<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.org/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.org/enblog/read.php?242</link>
<title><![CDATA[Really No Storm Codec on Your PC?]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Wed, 09 Apr 2008 12:13:44 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?242</guid> 
<description>
<![CDATA[ 
	Zhelatin gang has updated its tactic again today. We&#039;ve received its new spams. In the latest spams, a malicious domain &quot;<strong>sup&lt;removed&gt;eas.com</strong>&quot; was contained. Besides spams, we also found this malicious domain was posted on lots of blogs.<br/><br/>Two files, &quot;<strong>StormCodec.exe</strong>&quot; and &quot;<strong>StormCodec8.exe</strong>&quot;, will be downloaded. Kaspersky detects them as Email-Worm.Win32.Zhelatin.wt.<br/><br/>Here is the screenshot of this malicious site: <br/>............<br/><br/>Tags - <a href="tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="tag.php?tag=stormcodec.exe" rel="tag">stormcodec.exe</a> , <a href="tag.php?tag=stormcodec8.exe" rel="tag">stormcodec8.exe</a> , <a href="tag.php?tag=zhelatin.wt" rel="tag">zhelatin.wt</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?241</link>
<title><![CDATA[Adobe Flash Player Bulletin: APSB08-11]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Exploit &amp; Vulnerability]]></category>
<pubDate>Wed, 09 Apr 2008 11:30:44 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?241</guid> 
<description>
<![CDATA[ 
	Adobe released a security bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb08-11.html" target="_blank"><u>APSB08-11</u></a>.<br/><br/>According to Adobe summary:<br/><div class="code">Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. It is recommended users update to the most current version of Flash Player available for their operating system. </div><br/><br/>Affected software versions:<br/><div class="code">Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier</div><br/><br/>............<br/><br/>Tags - <a href="tag.php?tag=adobe" rel="tag">adobe</a> , <a href="tag.php?tag=flash" rel="tag">flash</a> , <a href="tag.php?tag=player" rel="tag">player</a> , <a href="tag.php?tag=vulnerability" rel="tag">vulnerability</a> , <a href="tag.php?tag=9.0.124.0" rel="tag">9.0.124.0</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?240</link>
<title><![CDATA[Microsoft April 2008 Patch Day]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Microsoft Bulletins]]></category>
<pubDate>Wed, 09 Apr 2008 11:15:38 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?240</guid> 
<description>
<![CDATA[ 
	It&#039;s April 2008 Microsoft patch day today.<br/><br/>Microsoft released 8 bulleins for this month. Five of them are <strong>Critical</strong>, three of them are <strong>Important</strong>. Please update at once.<br/><br/><strong>MS08-018</strong>:Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)<br/><br/><strong>MS08-019</strong>:Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032)<br/><br/><strong>MS08-020</strong>:Vulnerability in DNS Client Could Allow Spoofing (945553)<br/><br/>............<br/><br/>Tags - <a href="tag.php?tag=vulnerability" rel="tag">vulnerability</a> , <a href="tag.php?tag=microsoft" rel="tag">microsoft</a> , <a href="tag.php?tag=bulletin" rel="tag">bulletin</a> , <a href="tag.php?tag=patch" rel="tag">patch</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?239</link>
<title><![CDATA[Storm Worm, Blogspot.com]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 07 Apr 2008 11:41:22 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?239</guid> 
<description>
<![CDATA[ 
