<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Webroot Threat Blog - Internet Security Threat Updates from Around the World</title>
	
	<link>http://blog.webroot.com</link>
	<description>WEBROOT - INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS</description>
	<lastBuildDate>Wed, 19 Jun 2013 15:47:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain="blog.webroot.com" port="80" path="/?rsscloud=notify" registerProcedure="" protocol="http-post" />
<image>
		<url>http://0.gravatar.com/blavatar/2f6f528880dcd9039e50bf3a1b6b8a40?s=96&amp;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Webroot Threat Blog - Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.webroot.com/osd.xml" title="Webroot Threat Blog - Internet Security Threat Updates from Around the World" />
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/WebrootThreatBlog" /><feedburner:info uri="webrootthreatblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://blog.webroot.com/?pushpress=hub" /><item>
		<title>Rogue ‘Oops Video Player’ attempts to visually social engineer users, mimicks Adobe Flash Player’s installation process</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/GSE3MCENnpQ/</link>
		<comments>http://blog.webroot.com/2013/06/19/rogue-oops-video-player-attempts-to-visually-social-engineer-users-mimicks-adobe-flash-players-installation-process/#comments</comments>
		<pubDate>Wed, 19 Jun 2013 07:00:26 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[adware]]></category>
		<category><![CDATA[Awimba LLC]]></category>
		<category><![CDATA[Bogus Video Player]]></category>
		<category><![CDATA[Domaiq]]></category>
		<category><![CDATA[Fake Ad]]></category>
		<category><![CDATA[Fake Advertisement]]></category>
		<category><![CDATA[Fake Video Player]]></category>
		<category><![CDATA[Monetization]]></category>
		<category><![CDATA[Oops Player]]></category>
		<category><![CDATA[Oops Video Player]]></category>
		<category><![CDATA[Potentially Unwanted Application]]></category>
		<category><![CDATA[PUA]]></category>
		<category><![CDATA[Rogue Ad]]></category>
		<category><![CDATA[Rogue Advertisement]]></category>
		<category><![CDATA[Rogue Video Player]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Visual Social Engineering]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11487</guid>
		<description>By Dancho Danchev Our sensors have just detected yet another rogue advertisement served through the Yieldmanager ad network, this one enticing users into downloading a rogue video player known as the &amp;#8216;Oops Video Player&amp;#8217;. What&amp;#8217;s particularly interesting about this rogue ad campaign is that the PUA (Potentially Unwanted Application) attempts to visually trick users by [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11487&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/GSE3MCENnpQ" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/19/rogue-oops-video-player-attempts-to-visually-social-engineer-users-mimicks-adobe-flash-players-installation-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/oops_video_player_rogue_bogus_fake_adobe_flash_player_01.png" medium="image">
			<media:title type="html">Oops_Video_Player_Rogue_Bogus_Fake_Adobe_Flash_Player_01</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/oops_video_player_rogue_bogus_fake_adobe_flash_player.png" medium="image">
			<media:title type="html">Oops_Video_Player_Rogue_Bogus_Fake_Adobe_Flash_Player</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/oops_video_player_rogue_bogus_fake_adobe_flash_player_02_domaiq.png" medium="image">
			<media:title type="html">Oops_Video_Player_Rogue_Bogus_Fake_Adobe_Flash_Player_02_DomaIQ</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/19/rogue-oops-video-player-attempts-to-visually-social-engineer-users-mimicks-adobe-flash-players-installation-process/</feedburner:origLink></item>
		<item>
		<title>New boutique iFrame crypting service spotted in the wild</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/3Pq4PbppGWI/</link>
		<comments>http://blog.webroot.com/2013/06/18/new-boutique-iframe-crypting-service-spotted-in-the-wild/#comments</comments>
		<pubDate>Tue, 18 Jun 2013 07:00:36 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Boutique]]></category>
		<category><![CDATA[Crypting]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Cybercrime Ecosystem]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[iFrame Crypting]]></category>
		<category><![CDATA[iFrame obfuscation]]></category>
		<category><![CDATA[Managed Cybercrime Service]]></category>
		<category><![CDATA[Managed Underground Service]]></category>
		<category><![CDATA[Obfuscation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Underground Economy]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11468</guid>
