<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DarkFiber Consulting - IT Managed Services &#187; Preventative Measures</title>
	<atom:link href="http://www.darkfiberla.com/tag/preventative-measures/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darkfiberla.com</link>
	<description>DarkFiber Consulting offers managed services for the SMB market. Some of the services we offer include network administration, server management, desktop support, smartphone and blackbery configuration, voip, and asterisk based pbx phone systems.</description>
	<lastBuildDate>Wed, 23 Jun 2010 18:43:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Malicious Code Circulating via Social Security Administration Phishing Messages</title>
		<link>http://www.darkfiberla.com/security-alerts/malicious-code-circulating-via-social-security-administration-phishing-messages/</link>
		<comments>http://www.darkfiberla.com/security-alerts/malicious-code-circulating-via-social-security-administration-phishing-messages/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 18:49:45 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Bank Accounts]]></category>
		<category><![CDATA[Caution]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Malicious Code]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Security Consulting]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Social Security]]></category>
		<category><![CDATA[Social Security Administration]]></category>
		<category><![CDATA[Social Security Number]]></category>
		<category><![CDATA[Social Security Statement]]></category>
		<category><![CDATA[Social Security Statements]]></category>
		<category><![CDATA[Traffic]]></category>
		<category><![CDATA[Unsolicited Email]]></category>
		<category><![CDATA[Virus Signatures]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/malicious-code-circulating-via-social-security-administration-phishing-messages/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of malicious code circulating via phishing email messages that appear to come from the Social Security Administration. The messages indicate that the users&#8217; annual Social Security statements may contain errors and instruct users to follow a link to review their Social Security statement. If users click this link, [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of public reports of malicious code circulating via phishing email messages that appear to come from the Social Security Administration. The messages indicate that the users&#8217; annual Social Security statements may contain errors and instruct users to follow a link to review their Social Security statement. If users click this link, they will be redirected to a seemingly legitimate website that prompts them for their Social Security number. If users enter their Social Security number and continue to the next page, they will be given an option to generate a statement. If users attempt to generate a statement, malicious code may be installed on their systems. This malicious code attempts to collect online banking traffic to gain access to the users&#8217; bank accounts.</p>
<p>DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:
<ul>
<li>Install antivirus software, and keep the virus signatures up to date.</li>
<li>Do not follow unsolicited links and do not open unsolicited email messages.</li>
<li>Use caution when visiting untrusted websites.</li>
<li>Use caution when entering personal information online.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>
<p>DarkFiber Consulting will provide additional information as it becomes available.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/bank-accounts/" title="Bank Accounts" rel="tag">Bank Accounts</a>, <a href="http://www.darkfiberla.com/tag/caution/" title="Caution" rel="tag">Caution</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/malicious-code/" title="Malicious Code" rel="tag">Malicious Code</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/security-consulting/" title="Security Consulting" rel="tag">Security Consulting</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/social-security/" title="Social Security" rel="tag">Social Security</a>, <a href="http://www.darkfiberla.com/tag/social-security-administration/" title="Social Security Administration" rel="tag">Social Security Administration</a>, <a href="http://www.darkfiberla.com/tag/social-security-number/" title="Social Security Number" rel="tag">Social Security Number</a>, <a href="http://www.darkfiberla.com/tag/social-security-statement/" title="Social Security Statement" rel="tag">Social Security Statement</a>, <a href="http://www.darkfiberla.com/tag/social-security-statements/" title="Social Security Statements" rel="tag">Social Security Statements</a>, <a href="http://www.darkfiberla.com/tag/traffic/" title="Traffic" rel="tag">Traffic</a>, <a href="http://www.darkfiberla.com/tag/unsolicited-email/" title="Unsolicited Email" rel="tag">Unsolicited Email</a>, <a href="http://www.darkfiberla.com/tag/virus-signatures/" title="Virus Signatures" rel="tag">Virus Signatures</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/malicious-code-circulating-via-social-security-administration-phishing-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>United States Presidential Election Email Attack</title>
		<link>http://www.darkfiberla.com/security-alerts/united-states-presidential-election-email-attack/</link>
		<comments>http://www.darkfiberla.com/security-alerts/united-states-presidential-election-email-attack/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 05:00:31 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Additional News]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[Caution]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Executable File]]></category>
