<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Watch a live spam bot in action.</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2006/11/01/watch-a-live-spam-bot-in-action/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/watch-a-live-spam-bot-in-action</link>
	<description></description>
	<lastBuildDate>Wed, 16 May 2012 22:25:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Featherfire Lennon</title>
		<link>http://blogs.mcafee.com/mcafee-labs/watch-a-live-spam-bot-in-action/comment-page-1#comment-6124</link>
		<dc:creator>Featherfire Lennon</dc:creator>
		<pubDate>Mon, 06 Nov 2006 07:34:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=123#comment-6124</guid>
		<description>Thankyou, I have been TRYING to let McAffee know for a year that they have had trouble with viruses and worms. Whether from a third party I don&#039;t know, but I traced it through an independent scan for PUPS, and McAffee kept coming up again &amp; again, from Soth America, Venezuela.
I rang McAffee, and was told &quot;This is aload of bullshit, we don;t have ANY problems, thankyou. Now just redownload &amp; she&#039;ll be right mate, ansd stop trying to say we have &quot;PUP.
But I have just been reconnected again, after being offline, and had to Downlad McAffee again, and again I got up on Saturdy, Australian Daylight Savings Time, and my pc was acting weirdly, and I scanned, it came up with nothing until today 6/11/06 monday. pup worm&quot;W32/IRCbot.worm. well, well, well, what a surprise hey. i have downloaded &quot;stinger&quot; thankyou, and hope this helps. it&quot;s (worm) has crashed my pc today over &amp; over. Spybot won&#039;t work. Microsoft Works 8 has disappeared, and I keep getting &quot;error-500&quot; messages constantly, so closing &amp; restarting.
I think this &quot;worm is QUITE More seriou than low Profile, as my pc has even returned to WINDOWS 98 Edition.!!!! please warn others that this may have mutated and seems to hide in the Hard Drive, just waiting for the &quot;right&quot; program to attack It is VERY selective, But EXTREMELY tough &amp; resilient even to the latest Remval Tools etc. OK. So PLEASE let it be posted on the web if you could.And perhaps have another look at its functioning capabilities and destructive capabilities.
Thankyou for your help with keeping us posted out here, we rely on you people.
                                                                    Featherfire Lennon
                                                          striker@bigpond.net.au</description>
		<content:encoded><![CDATA[<p>Thankyou, I have been TRYING to let McAffee know for a year that they have had trouble with viruses and worms. Whether from a third party I don&#8217;t know, but I traced it through an independent scan for PUPS, and McAffee kept coming up again &amp; again, from Soth America, Venezuela.<br />
I rang McAffee, and was told &#8220;This is aload of bullshit, we don;t have ANY problems, thankyou. Now just redownload &amp; she&#8217;ll be right mate, ansd stop trying to say we have &#8220;PUP.<br />
But I have just been reconnected again, after being offline, and had to Downlad McAffee again, and again I got up on Saturdy, Australian Daylight Savings Time, and my pc was acting weirdly, and I scanned, it came up with nothing until today 6/11/06 monday. pup worm&#8221;W32/IRCbot.worm. well, well, well, what a surprise hey. i have downloaded &#8220;stinger&#8221; thankyou, and hope this helps. it&#8221;s (worm) has crashed my pc today over &amp; over. Spybot won&#8217;t work. Microsoft Works 8 has disappeared, and I keep getting &#8220;error-500&#8243; messages constantly, so closing &amp; restarting.<br />
I think this &#8220;worm is QUITE More seriou than low Profile, as my pc has even returned to WINDOWS 98 Edition.!!!! please warn others that this may have mutated and seems to hide in the Hard Drive, just waiting for the &#8220;right&#8221; program to attack It is VERY selective, But EXTREMELY tough &amp; resilient even to the latest Remval Tools etc. OK. So PLEASE let it be posted on the web if you could.And perhaps have another look at its functioning capabilities and destructive capabilities.<br />
Thankyou for your help with keeping us posted out here, we rely on you people.<br />
                                                                    Featherfire Lennon<br />
                                                          striker@bigpond.net.au</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: William Salusky</title>
		<link>http://blogs.mcafee.com/mcafee-labs/watch-a-live-spam-bot-in-action/comment-page-1#comment-6123</link>
		<dc:creator>William Salusky</dc:creator>
		<pubDate>Wed, 01 Nov 2006 19:31:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=123#comment-6123</guid>
		<description>Hi Chris,

William Salusky here, a volunteer handler with the Internet Storm Center.  Great post, but maybe it&#039;s worth mentioning that what you&#039;ve overviewed here is only one particular methodology used by spambots that are phone home and template driven vs. a typical generic socks proxybot that requires an upstream controller to manage all smtp sessions.

Can you also provide us with the AV classification that McAfee has given to this particular sample?  If possible I&#039;d also love it if you could share the md5 hash from the original sample to determine we&#039;ve seen this one specifically.

thanks,

W</description>
		<content:encoded><![CDATA[<p>Hi Chris,</p>
<p>William Salusky here, a volunteer handler with the Internet Storm Center.  Great post, but maybe it&#8217;s worth mentioning that what you&#8217;ve overviewed here is only one particular methodology used by spambots that are phone home and template driven vs. a typical generic socks proxybot that requires an upstream controller to manage all smtp sessions.</p>
<p>Can you also provide us with the AV classification that McAfee has given to this particular sample?  If possible I&#8217;d also love it if you could share the md5 hash from the original sample to determine we&#8217;ve seen this one specifically.</p>
<p>thanks,</p>
<p>W</p>
]]></content:encoded>
	</item>
</channel>
</rss>