		<description>By Dancho Danchev In a series of blog posts shedding more light into the emergence of the boutique cybercrime &amp;#8216;enterprise&amp;#8217;, we&amp;#8217;ve been profiling underground market propositions that continue populating the cybercrime ecosystem on a daily basis, but fail to result in any widespread damage or introduce potential ecosystem disrupting features. Despite these observations, the novice [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11468&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/3Pq4PbppGWI" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/18/new-boutique-iframe-crypting-service-spotted-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/iframe_crypting_as_a_service_cybercrime.png" medium="image">
			<media:title type="html">iFrame_crypting_as_a_service_cybercrime</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/18/new-boutique-iframe-crypting-service-spotted-in-the-wild/</feedburner:origLink></item>
		<item>
		<title>Rogue ads target EU users, expose them to Win32/Toolbar.SearchSuite through the KingTranslate PUA</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/JwHudaXY2uc/</link>
		<comments>http://blog.webroot.com/2013/06/17/rogue-ads-target-eu-users-expose-them-to-win32toolbar-searchsuite-through-the-kingtranslate-pua/#comments</comments>
		<pubDate>Mon, 17 Jun 2013 07:00:43 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Bandoo Media Inc]]></category>
		<category><![CDATA[KingTranslate]]></category>
		<category><![CDATA[Koyote-Lab Inc]]></category>
		<category><![CDATA[Monetization]]></category>
		<category><![CDATA[Potentially Unwanted Application]]></category>
		<category><![CDATA[PUA]]></category>
		<category><![CDATA[Rogue App]]></category>
		<category><![CDATA[Rogue Application]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Searchqu]]></category>
		<category><![CDATA[SearchSuite]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11462</guid>
		<description>By Dancho Danchev Who would need a virtually unknown, but supposedly free, desktop based application in order to translate texts between multiple languages? Tens of thousands of socially engineered European ads, who continue getting exposed to the rogue ads served through Yieldmanager&amp;#8217;s network, are promoting more Potentially Unwanted Applications (PUAs) courtesy of Bandoo Media Inc and their subsidiary [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11462&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/JwHudaXY2uc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/17/rogue-ads-target-eu-users-expose-them-to-win32toolbar-searchsuite-through-the-kingtranslate-pua/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/kingtranslate_pua_01.png" medium="image">
			<media:title type="html">KingTranslate_PUA_01</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/kingtranslate_pua.png" medium="image">
			<media:title type="html">KingTranslate_PUA</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/17/rogue-ads-target-eu-users-expose-them-to-win32toolbar-searchsuite-through-the-kingtranslate-pua/</feedburner:origLink></item>
		<item>
		<title>How cybercriminals apply Quality Assurance (QA) to their malware campaigns before launching them</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/r-WLyVaY0-I/</link>
		<comments>http://blog.webroot.com/2013/06/14/how-cybercriminals-apply-quality-assurance-qa-to-their-malware-campaigns-before-launching-them/#comments</comments>
		<pubDate>Fri, 14 Jun 2013 07:00:48 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Antivirus Scanner]]></category>
		<category><![CDATA[Antivirus Signatures]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malware Scanner]]></category>
		<category><![CDATA[QA]]></category>
		<category><![CDATA[Quality Assurance]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Signatures Based Scanning]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11450</guid>
		<description>By Dancho Danchev In 2013, the use of basic Quality Assurance (QA) practices has become standard practice for cybercrininals when launching a new campaign. In an attempt to increase the probability of a successful outcome for their campaigns &amp;#8212; think malware infection, increased visitor-to-malware infected conversion, improved conversion of blackhat SEO acquired traffic leading to the purchase of counterfeit pharmaceutical items etc. &amp;#8212; [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11450&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/r-WLyVaY0-I" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/14/how-cybercriminals-apply-quality-assurance-qa-to-their-malware-campaigns-before-launching-them/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/cybercrime_malware_malicious_software_multiple_antivirus_scanners_desktop_scanner.png" medium="image">
			<media:title type="html">Cybercrime_Malware_Malicious_Software_Multiple_Antivirus_Scanners_Desktop_Scanner</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/cybercrime_malware_malicious_software_multiple_antivirus_scanners_desktop_scanner_01.png" medium="image">
			<media:title type="html">Cybercrime_Malware_Malicious_Software_Multiple_Antivirus_Scanners_Desktop_Scanner_01</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/14/how-cybercriminals-apply-quality-assurance-qa-to-their-malware-campaigns-before-launching-them/</feedburner:origLink></item>
		<item>