		<category><![CDATA[Legitimate Source]]></category>
		<category><![CDATA[Malicious Code]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[President Elect]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Software Applications]]></category>
		<category><![CDATA[United States Presidential Election]]></category>
		<category><![CDATA[Virus Signatures]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/united-states-presidential-election-email-attack/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of email attacks circulating that are related to the recent U.S. presidential election. The email messages appear to be coming from a seemingly legitimate source and contain a message indicating that additional news coverage of the election is available by following a link. The link directs users to [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of <a href="http://www.f-secure.com/weblog/archives/00001530.html" target="_self">public reports</a> of email attacks circulating that are related to the recent U.S. presidential election. The email messages appear to be coming from a seemingly legitimate source and contain a message indicating that additional news coverage of the election is available by following a link. The link directs users to a website that appears to contain a video of the president elect. The website will instruct the user to update to a new version of Adobe Flash Player in order to view the video. This update is not a legitimate Adobe Flash Player update; it is malicious code. If the user downloads this executable file, malicious code may be installed on the system.</p>
<p>DarkFiber Consulting encourages users to take the following preventative measures to mitigate the security risks:
<ul>
<li>Install antivirus software, and keep the virus signatures up to date.</li>
<li>Do not follow unsolicited links.</li>
<li>Use caution when visiting untrusted websites.</li>
<li>Use caution when downloading and installing applications.</li>
<li>Obtain software applications and updates directly from the vendor&#8217;s website.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/additional-news/" title="Additional News" rel="tag">Additional News</a>, <a href="http://www.darkfiberla.com/tag/adobe-flash-player/" title="Adobe Flash Player" rel="tag">Adobe Flash Player</a>, <a href="http://www.darkfiberla.com/tag/caution/" title="Caution" rel="tag">Caution</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/executable-file/" title="Executable File" rel="tag">Executable File</a>, <a href="http://www.darkfiberla.com/tag/legitimate-source/" title="Legitimate Source" rel="tag">Legitimate Source</a>, <a href="http://www.darkfiberla.com/tag/malicious-code/" title="Malicious Code" rel="tag">Malicious Code</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/president-elect/" title="President Elect" rel="tag">President Elect</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/software-applications/" title="Software Applications" rel="tag">Software Applications</a>, <a href="http://www.darkfiberla.com/tag/united-states-presidential-election/" title="United States Presidential Election" rel="tag">United States Presidential Election</a>, <a href="http://www.darkfiberla.com/tag/virus-signatures/" title="Virus Signatures" rel="tag">Virus Signatures</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/united-states-presidential-election-email-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Torpig Trojan Horse Attack Activity</title>
		<link>http://www.darkfiberla.com/security-alerts/torpig-trojan-horse-attack-activity/</link>
		<comments>http://www.darkfiberla.com/security-alerts/torpig-trojan-horse-attack-activity/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 22:06:39 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Additional User]]></category>
		<category><![CDATA[Attackers]]></category>
		<category><![CDATA[Credentials]]></category>
		<category><![CDATA[Current User]]></category>
		<category><![CDATA[Digital Certificates]]></category>
		<category><![CDATA[Financial Accounts]]></category>
		<category><![CDATA[Firewall Logs]]></category>
		<category><![CDATA[High Volume]]></category>
		<category><![CDATA[Information Systems]]></category>
		<category><![CDATA[Internet Connections]]></category>
		<category><![CDATA[Ip Addresses]]></category>
		<category><![CDATA[Malicious Programs]]></category>
		<category><![CDATA[Mbr]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Torpig]]></category>
		<category><![CDATA[Traffic Analysis]]></category>
		<category><![CDATA[Trojan Horse Attack]]></category>
		<category><![CDATA[Virus Signatures]]></category>
		<category><![CDATA[Web Pages]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/torpig-trojan-horse-attack-activity/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of a high volume of financial accounts compromised by the Torpig (also known as Sinowal or Anserin) Trojan horse. This Trojan horse uses HTML injection to add fields to web pages in order to convince users to provide additional user credentials or financial account information. Systems compromised by [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1378" target="_self">public reports</a> of a high volume of financial accounts compromised by the Torpig (also known as Sinowal or Anserin) Trojan horse. This Trojan horse uses HTML injection to add fields to web pages in order to convince users to provide additional user credentials or financial account information. Systems compromised by this Trojan horse are being used by attackers to obtain FTP credentials, email addresses, and digital certificates of the current user.</p>
