<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Today&#8217;s Other Malware Threat: IE7.0.exe</title>
	<atom:link href="http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Wed, 10 Mar 2010 17:00:15 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: &#187; Trojan masquerades as IE 7 downloads &#124; Zero Day &#124; ZDNet.com</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-21249</link>
		<dc:creator>&#187; Trojan masquerades as IE 7 downloads &#124; Zero Day &#124; ZDNet.com</dc:creator>
		<pubDate>Tue, 22 May 2007 22:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-21249</guid>
		<description>[...] A copy of this spam that landed in my GMail inbox arrived from &quot;admin@microsoft.com&quot; with the subject line &quot;Internet Explorer 7 Downloads.&quot;&#160; Anti-virus vendors tracking the threat say the sender address and download locations are constantly changing as this spam run picks up steam.  As fast as these domains appear, get spammed, and get killed, they re-appear. If you run a network stream, you can easily look for &#8220;/IE7.0.exe&#8221; with a tool like ngrep or flowgrep and look at the download sites. This one is aggressive and is going to get a lot of play. AV detection was poor earlier in the day, and it&#8217;s not much better. Names like Agent.CL and Grum are being used, but even 12 hours later the detection for it is pretty weak. It&#8217;s got an unrecognized packer and some methods that seem uncommon. [...]</description>
		<content:encoded><![CDATA[<p>[...] A copy of this spam that landed in my GMail inbox arrived from &quot;admin@microsoft.com&quot; with the subject line &quot;Internet Explorer 7 Downloads.&quot;&nbsp; Anti-virus vendors tracking the threat say the sender address and download locations are constantly changing as this spam run picks up steam.  As fast as these domains appear, get spammed, and get killed, they re-appear. If you run a network stream, you can easily look for &ldquo;/IE7.0.exe&rdquo; with a tool like ngrep or flowgrep and look at the download sites. This one is aggressive and is going to get a lot of play. AV detection was poor earlier in the day, and it&rsquo;s not much better. Names like Agent.CL and Grum are being used, but even 12 hours later the detection for it is pretty weak. It&rsquo;s got an unrecognized packer and some methods that seem uncommon. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Free AntiRootkit Software &#183; Security to the Core &#124; Arbor Networks Security Blog</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-11920</link>
		<dc:creator>Free AntiRootkit Software &#183; Security to the Core &#124; Arbor Networks Security Blog</dc:creator>
		<pubDate>Wed, 04 Apr 2007 14:21:48 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-11920</guid>
		<description>[...] As a complement to a recent post I made here with a list of free online AV scanners, I&#8217;d like to share with you a list of free AntiRootkit software for your PC. Especially in light of this past week&#8217;s ANI-related malware spate and the new Grum Trojan, you should make sure that you&#8217;re always on the lookout for threats. In the past few weeks we&#8217;ve seen even more malware that was simply not detected by AV. [...]</description>
		<content:encoded><![CDATA[<p>[...] As a complement to a recent post I made here with a list of free online AV scanners, I&#8217;d like to share with you a list of free AntiRootkit software for your PC. Especially in light of this past week&#8217;s ANI-related malware spate and the new Grum Trojan, you should make sure that you&#8217;re always on the lookout for threats. In the past few weeks we&#8217;ve seen even more malware that was simply not detected by AV. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Best Posts from around the Web &#187; Today’s Other Malware Threat: IE7.0.exe</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-11427</link>
		<dc:creator>Best Posts from around the Web &#187; Today’s Other Malware Threat: IE7.0.exe</dc:creator>
		<pubDate>Mon, 02 Apr 2007 18:04:17 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-11427</guid>
		<description>[...] Original post by Jose Nazario [...]</description>
		<content:encoded><![CDATA[<p>[...] Original post by Jose Nazario [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TRaef06</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-11047</link>
		<dc:creator>TRaef06</dc:creator>
		<pubDate>Sun, 01 Apr 2007 09:52:06 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-11047</guid>
		<description>Another case where relying on anti-virus signatures leaves you vulnerable.