		<title>Rogue ads lead to SafeMonitorApp Potentially Unwanted Application (PUA)</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/5UA4Gb5-SQQ/</link>
		<comments>http://blog.webroot.com/2013/06/13/rogue-ads-lead-to-safemonitorapp-potentially-unwanted-application-pua/#comments</comments>
		<pubDate>Thu, 13 Jun 2013 07:00:42 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Ad]]></category>
		<category><![CDATA[Advertising]]></category>
		<category><![CDATA[Potentially Unwanted Application]]></category>
		<category><![CDATA[PUA]]></category>
		<category><![CDATA[Rogue Ads]]></category>
		<category><![CDATA[SafeMonitorApp]]></category>
		<category><![CDATA[SearchDonkey]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11405</guid>
		<description>By Dancho Danchev Our sensors just picked up yet another rogue ad enticing users into installing the SafeMonitorApp, a potentially unwanted application (PUA) that socially engineers users into giving away their privacy through deceptive advertising of the rogue application&amp;#8217;s &amp;#8220;features&amp;#8221;. More details: Sample screenshot of the landing page, featuring a bogus &amp;#8216;Norton Secured&amp;#8217; Seal: Sample screenshot [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11405&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/5UA4Gb5-SQQ" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/13/rogue-ads-lead-to-safemonitorapp-potentially-unwanted-application-pua/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/safemonitorapp_pua_01.png" medium="image">
			<media:title type="html">SafeMonitorApp_PUA_01</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/safemonitorapp_pua.png" medium="image">
			<media:title type="html">SafeMonitorApp_PUA</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/13/rogue-ads-lead-to-safemonitorapp-potentially-unwanted-application-pua/</feedburner:origLink></item>
		<item>
		<title>Tens of thousands of spamvertised emails lead to W32/Casonline</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/vFAKkiXvY9Q/</link>
		<comments>http://blog.webroot.com/2013/06/12/tens-of-thousands-of-spamvertised-emails-lead-to-w32casonline/#comments</comments>
		<pubDate>Wed, 12 Jun 2013 07:00:25 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Fake Casino]]></category>
		<category><![CDATA[Gambling]]></category>
		<category><![CDATA[Online Gambling]]></category>
		<category><![CDATA[Potentially Unwanted Application]]></category>
		<category><![CDATA[PUA]]></category>
		<category><![CDATA[Rogue Casino]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Spam Campaign]]></category>
		<category><![CDATA[Spamvertised]]></category>
		<category><![CDATA[W32/Casonline]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11390</guid>
		<description>By Dancho Danchev Fraudsters are currently spamvertising tens of thousands of emails enticing users into installing rogue, potentially unwanted (PUAs) casino software. Most commonly known as W32/Casonline, this scam earns revenue through the rogue online gambling software&amp;#8217;s affiliate network. More details: Sample screenshots of the landing URLs: Spamvertised URLs: hxxp://luckynuggetcasino.com &amp;#8211; 67.211.111.163 hxxp://888casino.com &amp;#8211; 213.52.252.59 hxxp://spinpalace.com &amp;#8211; 109.202.114.65 hxxp://alljackpotscasino.com &amp;#8211; [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11390&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/vFAKkiXvY9Q" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/12/tens-of-thousands-of-spamvertised-emails-lead-to-w32casonline/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/email_spam_fake_rogue_pua_casino_casonline.png" medium="image">
			<media:title type="html">Email_Spam_Fake_Rogue_PUA_Casino_Casonline</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/email_spam_fake_rogue_pua_casino_casonline_02.png" medium="image">
			<media:title type="html">Email_Spam_Fake_Rogue_PUA_Casino_Casonline_02</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/email_spam_fake_rogue_pua_casino_casonline_03.png" medium="image">
			<media:title type="html">Email_Spam_Fake_Rogue_PUA_Casino_Casonline_03</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/email_spam_fake_rogue_pua_casino_casonline_04.png" medium="image">
			<media:title type="html">Email_Spam_Fake_Rogue_PUA_Casino_Casonline_04</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/email_spam_fake_rogue_pua_casino_casonline_05.png" medium="image">
			<media:title type="html">Email_Spam_Fake_Rogue_PUA_Casino_Casonline_05</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/email_spam_fake_rogue_pua_casino_casonline_01.png" medium="image">
			<media:title type="html">Email_Spam_Fake_Rogue_PUA_Casino_Casonline_01</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/12/tens-of-thousands-of-spamvertised-emails-lead-to-w32casonline/</feedburner:origLink></item>
		<item>
		<title>How not to install Adobe Flash Player</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/LLGQ8rSamvk/</link>
		<comments>http://blog.webroot.com/2013/06/11/how-not-to-install-adobe-flash-player/#comments</comments>