<p>This Trojan horse uses an MBR rootkit known as Mebroot. This rootkit contains configuration information for the Trojan horse as well as techniques used to keep the Trojan horse undetectable.</p>
<p>DarkFiber Consulting encourages users to do the following preventative measures to mitigate the security risks:
<ul>
<li>Install antivirus software, and keep the virus signatures up to date.</li>
<li>Investigate anomalous or slow-running machines, looking for unknown processes or unexpected Internet connections as this may be a sign of malicious programs operating in the background.</li>
<li>Examine firewall logs of systems for connections to or from anomalous IP addresses.</li>
<li>Consider traffic analysis to identify compromised systems that are exfiltrating data.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/additional-user/" title="Additional User" rel="tag">Additional User</a>, <a href="http://www.darkfiberla.com/tag/attackers/" title="Attackers" rel="tag">Attackers</a>, <a href="http://www.darkfiberla.com/tag/credentials/" title="Credentials" rel="tag">Credentials</a>, <a href="http://www.darkfiberla.com/tag/current-user/" title="Current User" rel="tag">Current User</a>, <a href="http://www.darkfiberla.com/tag/digital-certificates/" title="Digital Certificates" rel="tag">Digital Certificates</a>, <a href="http://www.darkfiberla.com/tag/financial-accounts/" title="Financial Accounts" rel="tag">Financial Accounts</a>, <a href="http://www.darkfiberla.com/tag/firewall-logs/" title="Firewall Logs" rel="tag">Firewall Logs</a>, <a href="http://www.darkfiberla.com/tag/high-volume/" title="High Volume" rel="tag">High Volume</a>, <a href="http://www.darkfiberla.com/tag/information-systems/" title="Information Systems" rel="tag">Information Systems</a>, <a href="http://www.darkfiberla.com/tag/internet-connections/" title="Internet Connections" rel="tag">Internet Connections</a>, <a href="http://www.darkfiberla.com/tag/ip-addresses/" title="Ip Addresses" rel="tag">Ip Addresses</a>, <a href="http://www.darkfiberla.com/tag/malicious-programs/" title="Malicious Programs" rel="tag">Malicious Programs</a>, <a href="http://www.darkfiberla.com/tag/mbr/" title="Mbr" rel="tag">Mbr</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/torpig/" title="Torpig" rel="tag">Torpig</a>, <a href="http://www.darkfiberla.com/tag/traffic-analysis/" title="Traffic Analysis" rel="tag">Traffic Analysis</a>, <a href="http://www.darkfiberla.com/tag/trojan-horse-attack/" title="Trojan Horse Attack" rel="tag">Trojan Horse Attack</a>, <a href="http://www.darkfiberla.com/tag/virus-signatures/" title="Virus Signatures" rel="tag">Virus Signatures</a>, <a href="http://www.darkfiberla.com/tag/web-pages/" title="Web Pages" rel="tag">Web Pages</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/torpig-trojan-horse-attack-activity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Antivirus Software Circulating</title>
		<link>http://www.darkfiberla.com/security-alerts/fake-antivirus-software-circulating/</link>
		<comments>http://www.darkfiberla.com/security-alerts/fake-antivirus-software-circulating/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 16:30:16 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Antivirus Applications]]></category>
		<category><![CDATA[Antivirus Software]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Caution]]></category>
		<category><![CDATA[Credit Card Information]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Fraudulent Activity]]></category>
		<category><![CDATA[Install Software]]></category>
		<category><![CDATA[Instances]]></category>
		<category><![CDATA[Instant Messages]]></category>
		<category><![CDATA[Malicious Code]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Private Messages]]></category>
		<category><![CDATA[Purchasing]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[Social Networking Sites]]></category>
		<category><![CDATA[Software Applications]]></category>
		<category><![CDATA[Software Consulting]]></category>
		<category><![CDATA[Virus Signature]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/fake-antivirus-software-circulating/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports indicating an increase in the instances of fake antivirus software circulating. These software applications are malicious code, not legitimate antivirus applications. These instances of malicious code are noted as being distributed through spam email messages containing malicious links, instant messages containing malicious links, private messages on social networking [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of <a href="http://blog.trendmicro.com/rogue-av-theatrics-on-extended-run/" target="_self">public reports</a> indicating an increase in the instances of fake antivirus software circulating. These software applications are malicious code, not legitimate antivirus applications. These instances of malicious code are noted as being distributed through spam email messages containing malicious links, instant messages containing malicious links, private messages on social networking sites, infection from other malware, and from visiting compromised websites. </p>
<p>Quite often, this malware attempts to convince users that there is something wrong with their systems. This leads to an attempt persuade the users into purchasing an illegitimate antivirus application. If the user purchases the bogus software, the attacker may be able to obtain personal and credit card information for use in additional scams and fraudulent activity.</p>
