<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fake Invoice Spam Carries Malware</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2008/07/24/fake-invoice-spam-carries-malware/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Geoff</title>
		<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware/comment-page-1#comment-18512</link>
		<dc:creator>Geoff</dc:creator>
		<pubDate>Wed, 06 Aug 2008 08:59:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=696#comment-18512</guid>
		<description>I&#039;ve been seeing these daily now, and each time McAfee has not detected it until the next day or day after. We really do need to move to a formal twice-daily DAT release so this sort of thing can be picked up.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been seeing these daily now, and each time McAfee has not detected it until the next day or day after. We really do need to move to a formal twice-daily DAT release so this sort of thing can be picked up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jampa Stewart</title>
		<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware/comment-page-1#comment-18511</link>
		<dc:creator>Jampa Stewart</dc:creator>
		<pubDate>Wed, 30 Jul 2008 20:39:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=696#comment-18511</guid>
		<description>Today I received the following e-mail similar to the one Jeanne Ross received.  It contained an attachment, supposedly with an e-ticket (which I had not ordered); of course I did not open the attachment:

Good day,
Thank you for using our new service &quot;Buy flight ticket Online&quot; on our website.
Your account has been created:

Your login: info@healingtaoinstitute.com Your password: passC4WR

Your credit card has been charged for $467.08.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!
Attached to this message is the purchase Invoice and the flight ticket.
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
Dave Holbrook
Southwest Airlines</description>
		<content:encoded><![CDATA[<p>Today I received the following e-mail similar to the one Jeanne Ross received.  It contained an attachment, supposedly with an e-ticket (which I had not ordered); of course I did not open the attachment:</p>
<p>Good day,<br />
Thank you for using our new service &#8220;Buy flight ticket Online&#8221; on our website.<br />
Your account has been created:</p>
<p>Your login: <span id="emoba-7721"><span class="emoba-em">info<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/at-glyph.gif" alt="at"  class="emoba-glyph" />healingtaoinstitute<img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />com</span></span><script type="text/javascript">emobascript('%69%6E%66%6F%40%68%65%61%6C%69%6E%67%74%61%6F%69%6E%73%74%69%74%75%74%65%2E%63%6F%6D','&lt;span class="emoba-em">info&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/at-glyph.gif" alt="at"  class="emoba-glyph" />healingtaoinstitute&lt;img src="http://blogs.mcafee.com/wp-content/plugins/emoba-email-obfuscator-advanced/dot-glyph.gif" alt="dot" class="emoba-glyph" />com&lt;/span>','emoba-7721','','','0'); </script> Your password: passC4WR</p>
<p>Your credit card has been charged for $467.08.<br />
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!<br />
Attached to this message is the purchase Invoice and the flight ticket.<br />
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!</p>
<p>Kind regards,<br />
Dave Holbrook<br />
Southwest Airlines</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware/comment-page-1#comment-18510</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Mon, 28 Jul 2008 16:43:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=696#comment-18510</guid>
		<description>I agree with the amount of DATs that are released. It def needs to be done over the weekend and once a day just doesn&#039;t cover it in this sort of scenario

We had a couple of the UPS ones come in and it wasn&#039;t until the next day till McAfee detected it. By then it was different ones coming in (customs I think it was)</description>
		<content:encoded><![CDATA[<p>I agree with the amount of DATs that are released. It def needs to be done over the weekend and once a day just doesn&#8217;t cover it in this sort of scenario</p>
<p>We had a couple of the UPS ones come in and it wasn&#8217;t until the next day till McAfee detected it. By then it was different ones coming in (customs I think it was)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Geoff</title>
		<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware/comment-page-1#comment-18509</link>
		<dc:creator>Geoff</dc:creator>
		<pubDate>Sun, 27 Jul 2008 13:54:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=696#comment-18509</guid>
		<description>Yeah, McAfee have been slow to get these detections into the DATs. Doing one DAT per workday is so 1990s. McAfee needs to start pushing out two per day, 7 days a week.</description>
		<content:encoded><![CDATA[<p>Yeah, McAfee have been slow to get these detections into the DATs. Doing one DAT per workday is so 1990s. McAfee needs to start pushing out two per day, 7 days a week.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeanne Ross</title>
		<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware/comment-page-1#comment-18507</link>
		<dc:creator>Jeanne Ross</dc:creator>
		<pubDate>Fri, 25 Jul 2008 16:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=696#comment-18507</guid>
		<description>I received one of the UPS e-mails on Tuesday, and today I received a similar e-mail proporting to be from Delta Airlines.  It also has a .zip attachment ( E-ticket_N7399294.zip) and says:
Good day,
Thank you for using our new service &quot;Buy flight ticket Online&quot; on our website.
Your account has been created:

Your login: Assistant
Your password: passUTNH

Your credit card has been charged for $434.62.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!
Attached to this message is the purchase Invoice and the airplane ticket.
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
Celeste Humphrey
Delta Air Lines</description>
		<content:encoded><![CDATA[<p>I received one of the UPS e-mails on Tuesday, and today I received a similar e-mail proporting to be from Delta Airlines.  It also has a .zip attachment ( E-ticket_N7399294.zip) and says:<br />
Good day,<br />
Thank you for using our new service &#8220;Buy flight ticket Online&#8221; on our website.<br />
Your account has been created:</p>
<p>Your login: Assistant<br />
Your password: passUTNH</p>
<p>Your credit card has been charged for $434.62.<br />
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!<br />
Attached to this message is the purchase Invoice and the airplane ticket.<br />
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!</p>
<p>Kind regards,<br />
Celeste Humphrey<br />
Delta Air Lines</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: User</title>
		<link>http://blogs.mcafee.com/mcafee-labs/fake-invoice-spam-carries-malware/comment-page-1#comment-18506</link>
		<dc:creator>User</dc:creator>
		<pubDate>Fri, 25 Jul 2008 11:10:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=696#comment-18506</guid>
		<description>AVERT were pretty slow with providing detections for these new variants. Any chance you can speed things up?</description>
		<content:encoded><![CDATA[<p>AVERT were pretty slow with providing detections for these new variants. Any chance you can speed things up?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

