<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Spam on Omid Farhang</title><link>https://omid.dev/tags/spam/</link><description>Recent content in Spam on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.165.0</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Thu, 19 Jul 2012 23:00:00 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/spam/index.xml" rel="self" type="application/rss+xml"/><atom:link href="https://pubsubhubbub.appspot.com/" rel="hub"/><item><title>Security researchers take out botnet responsible for 18 billion spam emails a day</title><link>https://omid.dev/2012/07/19/security-researchers-take-out-botnet-responsible-for-18-billion-spam-emails-a-day/</link><pubDate>Thu, 19 Jul 2012 23:00:00 +0000</pubDate><guid>https://omid.dev/2012/07/19/security-researchers-take-out-botnet-responsible-for-18-billion-spam-emails-a-day/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-N9STBulhiHw/UAiKWOJglHI/AAAAAAAAGhI/hPNE0ZwAHoc/s1600-h/mail-spam%25255B3%25255D.jpg" alt="mail-spam" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.independent.co.uk/life-style/gadgets-and-tech/news/security-researchers-take-out-botnet-responsible-for-18-billion-spam-emails-a-day-7959463.html"&gt;Independent&lt;/a&gt;: If you&amp;rsquo;re a fan of fake Rolex watches and cheap Viagra look away now.&lt;/p&gt;
&lt;p&gt;A huge spam botnet responsible for an estimated 18 billion messages a day has been taken out by security researchers.&lt;/p&gt;
&lt;p&gt;The four year old botnet – known as Grum – is believed to have been responsible for around 18% of the world&amp;rsquo;s spam emails.&lt;/p&gt;
&lt;p&gt;A botnet is a cluster of infected computers used by cybercriminals to send a variety of spam emails – often offering cheap Viagra, fake watches or unusual dating solutions.&lt;/p&gt;</description></item><item><title>Fake Facebook Photo Notifications Contain Malware</title><link>https://omid.dev/2012/07/19/fake-facebook-photo-notifications-contain-malware/</link><pubDate>Thu, 19 Jul 2012 09:25:00 +0000</pubDate><guid>https://omid.dev/2012/07/19/fake-facebook-photo-notifications-contain-malware/</guid><description>&lt;p&gt;Mashable: Sophos’s &lt;a href="http://nakedsecurity.sophos.com/2012/07/17/malware-facebook-photo-tag-notification/"&gt;NakedSecurity blog&lt;/a&gt; outlined the threat on Wednesday. The company’s SophosLabs intercepted a “spammed-out email campaign” which was designed to spread malware. Sophos provided the following example:&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-RQCy-TZ9Y9w/UAfLV4rz6-I/AAAAAAAAGfs/T1ql0bleaRw/s1600-h/facebook-malware-email%25255B16%25255D.jpg" alt="facebook-malware-email" /&gt;
&lt;/p&gt;
&lt;p&gt;The blog notes that the email address above misspells “Facebook” as “Faceboook.” The link takes the user to a malicious iFrame script, which exposes the user’s computer to malware. However, within four seconds, the user’s browser is directed to a presumably innocent Facebook page like the one below to act as a smokescreen.&lt;/p&gt;</description></item><item><title>Spam attack on Dropbox users</title><link>https://omid.dev/2012/07/19/spam-attack-on-dropbox-users/</link><pubDate>Thu, 19 Jul 2012 07:29:00 +0000</pubDate><guid>https://omid.dev/2012/07/19/spam-attack-on-dropbox-users/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-WeghfryhxuA/UAewOKj1QVI/AAAAAAAAGfU/V0Bq_7T5_U0/s1600-h/Dropbox_logo_120%25255B2%25255D.png" alt="Dropbox_logo_120" /&gt;
&lt;/p&gt;
&lt;p&gt;H-Online: Spammers are currently sending large volumes of spam to users of cloud storage service provider &lt;a href="https://www.dropbox.com/"&gt;Dropbox&lt;/a&gt;. The H&amp;rsquo;s associates at heise Security have so far received four different pieces of German-language spam at an email address used solely to register with Dropbox, and some of their readers have reported the same problem; &lt;a href="http://forums.dropbox.com/topic.php?id=64367"&gt;similar reports&lt;/a&gt; can also be found on the Dropbox forums. In almost all cases, the spam is for suspicious-looking online casinos.&lt;/p&gt;</description></item><item><title>‘Botnet' sends out spam as malware spreads on Android phones: researcher</title><link>https://omid.dev/2012/07/15/botnet-sends-out-spam-as-malware-spreads-on-android-phones-researcher/</link><pubDate>Sun, 15 Jul 2012 18:04:00 +0000</pubDate><guid>https://omid.dev/2012/07/15/botnet-sends-out-spam-as-malware-spreads-on-android-phones-researcher/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-jSrDMxu2nos/UAL_EEkwBzI/AAAAAAAAGcc/_aSefCvLS1I/s1600-h/pt_948_6394_o%25255B4%25255D.jpg" alt="pt_948_6394_o" /&gt;