<p>DarkFiber Consulting encourages users to perform the following preventative measures to help mitigate the risks:
<ul>
<li>Install legitimate antivirus software from a trusted vendor, and keep its virus signature files up-to-date.</li>
<li>Do not follow unsolicited web links found in email messages or instant messages.</li>
<li>Use caution when visiting untrusted websites.</li>
<li>Do not install untrusted software.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/antivirus-applications/" title="Antivirus Applications" rel="tag">Antivirus Applications</a>, <a href="http://www.darkfiberla.com/tag/antivirus-software/" title="Antivirus Software" rel="tag">Antivirus Software</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/caution/" title="Caution" rel="tag">Caution</a>, <a href="http://www.darkfiberla.com/tag/credit-card-information/" title="Credit Card Information" rel="tag">Credit Card Information</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/fraudulent-activity/" title="Fraudulent Activity" rel="tag">Fraudulent Activity</a>, <a href="http://www.darkfiberla.com/tag/install-software/" title="Install Software" rel="tag">Install Software</a>, <a href="http://www.darkfiberla.com/tag/instances/" title="Instances" rel="tag">Instances</a>, <a href="http://www.darkfiberla.com/tag/instant-messages/" title="Instant Messages" rel="tag">Instant Messages</a>, <a href="http://www.darkfiberla.com/tag/malicious-code/" title="Malicious Code" rel="tag">Malicious Code</a>, <a href="http://www.darkfiberla.com/tag/malware/" title="Malware" rel="tag">Malware</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/private-messages/" title="Private Messages" rel="tag">Private Messages</a>, <a href="http://www.darkfiberla.com/tag/purchasing/" title="Purchasing" rel="tag">Purchasing</a>, <a href="http://www.darkfiberla.com/tag/scams/" title="Scams" rel="tag">Scams</a>, <a href="http://www.darkfiberla.com/tag/social-networking-sites/" title="Social Networking Sites" rel="tag">Social Networking Sites</a>, <a href="http://www.darkfiberla.com/tag/software-applications/" title="Software Applications" rel="tag">Software Applications</a>, <a href="http://www.darkfiberla.com/tag/software-consulting/" title="Software Consulting" rel="tag">Software Consulting</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/fake-antivirus-software-circulating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Circulating via Russia/Georgia Conflict Spam Messages</title>
		<link>http://www.darkfiberla.com/security-alerts/malware-circulating-via-russiageorgia-conflict-spam-messages/</link>
		<comments>http://www.darkfiberla.com/security-alerts/malware-circulating-via-russiageorgia-conflict-spam-messages/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 04:15:43 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Anti Virus Software]]></category>
		<category><![CDATA[Conflict]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Factual Information]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam Email]]></category>
		<category><![CDATA[Virus Signature]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/malware-circulating-via-russiageorgia-conflict-spam-messages/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of malware circulating via spam email messages related to the Russia/Georgia conflict. These messages contain factual information about the conflict. The messages also contain download instructions for the user to watch a video that is attached to the message. If a user opens the attachment, malware may be [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of <a href="https://forums.symantec.com/syment/blog/article?blog.id=spam&amp;thread.id=111" target="_self">public reports</a> of malware circulating via spam email messages related to the Russia/Georgia conflict. These messages contain factual information about the conflict. The messages also contain download instructions for the user to watch a video that is attached to the message. If a user opens the attachment, malware may be downloaded and installed onto their system.</p>
<p>DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:
<ul>
<li>Install anti-virus software, and keep its virus signature files up-to-date.</li>
<li>Do not follow unsolicited web links received in email messages.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/anti-virus-software/" title="Anti Virus Software" rel="tag">Anti Virus Software</a>, <a href="http://www.darkfiberla.com/tag/conflict/" title="Conflict" rel="tag">Conflict</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/factual-information/" title="Factual Information" rel="tag">Factual Information</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/russia/" title="Russia" rel="tag">Russia</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/spam-email/" title="Spam Email" rel="tag">Spam Email</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/malware-circulating-via-russiageorgia-conflict-spam-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Circulating via Spam Messages</title>
		<link>http://www.darkfiberla.com/security-alerts/malware-circulating-via-spam-messages/</link>
		<comments>http://www.darkfiberla.com/security-alerts/malware-circulating-via-spam-messages/#comments</comments>
		<pubDate>Fri, 08 Aug 2008 04:27:12 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Anti Virus Software]]></category>
		<category><![CDATA[Cnn]]></category>
		<category><![CDATA[Cnn News]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Fake News]]></category>
		<category><![CDATA[Flash Player]]></category>
		<category><![CDATA[News Reports]]></category>
		<category><![CDATA[Olympics]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam Messages]]></category>
