnerability CVE-2010-0249 have been sent to organizations in a targeted manner since December 2009, and the attack is still on-going. This same vulnerability was used to target Google, Adobe, and approximately 30 other companies in mid-December 2009. This is a development of the attack we have blogged about previously &lt;A href=&quot;http://securitylabs.websense.com/content/Blogs/3534.aspx&quot;&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Investigation has so far lead to the conclusion that these targeted attacks appear to have started during the week of 20 December 2009, and are on-going to government, defence, energy sectors and other organizations in the United States and United Kingdom. &lt;/P&gt;
&lt;P&gt;Within the malicious emails the sender's domain is spoofed to match the recipient's domain making the targeted emails more convincing to the recipient. The malicious executables that are delivered by the exploit code include hxxp://cnn[removed]/US/20100119/update.exe or hxxp://usnews[removed]/svchost.exe. These exhibit traits of an information-stealing Trojan with Backdoor capabilities. As of today only 25% of AV vendors protect against the payload according to this &lt;A href=&quot;http://www.virustotal.com/analisis/ee6d60ade4f20dd305ab27100623718d0ea8409be524d45e7b375269857fd797-1264090078&quot;&gt;VT report.&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Example email subjects include:&lt;BR&gt;&quot;Helping You Serve Your Customers&quot;&lt;BR&gt;&quot;Obama Slips in Polls as Crises Dominate First Year as President&quot;&lt;BR&gt;&quot;2010&amp;nbsp;***** Commercial SATCOM&quot;&lt;BR&gt;&quot;The Twelve Days of Christmas&quot;&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;Microsoft has released a patch to address the vulnerability on Thursday 21 January at 10am PST. See &lt;A href=&quot;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&quot;&gt;MS10-002 summary&lt;/A&gt; for details. &lt;/P&gt;
&lt;P&gt;Screenshots of targeted emails: &lt;/P&gt;&lt;BR&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_IE0day_email_1.png&quot;&gt;&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_IE0day_email_2.png&quot;&gt;&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_IE0day_email_3.png&quot;&gt;&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/alert_IE0day_email_4.png&quot;&gt;&lt;BR&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description><pubDate>Thu, 21 Jan 2010 12:00:00 AM GMT</pubDate><guid>197530D7034E4878A328475D838A053C</guid></item><item><title>Malicious Web Site / Malicious Code: Black Hat SEO Causing Malicious Search Results For Recent Haiti Earthquake </title><link>http://securitylabs.websense.com/content/Alerts/3524.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered that searches on terms related to the recent earthquake in Haiti return results leading to a rogue antivirus program. The earthquake, which happened on Tuesday near Port-au-Prince, had a magnitude of 7.0 and is said to be the most powerful earthquake to hit Haiti. &lt;BR&gt;&lt;BR&gt;
&lt;OBJECT width=425 height=344&gt;&lt;PARAM NAME=&quot;movie&quot; VALUE=&quot;http://www.youtube.com/v/r0oDnQ0P0fI&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;&quot;&gt;&lt;PARAM NAME=&quot;allowFullScreen&quot; VALUE=&quot;true&quot;&gt;&lt;PARAM NAME=&quot;allowscriptaccess&quot; VALUE=&quot;always&quot;&gt;
&lt;embed src=&quot;http://www.youtube.com/v/r0oDnQ0P0fI&amp;hl=en_US&amp;fs=1&amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;425&quot; height=&quot;344&quot;&gt;&lt;/embed&gt;&lt;/OBJECT&gt;&lt;BR&gt;&lt;BR&gt;People around the world are searching the Internet to find the latest updates on this issue, wanting to know how to make charitable donations, trying to discover the extent of the calamity through photos or videos, and looking to see what their favorite artists and musicians are saying about the disaster. Unfortunately, the bad guys use major crises and events like this to spread their malicious code. &lt;BR&gt;&lt;BR&gt;Maliciously engineered search results:&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/haiti_earthquake_search_results.PNG&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;Screen