<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.org/enblog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>en-US</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.org/enblog/read.php?</link>
<title><![CDATA[New worm use the .ani zero day vulnerability]]></title> 
<author>smallmo &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[Worm]]></category>
<pubDate>Sat, 31 Mar 2007 10:45:57 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?</guid> 
<description>
<![CDATA[ 
	It&#039;s a bad news that the <strong>Windows Animated Cursor Handling</strong> zero-day vulnerability has been used by malwares in China now. We have received this kind of new worm today. It has the same behavior as Worm.Win32.Fujacks. It also can infects .HTML .ASPX .HTM .PHP .JSP .ASP and .EXE files, and inserts the malicious links which contained <strong>Windows Animated Cursor Handling</strong> zero-day vulnerability into .HTML .ASPX .HTM .PHP .JSP .ASP files. It also can send out Chinese spams which are include the same zero-day vulnerability link. <br/><br/>And the author is updating the variants now. We have received different sizes and MD5 hashes. The worm can be downloaded from the following domains, we suggest all users should block now.<br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/enblog/tag.php?tag=trojan-downloader.win32.agent.bky" rel="tag">trojan-downloader.win32.agent.bky</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=w32.fubalca" rel="tag">w32.fubalca</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=macr.microfsot.com" rel="tag">macr.microfsot.com</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=a.2007ip.com" rel="tag">a.2007ip.com</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=vulnerability" rel="tag">vulnerability</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=.ani" rel="tag">.ani</a> , <a href="http://www.cisrt.org/enblog/tag.php?tag=microsoft" rel="tag">microsoft</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/enblog/read.php?#blogcomment</link>
<title><![CDATA[[Comments] New worm use the .ani zero day vulnerability]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[Comments]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.cisrt.org/enblog/read.php?#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>