		<category><![CDATA[Virus Signature]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/malware-circulating-via-spam-messages/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of malware spreading via spam. It has been reported that malware is spreading in spam messages related to the upcoming Olympics and to fake CNN news reports. If a user clicks the link to one of these fake news reports they are prompted to install a Flash Player [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of public reports of malware spreading via spam. It has been reported that malware is spreading in spam messages related to the upcoming Olympics and to fake CNN news reports. If a user clicks the link to one of these fake news reports they are prompted to install a Flash Player update. If users attempt to install the update, malware may be downloaded and installed onto their system.</p>
<p>DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:
<ul>
<li>Install anti-virus software, and keep its virus signature files up-to-date.</li>
<li>Do not follow unsolicited web links received in email messages. </li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams. </li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/anti-virus-software/" title="Anti Virus Software" rel="tag">Anti Virus Software</a>, <a href="http://www.darkfiberla.com/tag/cnn/" title="Cnn" rel="tag">Cnn</a>, <a href="http://www.darkfiberla.com/tag/cnn-news/" title="Cnn News" rel="tag">Cnn News</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/fake-news/" title="Fake News" rel="tag">Fake News</a>, <a href="http://www.darkfiberla.com/tag/flash-player/" title="Flash Player" rel="tag">Flash Player</a>, <a href="http://www.darkfiberla.com/tag/news-reports/" title="News Reports" rel="tag">News Reports</a>, <a href="http://www.darkfiberla.com/tag/olympics/" title="Olympics" rel="tag">Olympics</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/spam-messages/" title="Spam Messages" rel="tag">Spam Messages</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/malware-circulating-via-spam-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Targeting Adobe Flash Player</title>
		<link>http://www.darkfiberla.com/security-alerts/malware-targeting-adobe-flash-player/</link>
		<comments>http://www.darkfiberla.com/security-alerts/malware-targeting-adobe-flash-player/#comments</comments>
		<pubDate>Tue, 05 Aug 2008 16:43:13 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Adobe Flash Player]]></category>
		<category><![CDATA[Anti Virus Software]]></category>
		<category><![CDATA[Attempt]]></category>
		<category><![CDATA[Installer Adobe]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Social Networking Sites]]></category>
		<category><![CDATA[Urges]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/malware-targeting-adobe-flash-player/</guid>
		<description><![CDATA[Adobe has issued a Security Bulletin warning of malware spreading via a fraudulent Flash Player installer. Adobe warns that a worm is making fraudulent posts on social networking sites. These posts include links that lead to fake sites that prompt users to update their versions of Flash Player. If users attempt to use the installer [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe has issued a <a href="http://blogs.adobe.com/psirt/2008/08/verifying_installers.html" target="_self">Security Bulletin</a> warning of malware spreading via a fraudulent Flash Player installer. Adobe warns that a worm is making fraudulent posts on social networking sites. These posts include links that lead to fake sites that prompt users to update their versions of Flash Player. If users attempt to use the installer to make the update, malware may be downloaded and installed onto their systems.</p>
<p>DarkFiber Consulting urges users and administrators to take the following preventative measures to help mitigate the security risks:
<ul>
<li>Do not follow unsolicited web links.</li>
<li>Configure your web browser as described in the <a href="http://www.DarkFiber Consulting.gov/reading_room/securing_browser/" target="_self">Securing Your Web Browser</a> document.</li>
<li>Install anti-virus software, and keep its virus signature files up-to-date.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/adobe-flash-player/" title="Adobe Flash Player" rel="tag">Adobe Flash Player</a>, <a href="http://www.darkfiberla.com/tag/anti-virus-software/" title="Anti Virus Software" rel="tag">Anti Virus Software</a>, <a href="http://www.darkfiberla.com/tag/attempt/" title="Attempt" rel="tag">Attempt</a>, <a href="http://www.darkfiberla.com/tag/installer-adobe/" title="Installer Adobe" rel="tag">Installer Adobe</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/security-bulletin/" title="Security Bulletin" rel="tag">Security Bulletin</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/social-networking-sites/" title="Social Networking Sites" rel="tag">Social Networking Sites</a>, <a href="http://www.darkfiberla.com/tag/urges/" title="Urges" rel="tag">Urges</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a>, <a href="http://www.darkfiberla.com/tag/worm/" title="Worm" rel="tag">Worm</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/malware-targeting-adobe-flash-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Airline E-ticket Email Attack</title>
		<link>http://www.darkfiberla.com/security-alerts/airline-e-ticket-email-attack/</link>
		<comments>http://www.darkfiberla.com/security-alerts/airline-e-ticket-email-attack/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 04:25:55 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Airline Ticket]]></category>
