<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.org/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.org/enblog/read.php?260</link>
<title><![CDATA[IM-Worm.Win32.Zeroll.a]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Tue, 24 Aug 2010 01:27:03 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?260</guid> 
<description>
<![CDATA[ 
	Kaspersky <a href="http://www.securelist.com/en/blog/2262/New_IM_Worm_Squirming_in_Latin_America" target="_blank"><u>reported</u></a> a new IM-Worm &quot;<strong>IM-Worm.Win32.Zeroll.a</strong>&quot; was spreading in Latin America.<br/><br/>According to Kaspersky&#039;s description:<br/><div class="quote"><div class="quote-title">Quotation</div><div class="quote-content">On Aug 21, we (Kaspersky Lab) detected a new instant messenger worm that spreads through almost all well-known IM programs, including Skype, GTalk, Yahoo Messenger and Live MSN Messenger. The name of the threat is “IM-Worm.Win32.Zeroll.a”<br/><br/>It “speaks” 13 different languages (including Spanish and Portuguese) according to the local language of the infected Windows computer.&nbsp;&nbsp;There are some characteristics that show the worm originated Mexico. It is written in VB and the C&amp;C is located on an IRC channel (an old botnet technique recycled by the Mexican coders). </div></div><br/><br/>So all the IM users should be careful of this worm.<br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=im-worm.win32.zeroll.a" rel="tag">im-worm.win32.zeroll.a</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?259</link>
<title><![CDATA[Fake iTunes Gift Certificate]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Fri, 07 May 2010 08:32:29 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?259</guid> 
<description>
<![CDATA[ 
	We recevied spams about fake <strong>iTunes Gift Certificate</strong>. Be careful of these spams.<br/><br/><strong>Subject</strong>:Thank you for buying iTunes Gift Certificate!<br/><br/><strong>Body</strong>:<br/>Hello! <br/>You have received an iTunes Gift Certificate in the amount of $50.00 You can find your certificate code in attachment below. <br/><br/>Then you need to open iTunes. Once you verify your account, $50.00 will be credited to your account, so you can start buying music, games, video right away. <br/><br/>iTunes Store. <br/><br/><strong>Attachment</strong>: iTunes_certificate_447.zip<br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=itunes_certificate_447.zip" rel="tag">itunes certificate 447.zip</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?258</link>
<title><![CDATA[The Death of Mr.Jiangmin Wang]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Others]]></category>
<pubDate>Mon, 05 Apr 2010 08:38:01 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?258</guid> 
<description>
<![CDATA[ 
	I just heard this bad news from <a href="http://global.jiangmin.com/contact.htm" target="_blank">Jiangmin Anti-virus Company</a>.<br/><br/>Mr.Jiangmin Wang, Branch Chairman of Jiangmin, died in Beijing due to illness at 9:20a.m. on April 4, 2010. <br/><br/>The color of <a href="http://www.jiangmin.com" target="_blank"><u>the chinese homepage of Jiangmin</u></a> has turned to be gray.<br/><br/>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?257</link>
<title><![CDATA[Baidu.com DNS hijacking]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Others]]></category>
<pubDate>Tue, 12 Jan 2010 02:47:05 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?257</guid> 
<description>
<![CDATA[ 
	We received lots of reports about <strong>Baidu.com</strong>, the most popular search engine in China, had been unavailable since this moning.<br/><br/>As the time of writing, Baidu.com is also unavailable.<br/><br/>We noticed this case may be caused by DNS hijacking by the “Iranian cyber Army”, <a href="http://www.cisrt.org/enblog/read.php?256" target="_blank">the same guys</a> we mentioned several weeks ago.<br/><br/>A related news: <a href="http://thenextweb.com/asia/2010/01/12/breaking-baidu-hacked-iranian/" target="_blank"><u>Baidu, China’s Largest Search Engine, Hacked by “Iranian Cyber Army”</u></a><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=baidu.com" rel="tag">baidu.com</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=dns" rel="tag">dns</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=hijack" rel="tag">hijack</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?256</link>
<title><![CDATA[ISC: Twitter outage via DNS hijacking]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Others]]></category>
<pubDate>Fri, 18 Dec 2009 08:31:18 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?256</guid> 
<description>
<![CDATA[ 
	I just saw <a href="http://isc.sans.org" target="_blank"><u>Sans.org</u></a> reported that <a href="http://isc.sans.org/diary.html?storyid=7774" target="_blank"><u>Twitter outage via DNS hijacking</u></a>.<br/><br/>A reader posted a image in the comments of this report.<br/><br/><a href="http://i.imgur.com/Q1EgM.jpg" target="_blank">http://i.imgur.com/Q1EgM.jpg</a><br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=twitter" rel="tag">twitter</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=hijack" rel="tag">hijack</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?255</link>