Defense in depth is the way to go. If your SPAM filters don&#039;t block it, which they should, then blocking executable downloads unless from a verified site, will keep this out - long before the anti-virus companies have created their signatures. Same thing with the Storm situation earlier in the year (2007).</description>
		<content:encoded><![CDATA[<p>Another case where relying on anti-virus signatures leaves you vulnerable.</p>
<p>Defense in depth is the way to go. If your SPAM filters don&#8217;t block it, which they should, then blocking executable downloads unless from a verified site, will keep this out &#8211; long before the anti-virus companies have created their signatures. Same thing with the Storm situation earlier in the year (2007).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Grum Trojan Tips Dr.com</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-10729</link>
		<dc:creator>The Grum Trojan Tips Dr.com</dc:creator>
		<pubDate>Fri, 30 Mar 2007 21:10:51 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-10729</guid>
		<description>[...] abnoba.net 66.98.149.237 cincinnatifeet.com cyberbutt.com gc-music.com arrestingphotography.com kcmancandy.com manualshop.com.ar monella.net tvz-archive.com nottyweb.com Source: Today’s Other Malware Threat: IE7.0.exe [...]</description>
		<content:encoded><![CDATA[<p>[...] abnoba.net 66.98.149.237 cincinnatifeet.com cyberbutt.com gc-music.com arrestingphotography.com kcmancandy.com manualshop.com.ar monella.net tvz-archive.com nottyweb.com Source: Today’s Other Malware Threat: IE7.0.exe [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-10710</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Fri, 30 Mar 2007 19:32:48 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-10710</guid>
		<description>&lt;strong&gt;Todays Other Malware Threat: IE7.0.exe...&lt;/strong&gt;

Lest you think that the ANI thing was the only thing going on today, youd miss the other part of todays entertainment. Theres a new Trojan spam going around trying to entice you to download MSFT IE7.0 Beta 2 (never mind that its been released). This is...</description>
		<content:encoded><![CDATA[<p><strong>Todays Other Malware Threat: IE7.0.exe&#8230;</strong></p>
<p>Lest you think that the ANI thing was the only thing going on today, youd miss the other part of todays entertainment. Theres a new Trojan spam going around trying to entice you to download MSFT IE7.0 Beta 2 (never mind that its been released). This is&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: beforeyoukillyourcomputer.com &#187; Blog Archive &#187; IE7 Trojan on the loose</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-10676</link>
		<dc:creator>beforeyoukillyourcomputer.com &#187; Blog Archive &#187; IE7 Trojan on the loose</dc:creator>
		<pubDate>Fri, 30 Mar 2007 16:36:44 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-10676</guid>
		<description>[...] Source [...]</description>
		<content:encoded><![CDATA[<p>[...] Source [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zuneone</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-10638</link>
		<dc:creator>zuneone</dc:creator>
		<pubDate>Fri, 30 Mar 2007 14:19:56 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-10638</guid>
		<description>I got two of those e-mails and deleted them. Easy to spot as spam visually but they were not blocked by my filter.  Good thing I already use IE7!</description>
		<content:encoded><![CDATA[<p>I got two of those e-mails and deleted them. Easy to spot as spam visually but they were not blocked by my filter.  Good thing I already use IE7!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BTT &#124; Blog The Tech &#187; Blog Archive &#187; Today&apos;s Other Malware Threat: IE7.0.exe (Jose Nazario/Security to the Core)</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-10636</link>
		<dc:creator>BTT &#124; Blog The Tech &#187; Blog Archive &#187; Today&apos;s Other Malware Threat: IE7.0.exe (Jose Nazario/Security to the Core)</dc:creator>
		<pubDate>Fri, 30 Mar 2007 14:16:22 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-10636</guid>
		<description>[...] Today&#8217;s Other Malware Threat: IE7.0.exe&#160; &#8212;&#160; Lest you think that the ANI thing was the only thing going on today, you&#8217;d miss the other part of today&#8217;s entertainment.&#160; There&#8217;s a new Trojan spam going around trying to entice you to download MSFT IE7.0 Beta 2 (never mind that it&#8217;s been released).   Source: &#160; Security to the Core &#124; Arbor Networks Security Blog Author: &#160; Jose Nazario Link: &#160; http://asert.arbornetworks.com/2007/03/todays-other&#8230; Techmeme permalink [...]</description>
		<content:encoded><![CDATA[<p>[...] Today&#8217;s Other Malware Threat: IE7.0.exe&nbsp; &mdash;&nbsp; Lest you think that the ANI thing was the only thing going on today, you&#8217;d miss the other part of today&#8217;s entertainment.&nbsp; There&#8217;s a new Trojan spam going around trying to entice you to download MSFT IE7.0 Beta 2 (never mind that it&#8217;s been released).   Source: &nbsp; Security to the Core | Arbor Networks Security Blog Author: &nbsp; Jose Nazario Link: &nbsp; <a href="http://asert.arbornetworks.com/2007/03/todays-other&#038;hellip" rel="nofollow">http://asert.arbornetworks.com/2007/03/todays-other&#038;hellip</a>; Techmeme permalink [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; Your March 30th Morning Coffee</title>
		<link>http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/comment-page-1/#comment-10632</link>
		<dc:creator>Liquidmatrix Security Digest &#187; Your March 30th Morning Coffee</dc:creator>
		<pubDate>Fri, 30 Mar 2007 13:54:17 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2007/03/todays-other-malware-threat-ie70exe/#comment-10632</guid>
		<description>[...] Today’s Other Malware Threat: IE7.0.exe [...]</description>
		<content:encoded><![CDATA[<p>[...] Today’s Other Malware Threat: IE7.0.exe [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