		<category><![CDATA[Airlines]]></category>
		<category><![CDATA[Anti Virus Software]]></category>
		<category><![CDATA[Attributes]]></category>
		<category><![CDATA[E Ticket]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Malicious Code]]></category>
		<category><![CDATA[New Email]]></category>
		<category><![CDATA[Open Attachments]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[S System]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Subject Line]]></category>
		<category><![CDATA[Unsolicited Email]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Xxxx]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/airline-e-ticket-email-attack/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports indicating that a new email attack is circulating. This attack uses email messages that appear to be from legitimate airlines and contain information about a bogus e-ticket. These email messages instruct the user to open the attachment to obtain the e-ticket. If a user opens this attachment, a [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of public reports indicating that a new email attack is circulating. This attack uses email messages that appear to be from legitimate airlines and contain information about a bogus e-ticket. These email messages instruct the user to open the attachment to obtain the e-ticket. If a user opens this attachment, a file may be executed to infect the user&#8217;s system with malicious code.</p>
<p>Reports, including a posting by <a href="http://www.sophos.com/security/blog/2008/07/1604.html" target="_self">Sophos</a>, indicate that these messages have the following characteristics. Please note that these attributes may change at any time.
<ul>
<li>The subject line &#8220;E-Ticket#XXXXXXXXXX&#8221; </li>
<li>An attachment named &#8220;eTicket#XXXX.zip&#8221;</li>
</ul>
<p>DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:
<ul>
<li>Install anti-virus software, and keep its virus signature file up to date.</li>
<li>Do not open attachments in unsolicited email messages.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/airline-ticket/" title="Airline Ticket" rel="tag">Airline Ticket</a>, <a href="http://www.darkfiberla.com/tag/airlines/" title="Airlines" rel="tag">Airlines</a>, <a href="http://www.darkfiberla.com/tag/anti-virus-software/" title="Anti Virus Software" rel="tag">Anti Virus Software</a>, <a href="http://www.darkfiberla.com/tag/attributes/" title="Attributes" rel="tag">Attributes</a>, <a href="http://www.darkfiberla.com/tag/e-ticket/" title="E Ticket" rel="tag">E Ticket</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/malicious-code/" title="Malicious Code" rel="tag">Malicious Code</a>, <a href="http://www.darkfiberla.com/tag/new-email/" title="New Email" rel="tag">New Email</a>, <a href="http://www.darkfiberla.com/tag/open-attachments/" title="Open Attachments" rel="tag">Open Attachments</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/s-system/" title="S System" rel="tag">S System</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/subject-line/" title="Subject Line" rel="tag">Subject Line</a>, <a href="http://www.darkfiberla.com/tag/unsolicited-email/" title="Unsolicited Email" rel="tag">Unsolicited Email</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a>, <a href="http://www.darkfiberla.com/tag/xxxx/" title="Xxxx" rel="tag">Xxxx</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/airline-e-ticket-email-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Storm Worm Activity Spreading</title>
		<link>http://www.darkfiberla.com/security-alerts/new-storm-worm-activity-spreading/</link>
		<comments>http://www.darkfiberla.com/security-alerts/new-storm-worm-activity-spreading/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 04:23:19 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Anti Virus Software]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Executable File]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Federal Bureau Of Investigation]]></category>
		<category><![CDATA[Malicious Code]]></category>
		<category><![CDATA[Malicious Website]]></category>
		<category><![CDATA[New Storm]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[S System]]></category>
		<category><![CDATA[Security Risks]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Storm Worm]]></category>
		<category><![CDATA[Subject Lines]]></category>
		<category><![CDATA[Trojan Horse Virus]]></category>
		<category><![CDATA[Unsolicited Email]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[Worm Activity]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/new-storm-worm-activity-spreading/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of a new Storm Worm Campaign. The latest campaign is centered around messages related to the Federal Bureau of Investigation and Facebook. This Trojan horse virus is spread via an unsolicited email message that contains a link to a malicious website. This website contains a link, that when [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of public reports of a new Storm Worm Campaign. The latest campaign is centered around messages related to the Federal Bureau of Investigation and Facebook. This Trojan horse virus is spread via an unsolicited email message that contains a link to a malicious website. This website contains a link, that when clicked, may run the executable file &#8220;fbi_facebook.exe&#8221; to infect the user&#8217;s system with malicious code.</p>
<p>Reports, including a posting by <a href="http://www.sophos.com/security/blog/2008/07/1599.html" target="_self">Sophos</a>, indicate the following email subject lines are being used. Please note that subject lines can change at any time.
