<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DecaTech Solutions News &#187; Warning</title>
	<atom:link href="http://blog.decatech.com/category/warning/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.decatech.com</link>
	<description></description>
	<lastBuildDate>Wed, 30 Jun 2010 18:29:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>WARNING: &#8220;setting for your mailbox are changed&#8221; email is a fake</title>
		<link>http://blog.decatech.com/2010/warning-setting-for-your-mailbox-are-changed-email-is-a-fake/</link>
		<comments>http://blog.decatech.com/2010/warning-setting-for-your-mailbox-are-changed-email-is-a-fake/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 15:40:20 +0000</pubDate>
		<dc:creator>aswitzer</dc:creator>
				<category><![CDATA[Warning]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://blog.decatech.com/?p=79</guid>
		<description><![CDATA[It has come to our attention that a new &#8220;fake&#8221; email that appears to be coming from DecaTech is being generated for some domains as of today. The email comes with a PDF attachment and is typically using a from address of your own domain, which is unfortunately easy to fake and nothing that we [...]]]></description>
			<content:encoded><![CDATA[<p>It has come to our attention that a new &#8220;fake&#8221; email that appears to be coming from DecaTech is being generated for some domains as of today. The email comes with a PDF attachment and is typically using a from address of your own domain, which is unfortunately easy to fake and nothing that we can do about that.</p>
<p>The PDF itself does not appear to contain any known viruses, nor does it actually contain any actual information. It appears that the spammer or phisher is currently in an &#8220;experimenting&#8221; phase.</p>
<p>As with any email of this nature, please feel free to contact DecaTech for assitance before making any suspicious changes or responding to something like this online. </p>
<p><strong>UPDATE:</strong> I&#8217;ve found out that the PDF does actually contain an embedded payload &#8211; DO NOT OPEN IT!</p>
<p>More info, from another forum I found this morning:</p>
<p>The PDF contains an embedded payload of two vbs scripts. The second of the two vbs scripts calls a fso.OpenTextFile and writes a stream from an array defined within the vbs file. The file game.exe is created and then called from the vbs.</p>
<p>The file c:\program files\Microsoft Common\svchost.exe is then created and the following regkey is added:<br />
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]<br />
&#8220;Debugger&#8221;=&#8221;C:\\Program Files\\Microsoft Common\\svchost.exe&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.decatech.com/2010/warning-setting-for-your-mailbox-are-changed-email-is-a-fake/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WARNING: Phishing/Malware Attack via Email</title>
		<link>http://blog.decatech.com/2009/warning-phishingmalware-attack-via-email/</link>
		<comments>http://blog.decatech.com/2009/warning-phishingmalware-attack-via-email/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 01:16:54 +0000</pubDate>
		<dc:creator>aswitzer</dc:creator>
				<category><![CDATA[Warning]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://blog.decatech.com/?p=53</guid>
		<description><![CDATA[It has come to our attention that some DecaTech Clients are receiving the following message via email this week: Subject: Attention &#8211; Mail Server Upgrade Attention! On October 30, 2009 server upgrade will take place. Due to this the system may be offline for approximately half an hour. The changes will concern security, reliability and [...]]]></description>
			<content:encoded><![CDATA[<p>It has come to our attention that some DecaTech Clients are receiving the following message via email this week:</p>
<blockquote><p>Subject: Attention &#8211; Mail Server Upgrade</p>
<p>Attention!</p>
<p>On October 30, 2009 server upgrade will take place. Due to this the system may be offline for approximately half an hour.<br />
The changes will concern security, reliability and performance of mail service and the system as a whole.<br />
For compatibility of your browsers and mail clients with upgraded server software you should run SSl certificates update procedure.<br />
This procedure is quite simple. All you have to do is just to click the link provided, to save the patch file and then to run it from your computer location. That&#8217;s all.</p>
<p><a href="http://updates.yourdomain.com.secure.mail-admins.bogus/mail/id=717904896791-email@yourdomain.com-patch882.aspx" target="_blank">http://updates.yourdomain.com.secure.mail-admins.net/mail/id=717904896791-email@yourdomain.com-patch882.aspx</a></p>
<p>Thank you in advance for your attention to this matter and sorry for possible inconveniences.</p>
<p>System Administrator</p></blockquote>
<p>Please note that this message is definitely <strong>NOT</strong> from DecaTech Solutions, and most likely contains malware that can harm your computer.</p>
<p>If you ever receive a message like this and question its intentions in any way &#8211; feel free to contact <a title="DecaTech Support" href="http://decatech.com/contact">DecaTech Support</a> and we&#8217;ll be happy to help.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.decatech.com/2009/warning-phishingmalware-attack-via-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WARNING: Emails appear to be from Network Solutions</title>
		<link>http://blog.decatech.com/2008/warning-emails-appear-to-be-from-network-solutions/</link>
		<comments>http://blog.decatech.com/2008/warning-emails-appear-to-be-from-network-solutions/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 08:32:18 +0000</pubDate>
		<dc:creator>aswitzer</dc:creator>
				<category><![CDATA[Warning]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://blog.decatech.com/?p=19</guid>
		<description><![CDATA[Phishing is a type of deception on the internet designed to steal your valuable personal data, such as credit card numbers, passwords, and account data. Phishing as a type of online scam has been around for a few years. Unfortunately, the scammers have continued to get more sophisticated, making it tougher to determine when an [...]]]></description>
			<content:encoded><![CDATA[<p>Phishing is a type of deception on the internet designed to steal your valuable personal data, such as credit card numbers, passwords, and account data.</p>
<p>Phishing as a type of online scam has been around for a few years. Unfortunately, the scammers have continued to get more sophisticated, making it tougher to determine when an email is real and when it is a phishing attempt.</p>
<p>Several clients have received email messages with subjects like &#8220;<em>Please, renew your domain</em>&#8221; and &#8220;<em>Inaccurate </em><span class="nfakPe"><em>whois</em></span><em> informatio</em><em>n</em>&#8221; or even the urgent sounding &#8220;<em>Your domains will be deleted soon</em>&#8221; that appear to be from Network Solutions or some other well known domain registrar. The From Address looks valid, the email appears to have a legitimate request, and the link in it appears to go directly to www.networksolutions.com.</p>
<p><strong>Don&#8217;t be fooled!</strong></p>
<p>In a phishing email, the scammer can easily use HTML to make a link appear to be valid when the link actually goes somewhere different. In most recent cases, the scammer simply adds &#8220;www.networksolutions.com&#8221; as a subdomain for their own domain so that &#8220;www.networksolutions.com.scammer123.com&#8221; shows *their* phishing page. On that page they make it look like you are logging into your Network Solutions account when they are actually capturing your account information so that they can use it against you.</p>
<p>One way to detect these phishing emails and their bogus links is to hover your mouse over the link before clicking.</p>
<p>The best way to avoid these phishing attempts is to not click on the links &#8211; type in the URL into your browser yourself. You can also forward a suspicous email about your domain to support @decatech.com and we&#8217;d be happy to help you diagnose the request.</p>
<p>DecaTech Solutions &#8211; Helping you Stay Safe Online</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.decatech.com/2008/warning-emails-appear-to-be-from-network-solutions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