&lt;/p&gt;
&lt;p&gt;Malware has been spreading on Android mobile phones that takes control of certain email accounts to create a “botnet” to send out spam, a security researcher says.&lt;/p&gt;
&lt;p&gt;Microsoft security engineer Terry Zink says the malware has infected phones of users&amp;rsquo; Yahoo email accounts to send out spam messages.&lt;/p&gt;
&lt;p&gt;“We&amp;rsquo;ve all heard the rumors, but this is the first time I have seen it – a spammer has control of a botnet that lives on Android devices,” Zink said in a blog post on Tuesday.&lt;/p&gt;</description></item><item><title>Automated Skype calls and Fake Antiviruses</title><link>https://omid.dev/2012/06/03/automated-skype-calls-and-fake-antiviruses/</link><pubDate>Sun, 03 Jun 2012 15:47:00 +0000</pubDate><guid>https://omid.dev/2012/06/03/automated-skype-calls-and-fake-antiviruses/</guid><description>&lt;p&gt;This is an old story back from September, 2011, but since recently I’ve seen users complaining about this, I want to share it again [Credit to &lt;a href="http://nakedsecurity.sophos.com/2011/09/19/automated-skype-calls-spread-fake-anti-virus-warning-video"&gt;NakedSecurity&lt;/a&gt;, SophoLabs]:&lt;/p&gt;
&lt;p&gt;You may have received an automated call from a user who claim to be from Skype or somewhere which says:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Attention: this is an automated computer system alert. Your computer protection service is not active. To activate computer protection, and repair your computer, go to [LINK]&lt;/p&gt;</description></item><item><title>Hackers use fake Facebook cancellation emails to deploy malware</title><link>https://omid.dev/2012/05/23/hackers-use-fake-facebook-cancellation-emails-to-deploy-malware/</link><pubDate>Wed, 23 May 2012 12:34:00 +0000</pubDate><guid>https://omid.dev/2012/05/23/hackers-use-fake-facebook-cancellation-emails-to-deploy-malware/</guid><description>&lt;p&gt;H-Online: &lt;img loading="lazy" src="http://lh3.ggpht.com/-83fs6E3Xo80/T7zSTz3zoOI/AAAAAAAAGD0/XtYmc3fkomg/s1600-h/fb-malware%25255B2%25255D.jpg" alt="fb-malware" /&gt;
A new type of phishing strategy, which aims to trick unsuspecting users into installing a trojan by pretending to be an account cancellation request from Facebook, has been &lt;a href="http://nakedsecurity.sophos.com/2012/05/21/facebook-account-cancellation-malware-adobe-flash-update/"&gt;discovered by Sophos&lt;/a&gt;. The email messages link to a third party application on the site that will install a Java applet and then prompt the user to update their Flash player, but will actually deliver the trojan malware.&lt;/p&gt;
&lt;p&gt;The email messages that are sent out claim to be from Facebook and state: “We are sending you this email to inform you that we have received an account cancellation request from you.” However, Facebook never sends such account cancellation confirmation messages via email. Users who want to cancel their Facebook account can do so by visiting &lt;a href="https://www.facebook.com/deactivate.php"&gt;facebook.com/deactivate.php&lt;/a&gt; to deactivate their account; they may later delete it after a cool down period has passed.&lt;/p&gt;</description></item><item><title>Phishers Offer Fake Storage Upgrades</title><link>https://omid.dev/2012/05/03/phishers-offer-fake-storage-upgrades/</link><pubDate>Thu, 03 May 2012 11:20:00 +0000</pubDate><guid>https://omid.dev/2012/05/03/phishers-offer-fake-storage-upgrades/</guid><description>&lt;p&gt;Symantec Connect: Customers of popular email service providers have been a common target for phishers for identity theft purposes. Phishers are constantly devising new phishing bait strategies in the hope of stealing user email addresses and passwords. In April 2012, Symantec observed phishing pages that mimicked popular email services in an attempt to dupe users with attractive storage plans.&lt;/p&gt;