		<pubDate>Tue, 11 Jun 2013 15:00:09 +0000</pubDate>
		<dc:creator>Richard Melick</dc:creator>
				<category><![CDATA[Stupid malware tricks]]></category>
		<category><![CDATA[Threat Research]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11421</guid>
		<description>By Dan Para It seems simple enough, I want to install Adobe Flash Player so I search for &amp;#8220;flash player download and click on the first result, right? Ignoring the second link which doesn&amp;#8217;t have a five star rating and 37 reviews, I&amp;#8217;m brought to a page called downloadinfo.com. I click the download button, click [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11421&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/LLGQ8rSamvk" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/11/how-not-to-install-adobe-flash-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d70fbec1dd5d72d59e759849dcaa2c90?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">rmelick2013</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/search1.png" medium="image">
			<media:title type="html">search1</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/downloadinfo.png" medium="image">
			<media:title type="html">downloadinfo</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/optimum-downloader.png" medium="image">
			<media:title type="html">optimum downloader</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/realplayer.png" medium="image">
			<media:title type="html">realplayer</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/solid-savings.png" medium="image">
			<media:title type="html">Solid Savings</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/unit-layers.png" medium="image">
			<media:title type="html">Unit Layers</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/optimizer-pro.png" medium="image">
			<media:title type="html">Optimizer Pro</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/installing.png" medium="image">
			<media:title type="html">Installing</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/google-toolbar.png" medium="image">
			<media:title type="html">Google Toolbar</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/vlc-player-what.png" medium="image">
			<media:title type="html">VLC Player - what</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/optional-software-included.png" medium="image">
			<media:title type="html">optional software included</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/11/how-not-to-install-adobe-flash-player/</feedburner:origLink></item>
		<item>
		<title>Fake ‘Unsuccessful Fax Transmission’ themed emails lead to malware</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/JMz8872CM24/</link>
		<comments>http://blog.webroot.com/2013/06/11/fake-unsuccessful-fax-transmission-themed-emails-lead-to-malware/#comments</comments>
		<pubDate>Tue, 11 Jun 2013 11:16:38 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[Botnet activity]]></category>
		<category><![CDATA[mal-effects]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Bogus Email]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[eFax]]></category>
		<category><![CDATA[Fake Email]]></category>
		<category><![CDATA[Malicious Software]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Spam Campaign]]></category>
		<category><![CDATA[Spamvertised]]></category>
		<category><![CDATA[Unsuccessful Fax Transmission]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11377</guid>
		<description>By Dancho Danchev Have you sent an eFax recently? Watch out for an ongoing malicious spam campaign that tries to convince you that there&amp;#8217;s been an unsuccessful fax transmission. Once socially engineered users execute the malicious attachment found in the fake emails, their PCs automatically join the botnet of the cybercriminals behind the campaign. More [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11377&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/JMz8872CM24" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/11/fake-unsuccessful-fax-transmission-themed-emails-lead-to-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/fake_bogus_email_spam_efax_unsuccessful_fax_transmission_malware_malicious_software_social_engineering.png" medium="image">
			<media:title type="html">Fake_Bogus_Email_Spam_eFax_Unsuccessful_Fax_Transmission_Malware_Malicious_Software_Social_Engineering</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/11/fake-unsuccessful-fax-transmission-themed-emails-lead-to-malware/</feedburner:origLink></item>
		<item>
		<title>Scammers impersonate the UN Refugee Agency (UNHCR), seek your credit card details</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/v4WNAuu23xY/</link>
		<comments>http://blog.webroot.com/2013/06/10/scammers-impersonate-the-un-refugee-agency-unhcr-seek-your-credit-cards-details/#comments</comments>
		<pubDate>Mon, 10 Jun 2013 07:00:39 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[social engineering]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Donation]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[Fake Donation]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Fraudulent]]></category>