<ul>
<li>F.B.I. may strike Facebook</li>
<li>F.B.I. watching us</li>
<li>The FBI&#8217;s plan to &#8220;profile&#8221; Facebook</li>
<li>The FBI has a new way of tracking Facebook</li>
<li>F.B.I. are spying on your Facebook profiles</li>
<li>F.B.I. busts alleged Facebook</li>
<li>Get Facebook&#8217;s F.B.I. Files</li>
<li>Facebook&#8217;s F.B.I. ties</li>
<li>F.B.I. watching you</li>
</ul>
<p>DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:
<ul>
<li>Install anti-virus software, and keep its virus signature files up-to-date.</li>
<li>Do not follow unsolicited web links received in email messages.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/anti-virus-software/" title="Anti Virus Software" rel="tag">Anti Virus Software</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/executable-file/" title="Executable File" rel="tag">Executable File</a>, <a href="http://www.darkfiberla.com/tag/facebook/" title="Facebook" rel="tag">Facebook</a>, <a href="http://www.darkfiberla.com/tag/federal-bureau-of-investigation/" title="Federal Bureau Of Investigation" rel="tag">Federal Bureau Of Investigation</a>, <a href="http://www.darkfiberla.com/tag/malicious-code/" title="Malicious Code" rel="tag">Malicious Code</a>, <a href="http://www.darkfiberla.com/tag/malicious-website/" title="Malicious Website" rel="tag">Malicious Website</a>, <a href="http://www.darkfiberla.com/tag/new-storm/" title="New Storm" rel="tag">New Storm</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/s-system/" title="S System" rel="tag">S System</a>, <a href="http://www.darkfiberla.com/tag/security-risks/" title="Security Risks" rel="tag">Security Risks</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/storm-worm/" title="Storm Worm" rel="tag">Storm Worm</a>, <a href="http://www.darkfiberla.com/tag/subject-lines/" title="Subject Lines" rel="tag">Subject Lines</a>, <a href="http://www.darkfiberla.com/tag/trojan-horse-virus/" title="Trojan Horse Virus" rel="tag">Trojan Horse Virus</a>, <a href="http://www.darkfiberla.com/tag/unsolicited-email/" title="Unsolicited Email" rel="tag">Unsolicited Email</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a>, <a href="http://www.darkfiberla.com/tag/worm-activity/" title="Worm Activity" rel="tag">Worm Activity</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/new-storm-worm-activity-spreading/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Storm Worm Variant Spreading</title>
		<link>http://www.darkfiberla.com/security-alerts/new-storm-worm-variant-spreading/</link>
		<comments>http://www.darkfiberla.com/security-alerts/new-storm-worm-variant-spreading/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 09:26:06 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Anti Virus Software]]></category>
		<category><![CDATA[Conflict In The Middle East]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Iran Iran]]></category>
		<category><![CDATA[Iran Plans]]></category>
		<category><![CDATA[Iran Usa]]></category>
		<category><![CDATA[Mahmoud Ahmadinejad]]></category>
		<category><![CDATA[Malicious Website]]></category>
		<category><![CDATA[New Storm]]></category>
		<category><![CDATA[Preventative Measures]]></category>
		<category><![CDATA[S System]]></category>
		<category><![CDATA[Secret War]]></category>
		<category><![CDATA[Storm Worm]]></category>
		<category><![CDATA[Subject Lines]]></category>
		<category><![CDATA[Third War]]></category>
		<category><![CDATA[Third World War]]></category>
		<category><![CDATA[Virus Signature]]></category>
		<category><![CDATA[World War Iii]]></category>
		<category><![CDATA[Worm Activity]]></category>
		<category><![CDATA[Worm Variant]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/new-storm-worm-variant-spreading/</guid>
		<description><![CDATA[DarkFiber Consulting has received reports of new Storm Worm activity. The latest activity uses messages that refer to the conflict in the Middle East. This Trojan is spread via unsolicited email messages that contain a link to a malicious website. The website is noted as having the following malicious characteristics which may be used to [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting has received reports of new Storm Worm activity. The latest activity uses messages that refer to the conflict in the Middle East. This Trojan is spread via unsolicited email messages that contain a link to a malicious website. The website is noted as having the following malicious characteristics which may be used to infect the user&#8217;s system with malicious code.</p>