<title><![CDATA[First iPhone Worm Ikee]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Mon, 09 Nov 2009 00:43:26 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?255</guid> 
<description>
<![CDATA[ 
	There are lots of reports about first iPhone worm &quot;<strong>Ikee</strong>&quot; today.<br/><br/>F-Secure: <a href="http://www.f-secure.com/weblog/archives/00001814.html" target="_blank"><u>First iPhone worm found</u></a><br/><br/>Sophos: <a href="http://www.sophos.com/pressoffice/news/articles/2009/11/iphone-worm.html" target="_blank"><u>First iPhone worm spreading in the wild</u></a><br/><br/>ISC: <a href="http://isc.sans.org/diary.html?storyid=7549" target="_blank"><u>iPhone worm in the wild</u></a><br/><br/><br/><br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=ikee" rel="tag">ikee</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=iphone" rel="tag">iphone</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?254</link>
<title><![CDATA[Spams with Hello Darling]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 03 Nov 2009 11:37:52 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?254</guid> 
<description>
<![CDATA[ 
	The spams had been sent with the subject &quot;<strong>Hello Darling</strong>&quot; and attchment &quot;<strong>photo.zip</strong>&quot;.<br/><br/><strong>Subject</strong>: Hello Darling<br/><strong>Mail body</strong>:<br/>Hi, how are you? My photos Which I promised in attached file<br/><br/><strong>Attchment</strong>: photo.zip<br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=hello_darling" rel="tag">hello darling</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=photo.zip" rel="tag">photo.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=photo.exe" rel="tag">photo.exe</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?253</link>
<title><![CDATA[Get Back to My Office for More Details Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sun, 01 Nov 2009 10:55:09 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?253</guid> 
<description>
<![CDATA[ 
	I saw lots of spams which contained subject &quot;<strong>get back to my office for more details</strong>&quot; and attchment &quot;<strong>info.zip</strong>&quot; in recent two days. Be careful of them.<br/><br/><strong>From</strong>: boss &lt;&quot;boss&quot;&gt; <br/><strong>Subject</strong>: get back to my office for more details<br/><strong>Mail body</strong>:<br/>Please read the attached letter and get back to my office for more details to proceed further. <br/><br/>Thanks and have a very nice day. <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=info.zip" rel="tag">info.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=get_back_to_my_office_for_more_details" rel="tag">get back to my office for more details</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?252</link>
<title><![CDATA[Facebook Password Reset Confirmation Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Tue, 27 Oct 2009 01:10:07 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?252</guid> 
<description>
<![CDATA[ 
	Be careful of the new round of spams about <strong>Facebook Password Reset Confirmation</strong>. <br/><br/><strong>From</strong>: The Facebook Team &lt;service@facebook.com&gt;<br/><strong>Subject</strong>: Facebook Password Reset Confirmation.<br/><strong>Mail body</strong>:<br/>Hey gt , <br/><br/>Because of the measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document. <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=facebook_password_6ff26.zip" rel="tag">facebook password 6ff26.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=facebook_password_c92dd.zip" rel="tag">facebook password c92dd.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=facebook_password_reset_confirmation" rel="tag">facebook password reset confirmation</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?251</link>
<title><![CDATA[Contract of Settlements Spams]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Trojan]]></category>
<pubDate>Sat, 24 Oct 2009 10:53:50 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?251</guid> 
<description>
<![CDATA[ 
	There is a new round of spams, which contained the subject titles as &quot;<strong>Contract of Settlements</strong>&quot; and the attachments as &quot;<strong>contract_1.zip</strong>&quot;.<br/><br/>Be careful.<br/><br/><strong>Subjects</strong>: Contract of Settlements<br/><br/><strong>Mail body</strong>:<br/>Greetings, <br/>We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree all the provisions we are ready to make the payment on Friday for the first consignment, We are enclosing the file with prepared contract. Password: 34**** <br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=contract_1.zip" rel="tag">contract 1.zip</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=contract_of_settlements" rel="tag">contract of settlements</a>
]]>
</description>
</item>
</channel>
</rss>