<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Spamvertised American Airlines themed emails lead to Black Hole exploit kit</title>
	<atom:link href="http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/</link>
	<description>WEBROOT - INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS</description>
	<lastBuildDate>Fri, 17 May 2013 20:44:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: &#8216;Your Kindle e-book Amazon receipt&#8217; themed emails lead to Black Hole Exploit Kit &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/#comment-114839</link>
		<dc:creator><![CDATA[&#8216;Your Kindle e-book Amazon receipt&#8217; themed emails lead to Black Hole Exploit Kit &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World]]></dc:creator>
		<pubDate>Tue, 05 Feb 2013 07:01:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=7335#comment-114839</guid>
		<description><![CDATA[[...] Spamvertised American Airlines themed emails lead to Black Hole exploit kit [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Spamvertised American Airlines themed emails lead to Black Hole exploit kit [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogus IRS &#8216;Your tax return appeal is declined&#8217; themed emails lead to malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/#comment-86325</link>
		<dc:creator><![CDATA[Bogus IRS &#8216;Your tax return appeal is declined&#8217; themed emails lead to malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World]]></dc:creator>
		<pubDate>Mon, 19 Nov 2012 07:01:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=7335#comment-86325</guid>
		<description><![CDATA[[...] Your Transaction is Aborted’ themed emails serve client-side exploits and malware&#8220;; &#8220;Spamvertised American Airlines themed emails lead to Black Hole exploit kit&#8221; malicious campaigns, indicating that these have all been launched by the same [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Your Transaction is Aborted’ themed emails serve client-side exploits and malware&#8220;; &#8220;Spamvertised American Airlines themed emails lead to Black Hole exploit kit&#8221; malicious campaigns, indicating that these have all been launched by the same [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#8216;American Express Alert: Your Transaction is Aborted&#8217; themed emails serve client-side exploits and malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World</title>
		<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/#comment-84384</link>
		<dc:creator><![CDATA[&#8216;American Express Alert: Your Transaction is Aborted&#8217; themed emails serve client-side exploits and malware &#171; Webroot Threat Blog &#8211; Internet Security Threat Updates from Around the World]]></dc:creator>
		<pubDate>Mon, 12 Nov 2012 07:02:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=7335#comment-84384</guid>
		<description><![CDATA[[...] The last time we came across this IP (210.56.23.100), was in July 2012&#8242;s analysis of yet another malicious campaign, this time impersonating American Airlines. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] The last time we came across this IP (210.56.23.100), was in July 2012&#8242;s analysis of yet another malicious campaign, this time impersonating American Airlines. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cybercriminals spamvertise bogus greeting cards, serve exploits and malware &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/#comment-68525</link>
		<dc:creator><![CDATA[Cybercriminals spamvertise bogus greeting cards, serve exploits and malware &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Tue, 21 Aug 2012 21:29:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=7335#comment-68525</guid>
		<description><![CDATA[[...] The second sample phones back to 87.204.199.100:8080/mx5/B/in/ not surprisingly, we&#8217;ve already seen this command and control server used in numerous profiled campaigns, such as, for instance, the AT&amp;T Billing Center impersonation one, the Craigslist spam campaign, the PayPal spam campaign, the eBay spam campaign, and the American Airlines themed spam campaign. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] The second sample phones back to 87.204.199.100:8080/mx5/B/in/ not surprisingly, we&#8217;ve already seen this command and control server used in numerous profiled campaigns, such as, for instance, the AT&amp;T Billing Center impersonation one, the Craigslist spam campaign, the PayPal spam campaign, the eBay spam campaign, and the American Airlines themed spam campaign. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cybercriminals impersonate AT&#38;T&#8217;s Billing Service, serve exploits and malware &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/#comment-66544</link>
		<dc:creator><![CDATA[Cybercriminals impersonate AT&#38;T&#8217;s Billing Service, serve exploits and malware &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Fri, 10 Aug 2012 17:31:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=7335#comment-66544</guid>
		<description><![CDATA[[...] Once executed, the sample phones back to hxxp://87.204.199.100:8080/mx5/B/in/. We&#8217;ve already seen the same command and control served used in several malware-serving campaigns, namely, the Craigslist spam campaign, the PayPal spam campaign, the eBay spam campaign, and the American Airlines themed spam campaign. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Once executed, the sample phones back to hxxp://87.204.199.100:8080/mx5/B/in/. We&#8217;ve already seen the same command and control served used in several malware-serving campaigns, namely, the Craigslist spam campaign, the PayPal spam campaign, the eBay spam campaign, and the American Airlines themed spam campaign. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spamvertised &#8216;PayPal has sent you a bank transfer&#8217; themed emails lead to Black Hole exploit kit &#171; Webroot Threat Blog</title>
		<link>http://blog.webroot.com/2012/07/13/spamvertised-american-airlines-themed-emails-lead-to-black-hole-exploit-kit/#comment-64974</link>
		<dc:creator><![CDATA[Spamvertised &#8216;PayPal has sent you a bank transfer&#8217; themed emails lead to Black Hole exploit kit &#171; Webroot Threat Blog]]></dc:creator>
		<pubDate>Thu, 02 Aug 2012 17:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=7335#comment-64974</guid>
		<description><![CDATA[[...] execution the sample phones back to a well known command and control server - 87.204.199.100/mx5/B/in/ which we&#8217;ve already seen in several previously profiled [...]]]></description>
		<content:encoded><![CDATA[<p>[...] execution the sample phones back to a well known command and control server - 87.204.199.100/mx5/B/in/ which we&#8217;ve already seen in several previously profiled [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