shot showing the rogue antivirus software:&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/haiti_rogue_av.PNG&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;Malware sample 1: &lt;BR&gt;&lt;A href=&quot;http://www.virustotal.com/analisis/0bde0d236db303f9531105bc4a3164d857f50f972886210724adf02719f27d35-1263413669&quot;&gt;20%&lt;/A&gt; AV coverage &lt;BR&gt;SHA1 : e89ff91b9a279ac5e9e86c455f2150f2a0ffcf8f &lt;BR&gt;&lt;BR&gt;Malware sample 2: &lt;BR&gt;&lt;A href=&quot;http://www.virustotal.com/analisis/a1c0b23dcfa9bc10f2cdb55c1358c5bd7c01c903a2aa9829f205b73137d30e89-1263413836&quot;&gt;8% &lt;/A&gt;AV coverage &lt;BR&gt;SHA-1: 4e58a12a9f722be0712517a0475fda60a8e94fdc &lt;BR&gt;&lt;BR&gt;Malware sample 3: &lt;BR&gt;&lt;A href=&quot;http://www.virustotal.com/analisis/b291101a733cb656f39c3b85a887e2f5b9730a8564c09d3d80b49560c23f0458-1263404507&quot;&gt;20%&lt;/A&gt; AV coverage&lt;BR&gt;SHA1 : ee6e18f8cfe65862e7fa0537ae4b95cb0fcb7ada &lt;BR&gt;&lt;BR&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;</description><pubDate>Wed, 13 Jan 2010 12:00:00 AM GMT</pubDate><guid>DCABA210D1B9407AA6A4054414110176</guid></item><item><title>Malicious Web Site / Malicious Code: Ice Skating Car Video Black Hat SEO </title><link>http://securitylabs.websense.com/content/Alerts/3522.aspx</link><description>&lt;P&gt;
&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered that a popular video called &quot;Paignton Ice Skating for Cars&quot; has been targeted by both SEO poisoning attacks as well as Web spam. &lt;BR&gt;&lt;BR&gt;As a &lt;A href=&quot;http://www1.voanews.com/english/news/europe/Severe-Winter-Weather-Grips-Europe-81091747.html&quot;&gt;wave of icy weather is currently hitting large parts of Europe&lt;/A&gt;, the video has proved to be very popular, with currently more than 850,000 hits on &lt;A href=&quot;http://uk.video.yahoo.com/watch/6741223/17522772&quot;&gt;Yahoo Video&lt;/A&gt;. A different &lt;A href=&quot;http://www.youtube.com/watch?v=7MPRmOUxRMY&quot;&gt;uploaded version on YouTube&lt;/A&gt; has had more than 1 million views so far. Criminals have used the video's popularity as an opportunity to spread rogue anti-virus programs by poisoning the search results of major search engines. When the term &quot;ice skating car&quot; is searched via Google, nearly half of the search results on the first page redirect the user to rogue anti-virus sites. Clicking any of those links takes the user to a Web site with the message: &quot;Your PC is at risk of virus and malware attack.&quot; That's an old trick used to lure unsuspecting users to download a fake anti-virus installer. &lt;BR&gt;&lt;BR&gt;Here is the screenshot of the first page of a search for &quot;Ice Skating Car&quot; in Google:&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/ice_skating_car_1.jpg&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;This is the screenshot of the fake anti-virus site:&amp;nbsp;&lt;BR&gt;&lt;BR&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/ice_skating_car_2.jpg&quot;&gt;&amp;nbsp;&lt;BR&gt;&lt;BR&gt;The black hat search results in Google redirect the user through several sites, most of which are hosted in Russia, before finally landing in the rogue anti-virus site. The criminals often change the second site in the redirection chain in order to make it harder to detect. The file has a relatively low &lt;A href=&quot;http://www.virustotal.com/analisis/22a57e63ba0fb00cde7aace01c581583dab6c20b48f241e9ff30d0fea541657b-1263209375&quot;&gt;AV&lt;/A&gt; detection rate. &lt;/P&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description><pubDate>Mon, 11 Jan 2010 12:00:00 AM GMT</pubDate><guid>DDCCE246FEB6409CB9A43E111C0193A3</guid></item><item><title>Malicious Web Site / Malicious Code: Office.Microsoft.Com Search Results Can Lead To Rogue Anti-Virus</title><link>http://securitylabs.websense.com/content/Alerts/3519.aspx</link><description>Websense Security Labs&#8482; ThreatSeeker&#8482; Network has detected that search results on office.microsoft.com can lead users to a Rogue AV page. &lt;BR&gt;&lt;BR&gt;Users looking for information related to help with Office products on Microsoft&#8217;s own site are being targeted. Users may be unaware that, when they type in search queries on the site, Microsoft scours its own Web site for results, but also pulls in results from the broader Web. As the URL for the search results begins with http://office.microsoft.com, this is particularly troubling for users who trust sites simply because of their reputation.