	Storm Worm changed its tactic again. It began using Blog tactic now.<br/><br/>We received its latest spams which contained the links that point to <strong>Blogspot.com</strong>.<br/><br/>Here is the sample of spams body:<br/><br/><br/><img src="http://www.cisrt.org/enblog/template/living/images/viewimage.gif" alt=""/><a href="http://www.cisrt.org/enblog/attachment/200804/zhelatin_ww-080407a.png" target="_blank">Open in new window</a><br/><a href="http://www.cisrt.org/enblog/attachment/200804/zhelatin_ww-080407a.png" target="_blank">http://www.cisrt.org/enblog/attachment/200804/zh...</a><br/><br/><br/>............<br/><br/>Tags - <a href="tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="tag.php?tag=withlove.exe" rel="tag">withlove.exe</a> , <a href="tag.php?tag=love.exe" rel="tag">love.exe</a> , <a href="tag.php?tag=zhelatin.ww" rel="tag">zhelatin.ww</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?238</link>
<title><![CDATA[April Fools Day, Storm Worm Comes Back ]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 01 Apr 2008 11:00:43 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?238</guid> 
<description>
<![CDATA[ 
	Today is the April Fool&#039;s Day. More friends like joking on this day. The Storm Worm gang also like this day, and they come back after being inactive for a long time.<br/><br/>The new spams began being spread earlier today. We&#039;ve received lots of spams in our mailbox. The subject lines are as the following:<br/><div class="code">April Fools&#039; Day <br/>Happy All Fools! <br/>Doh! April&#039;s Fool. <br/>I am a Fool for your Love<br/>Gotcha! All Fool!<br/>Happy April Fool&#039;s Day. </div><br/><br/>............<br/><br/>Tags - <a href="tag.php?tag=funny.exe" rel="tag">funny.exe</a> , <a href="tag.php?tag=kickme.exe" rel="tag">kickme.exe</a> , <a href="tag.php?tag=foolsday.exe" rel="tag">foolsday.exe</a> , <a href="tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="tag.php?tag=foolday" rel="tag">foolday</a> , <a href="tag.php?tag=email-worm.win32.zhelatin.wt" rel="tag">email-worm.win32.zhelatin.wt</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?237</link>
<title><![CDATA[Storm Worm Began Reactive]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 03 Mar 2008 12:19:03 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?237</guid> 
<description>
<![CDATA[ 
	The last time Storm Worm active was <a href="http://www.cisrt.org/enblog/read.php?232" target="_blank"><u>Valentine Day</u></a>.<br/><br/>Today, we monitored the Storm Worm gang began reactive. The file &quot;<strong>postcard.exe</strong>&quot; or &quot;<strong>e-card.exe</strong>&quot; will be downloaded automatically in a few seconds after users visit these websites.<br/><br/>The spams are like the following: <br/>............<br/><br/>Tags - <a href="tag.php?tag=email-worm.zhelatin" rel="tag">email-worm.zhelatin</a> , <a href="tag.php?tag=postcard.exe" rel="tag">postcard.exe</a> , <a href="tag.php?tag=e-card.exe" rel="tag">e-card.exe</a> , <a href="tag.php?tag=zhelatin.vg" rel="tag">zhelatin.vg</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?236</link>
<title><![CDATA[Rising Antivirus Online Scanner Insecure Method Flaw Exploit]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Exploit &amp; Vulnerability]]></category>
<pubDate>Wed, 27 Feb 2008 04:31:27 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?236</guid> 
<description>
<![CDATA[ 
	A exploit about Rising Antivirus Online Scanner Insecure Method Flaw was published on milw0rm.com.<br/><br/><div class="code">- Rising is a popular anti-virus product around China.<br/>- there&#039;s an insecure method flaw inside its free online scanner.<br/>- it&#039;s quite easy to exploit the bug which leads to a remote execution.<br/>- clsid:E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153</div><br/><br/>Rising company released a <a href="http://it.rising.com.cn/Channels/Info/Rav_news/Rav_news/2008-02-26/1204034846d45513.shtml" target="_blank"><u>bulletin</u></a> last night to fix the vulnerability in Chinese. The users of &nbsp;Rising Antivirus Online Scanner should visit the Rising Antivirus Online Scanner <a href="http://online.rising.com.cn/free/rav.htm" target="_blank"><u>webpage</u></a> to install the latest ActiveX control.<br/><br/><br/>Tags - <a href="tag.php?tag=rising_antivirus_online_scanner" rel="tag">rising antivirus online scanner</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?235</link>