&lt;p&gt;Customers were flooded with fake offers of free additional storage space for services such as email, online photo albums, and documents. In the first example, the phishing site was titled “Welcome to New [BRAND NAME] Quota Verification Page”. According to the bogus offer, the additional storage plan ranged from 20 GB to 1 TB per year, at no extra cost. The phishing page boasted that the free additional storage plan will help customers prevent loss of data and the inability to send and receive emails due to exhausted storage space. It also stated that the plan will auto-renew each year and the customer can choose to cancel at any time by returning to the same page:&lt;/p&gt;</description></item><item><title>WikiPharmacy? Fake Notifications Spammed Out</title><link>https://omid.dev/2012/04/26/wikipharmacy-fake-notifications-spammed-out/</link><pubDate>Thu, 26 Apr 2012 15:03:00 +0000</pubDate><guid>https://omid.dev/2012/04/26/wikipharmacy-fake-notifications-spammed-out/</guid><description>&lt;p&gt;Symantec Connect: Symantec is intercepting a resurgence of spam attacks on popular brands. Spam messages that are replicas of the Wikipedia email address confirmation alert are the new vector for the present. The said spam messages pretend to be originating from Wikipedia, and are selling meds, with the following subject line: “&lt;em&gt;Subject:&lt;/em&gt; &lt;em&gt;Wikipedia e-mail address confirmation&lt;/em&gt;”.&lt;/p&gt;
&lt;p&gt;The spoofed Wikipedia page is a ploy to give legitimacy to the sale of meds online. The embedded URL in the message navigates to a fake online pharmacy site that is dressed up as a Wikipedia Web page. Furthermore, to give the email a legitimate look, the spammer has added the recipient’s IP address in the body of the spam mail. Needless to say this IP does not belong to the user.&lt;/p&gt;</description></item><item><title>IMG0893.zip – Your photo all over Facebook? Naked? Malware campaign spammed out</title><link>https://omid.dev/2012/04/23/img0893-zip-your-photo-all-over-facebook-naked-malware-campaign-spammed-out/</link><pubDate>Mon, 23 Apr 2012 19:02:00 +0000</pubDate><guid>https://omid.dev/2012/04/23/img0893-zip-your-photo-all-over-facebook-naked-malware-campaign-spammed-out/</guid><description>&lt;p&gt;SophosLabs is intercepting a spammed-out malware campaign, pretending to be an email about a revealing photo posted online of the recipient.&lt;/p&gt;
&lt;p&gt;The emails, which have a variety of subject lines and message bodies, arrive with an attached ZIP file (IMG0893.zip) which contains a Trojan horse.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-H3uvM3Y1geA/T5WgOdzbVfI/AAAAAAAAFnI/abKuy2zMXBw/s1600-h/malware-email%25255B5%25255D.jpg" alt="malware-email" /&gt;
&lt;/p&gt;
&lt;p&gt;Subject lines used in the spammed-out malware campaign include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;RE:Check the attachment you have to react somehow to this picture&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;FW:Check the attachment you have to react somehow to this picture&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;RE:You HAVE to check this photo in attachment man&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;RE:They killed your privacy man your photo is all over facebook! NAKED!&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;RE:Why did you put this photo online?&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/-yIb1NiPeb3Q/T5WgTBvjJyI/AAAAAAAAFnY/S1p6DOsOh6s/s1600-h/bredo-w-subjects%25255B4%25255D.jpg" alt="bredo-w-subjects" /&gt;