		<category><![CDATA[Scam]]></category>
		<category><![CDATA[Scammers]]></category>
		<category><![CDATA[Spam Campaign]]></category>
		<category><![CDATA[Spamvertised]]></category>
		<category><![CDATA[UN]]></category>
		<category><![CDATA[UNHCH]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11363</guid>
		<description>By Dancho Danchev Opportunistic scammers have just launched a targeted spam campaign impersonating the UN Refugee Agency (UNHCR) in an attempt to trick users into handing over their complete credit card details as they supposedly make a donation to support Syria&amp;#8217;s refugees. Needless to say, this scam is seeking full access to your credit card details through a fraudulent [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11363&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/v4WNAuu23xY" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/10/scammers-impersonate-the-un-refugee-agency-unhcr-seek-your-credit-cards-details/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/syria_fake_bogus_fraudulent_donation_site_campaign_agency_unhcr_scam_fraud_credit_card_02.png" medium="image">
			<media:title type="html">Syria_Fake_Bogus_Fraudulent_Donation_Site_Campaign_Agency_UNHCR_Scam_Fraud_Credit_Card_02</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/syria_fake_bogus_fraudulent_donation_site_campaign_agency_unhcr_scam_fraud_credit_card.png" medium="image">
			<media:title type="html">Syria_Fake_Bogus_Fraudulent_Donation_Site_Campaign_Agency_UNHCR_Scam_Fraud_Credit_Card</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/syria_fake_bogus_fraudulent_donation_site_campaign_agency_unhcr_scam_fraud_credit_card_01.png" medium="image">
			<media:title type="html">Syria_Fake_Bogus_Fraudulent_Donation_Site_Campaign_Agency_UNHCR_Scam_Fraud_Credit_Card_01</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/10/scammers-impersonate-the-un-refugee-agency-unhcr-seek-your-credit-cards-details/</feedburner:origLink></item>
		<item>
		<title>Hacked Origin, Uplay, Hulu Plus, Netflix, Spotify, Skype, Twitter, Instagram, Tumblr, Freelancer accounts offered for sale</title>
		<link>http://feedproxy.google.com/~r/WebrootThreatBlog/~3/pagjr9BERoE/</link>
		<comments>http://blog.webroot.com/2013/06/07/hacked-origin-uplay-hulu-plus-netflix-spotify-skype-twitter-instagram-tumblr-freelancer-accounts-offered-for-sale/#comments</comments>
		<pubDate>Fri, 07 Jun 2013 07:00:22 +0000</pubDate>
		<dc:creator>ddanchev</dc:creator>
				<category><![CDATA[Threat Research]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Buy]]></category>
		<category><![CDATA[Compromised]]></category>
		<category><![CDATA[Compromised Accounts]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[E-shop]]></category>
		<category><![CDATA[Freelancer]]></category>
		<category><![CDATA[Games]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[Gaming Market]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[Hacked Accounts]]></category>
		<category><![CDATA[Hulu Plus]]></category>
		<category><![CDATA[Instagram]]></category>
		<category><![CDATA[Keys]]></category>
		<category><![CDATA[License Codes]]></category>
		<category><![CDATA[Netflix]]></category>
		<category><![CDATA[Origin]]></category>
		<category><![CDATA[Sell]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[Spotify]]></category>
		<category><![CDATA[Tumblr]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Underground Market]]></category>
		<category><![CDATA[Uplay]]></category>

		<guid isPermaLink="false">http://blog.webroot.com/?p=11347</guid>
		<description>By Dancho Danchev Aiming to capitalize on the multi-billion gaming market, cybercriminals actively data mine their botnets for accounting credentials, not just for popular gaming platforms, but also the actual activation keys for some of the most popular games on the market. A newly launched e-shop aims to monetize stolen accounting credentials, not just for [&amp;#8230;]&lt;img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.webroot.com&amp;#038;blog=6518987&amp;#038;post=11347&amp;#038;subd=webrootblog&amp;#038;ref=&amp;#038;feed=1" width="1" height="1" /&gt;&lt;img src="http://feeds.feedburner.com/~r/WebrootThreatBlog/~4/pagjr9BERoE" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blog.webroot.com/2013/06/07/hacked-origin-uplay-hulu-plus-netflix-spotify-skype-twitter-instagram-tumblr-freelancer-accounts-offered-for-sale/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/e21e20e630ed1980d45ea435153a525f?s=96&amp;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&amp;r=PG" medium="image">
			<media:title type="html">ddanchev</media:title>
		</media:content>

		<media:content url="http://webrootblog.files.wordpress.com/2013/06/hacked_accounts_for_sale.jpg" medium="image">
			<media:title type="html">Hacked_Accounts_For_Sale</media:title>
		</media:content>
	<feedburner:origLink>http://blog.webroot.com/2013/06/07/hacked-origin-uplay-hulu-plus-netflix-spotify-skype-twitter-instagram-tumblr-freelancer-accounts-offered-for-sale/</feedburner:origLink></item>
	</channel>
</rss>