<ul>
<li>A video that, when opened, may run the executable file &#8220;iran_occupation.exe.&#8221;</li>
<li>A banner add that, when clicked, may run the executable file &#8220;form.exe.&#8221;</li>
<li>A hidden iframe linked to &#8220;ind.php.&#8221;</li>
</ul>
<p>Reports, including a posting by <a href="http://www.sophos.com/security/blog/2008/07/1569.html" target="_self">Sophos</a>, indicate that the following subject lines are being used. Please note that subject lines can change at any time.</p>
<ul>
<li>20000 US soldiers in Iran</li>
<li>Iran USA conflict developed into war</li>
<li>More than 10000 Iranians were murdered</li>
<li>Negotiations between USA and Iran ended in War</li>
<li>Occupation of Iran</li>
<li>Plans for Iran attack began</li>
<li>The Iran&#8217;s Leader Mahmoud Ahmadinejad declared Jihad to USA</li>
<li>The World War III has already begun</li>
<li>The begining of The World War III</li>
<li>The military operation in Iran has begun</li>
<li>The secret war against Iran</li>
<li>Third War in Iran</li>
<li>Third World War has begun</li>
<li>US Army crossed Iran&#8217;s borders</li>
<li>US Army invaded Iran</li>
<li>US army is about 20 kilometers from Tegeran</li>
<li>US soldiers occupied Iran</li>
<li>USA attacked Iran</li>
<li>USA declares war on Iran</li>
<li>USA occupeid Iran</li>
<li>USA unleashed war on Iran</li>
<li>War between USA&amp;Iran</li>
<li>War with Iran is the reality now</li>
<li>Washington prefers to shoot first</li>
</ul>
<p>DarkFiber Consulting encourages users and administrators to take the following preventative measures to help mitigate the security risks:</p>
<ul>
<li>Install anti-virus software, and keep its virus signature files up-to-date.</li>
<li>Do not follow unsolicited web links received in email messages.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/anti-virus-software/" title="Anti Virus Software" rel="tag">Anti Virus Software</a>, <a href="http://www.darkfiberla.com/tag/conflict-in-the-middle-east/" title="Conflict In The Middle East" rel="tag">Conflict In The Middle East</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/iran-iran/" title="Iran Iran" rel="tag">Iran Iran</a>, <a href="http://www.darkfiberla.com/tag/iran-plans/" title="Iran Plans" rel="tag">Iran Plans</a>, <a href="http://www.darkfiberla.com/tag/iran-usa/" title="Iran Usa" rel="tag">Iran Usa</a>, <a href="http://www.darkfiberla.com/tag/mahmoud-ahmadinejad/" title="Mahmoud Ahmadinejad" rel="tag">Mahmoud Ahmadinejad</a>, <a href="http://www.darkfiberla.com/tag/malicious-website/" title="Malicious Website" rel="tag">Malicious Website</a>, <a href="http://www.darkfiberla.com/tag/new-storm/" title="New Storm" rel="tag">New Storm</a>, <a href="http://www.darkfiberla.com/tag/preventative-measures/" title="Preventative Measures" rel="tag">Preventative Measures</a>, <a href="http://www.darkfiberla.com/tag/s-system/" title="S System" rel="tag">S System</a>, <a href="http://www.darkfiberla.com/tag/secret-war/" title="Secret War" rel="tag">Secret War</a>, <a href="http://www.darkfiberla.com/tag/storm-worm/" title="Storm Worm" rel="tag">Storm Worm</a>, <a href="http://www.darkfiberla.com/tag/subject-lines/" title="Subject Lines" rel="tag">Subject Lines</a>, <a href="http://www.darkfiberla.com/tag/third-war/" title="Third War" rel="tag">Third War</a>, <a href="http://www.darkfiberla.com/tag/third-world-war/" title="Third World War" rel="tag">Third World War</a>, <a href="http://www.darkfiberla.com/tag/virus-signature/" title="Virus Signature" rel="tag">Virus Signature</a>, <a href="http://www.darkfiberla.com/tag/world-war-iii/" title="World War Iii" rel="tag">World War Iii</a>, <a href="http://www.darkfiberla.com/tag/worm-activity/" title="Worm Activity" rel="tag">Worm Activity</a>, <a href="http://www.darkfiberla.com/tag/worm-variant/" title="Worm Variant" rel="tag">Worm Variant</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/new-storm-worm-variant-spreading/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