&lt;/p&gt;</description></item><item><title>Free Stuff on Social Networks Not Free</title><link>https://omid.dev/2012/03/29/free-stuff-on-social-networks-not-free/</link><pubDate>Thu, 29 Mar 2012 15:22:00 +0000</pubDate><guid>https://omid.dev/2012/03/29/free-stuff-on-social-networks-not-free/</guid><description>&lt;p&gt;&lt;strong&gt;Symantec Connect:&lt;/strong&gt; In recent years, scammers have flocked towards social networking sites as they have grown and made it easier to access a large number of potential eyeballs to convert into dollars. Brands have found value in leveraging social media to know what their customers are talking about, so, naturally, scammers are doing the exact same thing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Free iPads and iPhones&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every time Apple unveils a new iPad or iPhone, you can bet there are scammers out there trying to leverage the announcement for financial gain. In the days leading up to and after the announcement of the new third-generation iPad, Twitter users who tweet about the new tablet most likely will receive some targeted Twitter replies from scammers offering the new device for free:&lt;/p&gt;</description></item><item><title>New Dr Who girl Jenna-Louise Coleman's name exploited by Twitter sex video scammers</title><link>https://omid.dev/2012/03/22/new-dr-who-girl-jenna-louise-colemans-name-exploited-by-twitter-sex-video-scammers/</link><pubDate>Thu, 22 Mar 2012 12:41:00 +0000</pubDate><guid>https://omid.dev/2012/03/22/new-dr-who-girl-jenna-louise-colemans-name-exploited-by-twitter-sex-video-scammers/</guid><description>&lt;p&gt;&lt;strong&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-4R_qoXYPEg0/T2sWSJKkEQI/AAAAAAAAFQU/0hxqWkAqlnE/s1600-h/jenna-louise-coleman-170%25255B2%25255D.jpg" alt="jenna-louise-coleman-170" /&gt;
SophosLabs:&lt;/strong&gt; Jenna-Louise Coleman has been &lt;a href="http://www.bbc.co.uk/news/entertainment-arts-17456505"&gt;unveiled&lt;/a&gt; as the new “Doctor Who” companion, joining the BBC TV time traveller in his TARDIS later this year.&lt;/p&gt;
&lt;p&gt;“Doctor Who” is one of Britain&amp;rsquo;s biggest television shows, and is popular elsewhere around the world, so it was no surprise to find 25-year-old actress Jenna Louise-Coleman&amp;rsquo;s name was a trending topic on Twitter today.&lt;/p&gt;
&lt;p&gt;Unfortunately, there are frequently mischief-makers, scammers and cybercriminals waiting to exploit a popular search term or hashtag.&lt;/p&gt;</description></item><item><title>Apple's new iPad is great, but it's not free, nor called iPad 3</title><link>https://omid.dev/2012/03/19/apples-new-ipad-is-great-but-its-not-free-nor-called-ipad-3/</link><pubDate>Mon, 19 Mar 2012 08:37:00 +0000</pubDate><guid>https://omid.dev/2012/03/19/apples-new-ipad-is-great-but-its-not-free-nor-called-ipad-3/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-OCerIHzzAAk/T2bovG67GDI/AAAAAAAAFMw/iFDhVV_IIgs/s1600-h/newipad%25255B2%25255D.png" alt="newipad" /&gt;
&lt;/p&gt;
&lt;p&gt;SophosLabs: Only hours after the launch of Apple&amp;rsquo;s newest iPad we are beginning to see spammers trying to use the excitement over its release to ensnare innocent people into their scams.&lt;/p&gt;
&lt;p&gt;The scammers are sending out emails with the subject “Where do we send your Free iPad 3, just Test &amp;amp; Keep! See details”. The email contains an image with the text “TEST &amp;amp; KEEP an iPad 3 FREE – Click here”.&lt;/p&gt;</description></item><item><title>This time, the bad guys want your tax accountant</title><link>https://omid.dev/2012/03/09/this-time-the-bad-guys-want-your-tax-accountant/</link><pubDate>Fri, 09 Mar 2012 21:21:00 +0000</pubDate><guid>https://omid.dev/2012/03/09/this-time-the-bad-guys-want-your-tax-accountant/</guid><description>&lt;p&gt;&lt;strong&gt;avast:&lt;/strong&gt; While taxpayers are the regular target of springtime malware schemes, this year the bad guys are aiming for the accountants.&lt;/p&gt;
&lt;p&gt;A series of imposter emails are threatening recipients with the removal of their professional accreditation if they fail to respond promptly. The tax-phish appear to be from organizations such as the &lt;a href="http://www.aicpa.org/"&gt;American Institute of Certified Public Accountants(AICPA)&lt;/a&gt;, &lt;a href="http://www.bbb.org/"&gt;Better Business Bureau(BBB)&lt;/a&gt;, and &lt;a href="http://www.intuit.com/"&gt;Intuit&lt;/a&gt; tax services.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-ahJwab1csoE/T1ps-GcJVYI/AAAAAAAAFGg/BvJIW2nto4I/s1600-h/tax_mail_01-2-294x300%25255B3%25255D.jpg" alt="tax_mail_01-2-294x300" /&gt;
