<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>cnn-malware &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/cnn-malware/</link>
	<description>Feed of posts on WordPress.com tagged "cnn-malware"</description>
	<pubDate>Wed, 22 May 2013 17:00:22 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[CNN Daily Top 10 leads users to site hosting malware]]></title>
<link>http://blog.mxlab.eu/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/</link>
<pubDate>Mon, 04 Aug 2008 21:40:11 +0000</pubDate>
<dc:creator>mxlab</dc:creator>
<guid>http://blog.mxlab.eu/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/</guid>
<description><![CDATA[Following the links in the CNN.com Daily Top 10 email could lead you to sites that hosts malware. MX]]></description>
<content:encoded><![CDATA[<p>Following the links in the CNN.com Daily Top 10 email could lead you to sites that hosts malware. MX Lab detected and intercepted the first messages at around 7:48 PM local Belgian time and is monitoring an outbreak of this type.</p>
<p>Malware authors are abusing CNN by using the logo, the lay out and the concept of the CNN Daily Top 10 to distribute emails with URLs that point to sites that host malware.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20080804_cnn_01.gif" alt="" width="340" height="338" /></p>
<p>The messages itself is sent from a random generated user email address not on the cnn.com domain. The links behind the top 10 directs you to a web site that should show you the video but instead gives you an error that an incorrect Flash player is installed.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20080804_cnn_02.gif" alt="" width="340" height="443" /></p>
<p>A pop up window will ask you to download the correct video codec, an executable called get_flash_update.exe, but this is in fact the Trojan-Downloader.Agent.EL. This trojan ca an download and installs other malware onto infected machine.</p>
<p>This trojan will in fact create a new process on an infected machine: %System%\cbevtsvc.exe and creates a new service CbEvtSvc in the system. Quite some registry modifications are being made as well as a direct IP address connection to a remote host on TCP/IP port 443.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/327b65afddb3fe28aebd1d4896e25031" target="_blank">permalink</a> and MD5: dabb5a9b431c88c77281bcf1158a9879.</p>
<p>Remark: CNN is not responsible for the CNN Daily Top 10 that contained URLs to sites that host malware in the form of a downloadable Flash codec.</p>
]]></content:encoded>
</item>

</channel>
</rss>