&lt;BR&gt;&lt;BR&gt;The malicious URL is a redirect to a very real-looking virus scan and warning page presented by a Rogue AV program (SHA1: 6489c54e30af18801a9e83a5855fa639f3bae0b8). The executable used in the exploit is currently recognized by &lt;A href=&quot;http://www.virustotal.com/analisis/3322d75a2efbc649c726c7258e9ade91dc13f2d35cc1360ac4248e3c62a1ad3d-1262943359&quot; bitly=&quot;BITLY_PROCESSED&quot;&gt;1 of the 41&lt;/A&gt; AV engines on Virus Total.&lt;BR&gt;&lt;BR&gt;
&lt;P&gt;We have contacted Microsoft's Security Response Center with the neccessary information.&lt;/P&gt;
&lt;OBJECT width=425 height=344&gt;&lt;PARAM NAME=&quot;movie&quot; VALUE=&quot;http://www.youtube.com/v/90fulZenuuI&amp;amp;hl=en_GB&amp;amp;fs=1&amp;amp;&quot;&gt;&lt;PARAM NAME=&quot;allowFullScreen&quot; VALUE=&quot;true&quot;&gt;&lt;PARAM NAME=&quot;allowscriptaccess&quot; VALUE=&quot;always&quot;&gt;
&lt;embed src=&quot;http://www.youtube.com/v/90fulZenuuI&amp;hl=en_GB&amp;fs=1&amp;&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;425&quot; height=&quot;344&quot;&gt;&lt;/embed&gt;&lt;/OBJECT&gt;
&lt;P&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description><pubDate>Fri, 8 Jan 2010 12:00:00 AM GMT</pubDate><guid>2AA29F0CC2DD4E49834E11AE1342F7C5</guid></item><item><title>Malicious Web Site / Malicious Code: Binsservicesonline Scam Spreading on Facebook and SEO Poisoning</title><link>http://securitylabs.websense.com/content/Alerts/3518.aspx</link><description>&lt;P&gt;Websense Security Labs&#8482; ThreatSeeker&#8482; Network has discovered several spam messages on Facebook that trick the user into visiting BINSSERVICESONLINE(dot)INFO. When the link in the message is clicked, the Web site redirects the user to an online scam site similar to the one we published in the blog &lt;A href=&quot;http://securitylabs.websense.com/content/Blogs/3512.aspx&quot;&gt;Google Scam Kits&lt;/A&gt; in mid-December. The use of Facebook to distribute links that lead to Google scam kits is fairly new, and is sure to trick some users into buying the kits.&lt;/P&gt;
&lt;P&gt;A lot of users have apparently received this message, as it quickly became a popular search string on Google. As we've seen in the past, there are criminal groups monitoring the popular search terms on Google and other search engines to start their own malicious attacks, so it didn't take long until we started seeing Google search results for BINSSERVICESONLINE leading to rogue AV products.&lt;/P&gt;
&lt;P&gt;Note that the two attacks are done by separate groups of criminals. One group started the spam attacks on Facebook and another started manipulating Google results.&lt;BR&gt;&lt;BR&gt;We can see many messages spreading in Facebook, for example: &lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/BinsservicesonlineScam_Spreading_on_Facebook_and_SEO_Poisoning_1.JPG&quot;&gt;&lt;/P&gt;
&lt;P&gt;BINSSERVICESONLINE.INFO redirects to the following scam site: &lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/Binsservicesonline_Scam_Spreading_on_Facebook_and_SEO_Poisoning_2.JPG&quot;&gt;&lt;BR&gt;&lt;BR&gt;Google search results for BINSSERVICESONLINE: &lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/BinsservicesonlineScam_Spreading_on_Facebook_and_SEO_Poisoning_3.JPG&quot;&gt;&lt;/P&gt;
&lt;P&gt;The Google Trend showing the hot CTR for BINSSERVICESONLINE: &lt;/P&gt;
&lt;P&gt;&lt;IMG src=&quot;http://securitylabs.websense.com/content/Assets/AlertMedia/BinsservicesonlineScam_Spreading_on_Facebook_and_SEO_Poisoning_4.JPG&quot;&gt;&lt;BR&gt;&lt;BR&gt;Websense&#174; Messaging and Websense Web Security customers are protected against this attack. &lt;/P&gt;</description><pubDate>Tue, 5 Jan 2010 12:00:00 AM GMT</pubDate><guid>9C608085B6144F3CA6E37DCAEC968B64</guid></item>

</channel>
</rss>