&lt;/p&gt;
&lt;p&gt;After clicking on the email, users are redirected through a hacked legitimate site to the final malware distribution center where their computer can download fake antivirus or another malware package selected by the bad guys.&lt;/p&gt;</description></item><item><title>Dropbox Abused by Spammers</title><link>https://omid.dev/2012/03/08/dropbox-abused-by-spammers/</link><pubDate>Thu, 08 Mar 2012 11:55:00 +0000</pubDate><guid>https://omid.dev/2012/03/08/dropbox-abused-by-spammers/</guid><description>&lt;p&gt;&lt;strong&gt;Symantec Connect:&lt;/strong&gt; Recently we noticed spammers abusing Dropbox, a popular cloud-based, file-hosting and synchronization tool, to spread spam.&lt;/p&gt;
&lt;p&gt;Dropbox accounts have a public folder where files can be placed and made publicly available. This function is useful to spammers, as it effectively turns Dropbox into a free hosting site. Spammers have abused URL shortening and free hosting sites for some time. Dropbox also provides a URL shortening service, which spammers have also abused.&lt;/p&gt;</description></item><item><title>Google opens a pharmacy? It's spam of the day</title><link>https://omid.dev/2012/03/08/google-opens-a-pharmacy-its-spam-of-the-day/</link><pubDate>Thu, 08 Mar 2012 11:46:00 +0000</pubDate><guid>https://omid.dev/2012/03/08/google-opens-a-pharmacy-its-spam-of-the-day/</guid><description>&lt;p&gt;&lt;strong&gt;SophosLabs:&lt;/strong&gt; Is Google really extending its online empire, and opening an online pharmacy?&lt;/p&gt;
&lt;p&gt;Of course not. So don&amp;rsquo;t believe spammed-out emails like the following:&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-jHE3KlgernQ/T1iUyBzHoRI/AAAAAAAAFFA/wjDZT7I6E7Q/s1600-h/google-pharmacy-spam%25255B4%25255D.jpg" alt="google-pharmacy-spam" /&gt;
&lt;/p&gt;
&lt;p&gt;Do you notice how the spammers have changed the “o”s in Google to Cialis and Viagra tablets? Very creative.&lt;/p&gt;
&lt;p&gt;Part of the spam message reads as follows:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;We've just launched a pharmaceutical interfaces for Google, as well as several new features that will improve the Google experience for the people buying pills and using pharmaceutical interfaces.&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Free iPad 3? It doesn't exist! Beware of scams</title><link>https://omid.dev/2012/03/01/free-ipad-3-it-doesnt-exist-beware-of-scams/</link><pubDate>Thu, 01 Mar 2012 07:41:00 +0000</pubDate><guid>https://omid.dev/2012/03/01/free-ipad-3-it-doesnt-exist-beware-of-scams/</guid><description>&lt;p&gt;It is &lt;a href="http://www.bbc.co.uk/news/technology-17198049"&gt;widely anticipated&lt;/a&gt; that Apple will announce a new version of its iPad tablet computer in San Francisco on March 7th.&lt;/p&gt;
&lt;p&gt;An invitation sent to journalists, inviting them to an event organized by Apple, has fueled speculation even further as it appears to show a close-up of someone using an iPad.&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/-WJ38sO49Lr8/T08gi5kgyXI/AAAAAAAAFAU/4Fzt9bVjDaU/s1600-h/ipad-3-teaser%25255B6%25255D.jpg" alt="ipad-3-teaser" /&gt;
&lt;/p&gt;
&lt;p&gt;Could it be the new iPad with a much lusted for improved display and souped-up processor? Only time will tell..&lt;/p&gt;</description></item><item><title>Oops! Selena and Bieber's hidden camera bedroom video Facebook scam</title><link>https://omid.dev/2012/02/28/oops-selena-and-biebers-hidden-camera-bedroom-video-facebook-scam/</link><pubDate>Tue, 28 Feb 2012 21:00:00 +0000</pubDate><guid>https://omid.dev/2012/02/28/oops-selena-and-biebers-hidden-camera-bedroom-video-facebook-scam/</guid><description>&lt;p&gt;Oops indeed. At least if you were one of the Facebook users who believed that a hidden camera video had leaked onto the net of Justin Bieber sharing some intimate moments with his girlfriend Selena Gomez.&lt;/p&gt;