<title><![CDATA[Fake Hizer Mills Video]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sat, 16 Feb 2008 11:20:05 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?235</guid> 
<description>
<![CDATA[ 
	In recent two days, we found similar spams to <a href="http://www.cisrt.org/enblog/read.php?234" target="_blank"><u>the Hillary Clinton video spams</u></a>. The following malicious URLs are inaccessable now:<br/><div class="code">http://bibber.bi.funpic.de/test/bild&lt;removed&gt;/images/gallery/susy/rdown.php?ugeih<br/>http://www.neufeld-media.de/Neufeld-Media/Re&lt;removed&gt;/news/rdown.php?lEtEmwn<br/>http://bibo1981.bi.funpic.de/b&lt;removed&gt;/movie/rdown.php?ojfbG</div><br/><br/>We received another spam about <strong>Hizer Mills video</strong> today. The subject lines are such as &quot;<strong>Sensation.Video New - make haste to look!!!</strong>&quot;.<br/><br/>The screenshot of spams: <br/>............<br/><br/>Tags - <a href="tag.php?tag=pousadarecantonatureza.com.br" rel="tag">pousadarecantonatureza.com.br</a> , <a href="tag.php?tag=news_m.exe" rel="tag">news m.exe</a> , <a href="tag.php?tag=vshost.exe" rel="tag">vshost.exe</a> , <a href="tag.php?tag=loca.exe" rel="tag">loca.exe</a> , <a href="tag.php?tag=trojan.win32.agent.exq" rel="tag">trojan.win32.agent.exq</a> , <a href="tag.php?tag=trojan.win32.agent.epo" rel="tag">trojan.win32.agent.epo</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?234</link>
<title><![CDATA[Hillary Clinton Full Video?]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Wed, 13 Feb 2008 06:57:11 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?234</guid> 
<description>
<![CDATA[ 
	<strong>The United States 2008 presidential election</strong> is underway. Hillary Clinton and Barack Obama already eyeing another Super Tuesday - March 4,2008.<br/><br/>As while, the bad guys also eyeing the United States 2008 presidential election. We received a new trojan spam about it today. The subject lines of these spams are such as &quot;<strong>Hillary Clinton Full Video !!!</strong>&quot;. <br/><br/>The screenshot of spams body: <br/>............<br/><br/>Tags - <a href="tag.php?tag=mpg.exe" rel="tag">mpg.exe</a> , <a href="tag.php?tag=inst526.exe" rel="tag">inst526.exe</a> , <a href="tag.php?tag=hillary_clinton" rel="tag">hillary clinton</a> , <a href="tag.php?tag=barack_obama" rel="tag">barack obama</a> , <a href="tag.php?tag=trojan.win32.agent.epo" rel="tag">trojan.win32.agent.epo</a> , <a href="tag.php?tag=canotajetrilly.com" rel="tag">canotajetrilly.com</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?233</link>
<title><![CDATA[Microsoft February 2008 Bulletin]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Microsoft Bulletins]]></category>
<pubDate>Wed, 13 Feb 2008 05:52:33 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?233</guid> 
<description>
<![CDATA[ 
	Today Microsoft released its biggest batch of monthly patches, releasing 11 security updates to patch 17 vulnerabilities, six of which are <strong>Critical</strong>, five of which are <strong>Important</strong>.<br/><br/>The critical bulletins are include the following:<br/><div class="code">MS08-007: Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution(946026)<br/><br/>MS08-008: Vulnerability in OLE Automation Could Allow Remote Code Execution(947890)<br/><br/>MS08-009: Vulnerability in Microsoft Word Could Allow Remote Code Execution(947077)<br/><br/>MS08-010: Cumulative Security Update for Internet Explorer(944533)<br/><br/>MS08-012: Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution (947085)<br/><br/>MS08-013: Vulnerability in Microsoft Office Could Allow Remote Code Execution (947108)</div><br/>............<br/><br/>Tags - <a href="tag.php?tag=vulnerability" rel="tag">vulnerability</a> , <a href="tag.php?tag=microsoft" rel="tag">microsoft</a> , <a href="tag.php?tag=bulletin" rel="tag">bulletin</a> , <a href="tag.php?tag=patch" rel="tag">patch</a>
]]>
</description>
</item>
</channel>
</rss>