&lt;p&gt;Of course, Bieber&amp;rsquo;s typical fans – or those who would delight in his public humiliation by a hungry paparazzi – are probably unlikely to think twice about clicking on a link shared with them by their Facebook friends, claiming to leak to a sex video.&lt;/p&gt;</description></item><item><title>Beatles for Sale? It's spam of the day</title><link>https://omid.dev/2012/02/27/beatles-for-sale-its-spam-of-the-day/</link><pubDate>Mon, 27 Feb 2012 14:54:00 +0000</pubDate><guid>https://omid.dev/2012/02/27/beatles-for-sale-its-spam-of-the-day/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="http://lh6.ggpht.com/-cqy7RKTDxdg/T0uRt1N_JXI/AAAAAAAAE-g/0liQmX2uRoM/s1600-h/beatles-170%25255B2%25255D.jpg" alt="beatles-170" /&gt;
&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve owned up to some of the great loves of my life in the past.&lt;/p&gt;
&lt;p&gt;For instance, I&amp;rsquo;m a &lt;a href="http://www.last.fm/user/omidfarhang"&gt;music lover&lt;/a&gt; and I&amp;rsquo;m very partial to board games (even during a denial-of-service attack).&lt;/p&gt;
&lt;p&gt;Today I can also share that I like The Beatles. In particular, anything from “Rubber Soul” and later when the “Yeah yeah yeah” turned into something rather more “Yeah man. Dig it”.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve simply never come across a more talented combination of musicianship and songwriting abilities – for me, you can kick The Stones, The Who, Cream and.. yes.. even MeatLoaf to the kerb, as Lennon, McCartney, Harrison and Starr are the guv&amp;rsquo;nors.&lt;/p&gt;</description></item><item><title>Fake AICPA Mail Serves Blackholes and Rootkits</title><link>https://omid.dev/2012/02/21/fake-aicpa-mail-serves-blackholes-and-rootkits/</link><pubDate>Tue, 21 Feb 2012 20:29:00 +0000</pubDate><guid>https://omid.dev/2012/02/21/fake-aicpa-mail-serves-blackholes-and-rootkits/</guid><description>&lt;p&gt;&lt;strong&gt;Sunbelt:&lt;/strong&gt; Be wary of emails claiming to be from AICPA – as per their alert &lt;a href="http://www.aicpa.org/News/FeaturedNews/Pages/alert-fraudulent-email.aspx"&gt;here&lt;/a&gt;, these are not real and any mention of “unlawful tax return fraud” is just a bait to convince the end-user to open up a malicious attachment (in this case, a .doc file although there are rogue PDF files in circulation too).&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-BT0lPZFhSho/T0P3SFbgmkI/AAAAAAAAE7Y/ZMG7VbhiSM4/s1600-h/aicpaexploitmails%25255B3%25255D.jpg" alt="aicpaexploitmails" /&gt;
&lt;/p&gt;
&lt;p&gt;As with many of the malicious spam campaigns doing the rounds at the moment, this one will use the Blackhole exploit kit to serve up zbot from multiple compromised domains. Worse, a Sakura kit (typical example &lt;a href="http://xylibox.blogspot.com/2012/01/sakura-exploit-pack-10.html"&gt;here&lt;/a&gt;) will download Sirefef / ZeroAccess , which as we’ve seen elsewhere is &lt;a href="http://www.cio.com/article/691811/Bing_and_Yahoo_Sponsored_Results_Lead_to_Hard_to_Remove_Rootkit"&gt;not a good thing to have on your system&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Масленица Началась, And So Is Spam!</title><link>https://omid.dev/2012/02/21/%d0%bc%d0%b0%d1%81%d0%bb%d0%b5%d0%bd%d0%b8%d1%86%d0%b0-%d0%bd%d0%b0%d1%87%d0%b0%d0%bb%d0%b0%d1%81%d1%8c-and-so-is-spam/</link><pubDate>Tue, 21 Feb 2012 19:59:00 +0000</pubDate><guid>https://omid.dev/2012/02/21/%d0%bc%d0%b0%d1%81%d0%bb%d0%b5%d0%bd%d0%b8%d1%86%d0%b0-%d0%bd%d0%b0%d1%87%d0%b0%d0%bb%d0%b0%d1%81%d1%8c-and-so-is-spam/</guid><description>&lt;p&gt;&lt;strong&gt;Symantec Connect:&lt;/strong&gt; Maslenitsa (Маслница) is a religious holiday celebrated in Russia and Ukraine during the last week before Lent, i.e. the seventh week before Pascha (Easter). This festival is also known as Pancake week or Butter week. During this week people enjoy the social activities that are forbidden during the prayerful Lenten season, such as partying, dancing etc. This year the Maslenitsa will be celebrated from February 20 to February 26.&lt;/p&gt;</description></item></channel></rss>