<?xml version="1.0" encoding="ISO-8859-1"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="pt-BR">
	<title>Pescaria</title>
	<link rel="alternate" type="text/html" href="http://www.navegantes.org/index.php?blog=9" />
	
	<id>http://www.navegantes.org/index.php?blog=9&amp;tempskin=_atom</id>
	<subtitle />
	<generator uri="http://b2evolution.net/" version="3.3.1">b2evolution</generator>
	<updated>2010-03-22T11:26:03Z</updated>
	
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Pescaria" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="pescaria" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">Pescaria</feedburner:emailServiceId><feedburner:feedburnerHostname xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">http://feedburner.google.com</feedburner:feedburnerHostname><entry>
		<title type="text">Certificado Bradesco - Golpe por e-mail</title>
		<link rel="alternate" type="text/html" href="http://www.navegantes.org/index.php/2008/03/13/certificado-bradesco-golpe-por-e-mail?blog=9" />
		<author>
			<name>Glaydson Lima</name>
					</author>
				<category term="Bancos" />
				<id>http://www.navegantes.org/index.php/2008/03/13/certificado-bradesco-golpe-por-e-mail?blog=9</id>
		<published>2008-03-13T14:27:31Z</published>		<updated>2008-03-13T14:29:59Z</updated>
				<content type="html"><![CDATA[<p>Ao pesquisar uma conta do Hotmail que uso para testes, encontrei um phishing sobre um suposto certificado do Bradesco com o seguinte conte&#250;do:</p>

<p><img src="http://www.navegantes.org/media/blogs/navegantes/trojan_bradesco.jpg" alt="" title="" width="400" height="285" /></p>

<blockquote><p>Aten&#231;&#227;o - Comunicado Importante - Atualiza&#231;&#227;o v3.3.25<br />
Banco Bradesco S/A</p>

<p>Aten&#231;&#227;o: Consta em nosso sistema uma falha na autentica&#231;&#227;o de seu certificado ocorrendo erro na atualiza&#231;&#227;o de seu</p>

<p>Certificado Digital, por favor execute novamente o arquivo de atualiza&#231;&#227;o para completar sua atualiza&#231;&#227;o. </p>

<p>Essa atualiza&#231;&#227;o &#233; de extrema import&#226;ncia para que o cliente possa continuar acessando sua(s) conta(s) normalmente.<br />
 <br />
Para realizar a atualiza&#231;&#227;o escolha uma das op&#231;&#245;es abaixo:</p>

<p><strong>[links removidos]</strong><br />
 <br />
Para realizar a atualiza&#231;&#227;o basta clicar no link acima e logo ap&#243;s em executar, feito isso aguarde alguns segundos e siga as instru&#231;&#245;es de instala&#231;&#227;o.</p></blockquote>

<p>O <a href="http://www.virustotal.com/pt/analisis/75600e752682ccdd7bd8c219da3c776a">resultado do teste sobre malwares do Virustotal</a> no arquivo <em>NetEmpresa-3.3.25.exe</em> segue abaixo (note que o Avast n&#227;o identificou como suspeito):</p>

<p><code>Antiv&#237;rus 	Vers&#227;o 	&#218;ltima Atualiza&#231;&#227;o 	Resultado<br />
AhnLab-V3 	- 	- 	-<br />
AntiVir 	- 	- 	TR/Spy.Banpaes.BL.6<br />
Authentium 	- 	- 	-<br />
Avast 	- 	- 	-<br />
AVG 	- 	- 	PSW.Banker4.VVG<br />
BitDefender 	- 	- 	Trojan.Spy.Banpaes.BL<br />
CAT-QuickHeal 	- 	- 	(Suspicious) - DNAScan<br />
ClamAV 	- 	- 	Trojan.Bancos-3784<br />
DrWeb 	- 	- 	-<br />
eSafe 	- 	- 	suspicious Trojan/Worm<br />
eTrust-Vet 	- 	- 	-<br />
Ewido 	- 	- 	-<br />
FileAdvisor 	- 	- 	-<br />
Fortinet 	- 	- 	-<br />
F-Prot 	- 	- 	W32/Banpaes.A.gen!Eldorado<br />
F-Secure 	- 	- 	Trojan-Spy.Win32.Banker.jkt<br />
Ikarus 	- 	- 	Trojan-Spy.Win32.Banker.ahy<br />
Kaspersky 	- 	- 	Trojan-Spy.Win32.Banker.jkt<br />
McAfee 	- 	- 	New Malware.n<br />
Microsoft 	- 	- 	VirTool:Win32/Obfuscator.C<br />
NOD32v2 	- 	- 	a variant of Win32/Spy.Banpaes.AS<br />
Norman 	- 	- 	W32/Suspicious_U.gen<br />
Panda 	- 	- 	Suspicious file<br />
Prevx1 	- 	- 	-<br />
Rising 	- 	- 	Trojan.Spy.Win32.Banpeas.a<br />
Sophos 	- 	- 	Mal/EncPk-BW<br />
Sunbelt 	- 	- 	-<br />
Symantec 	- 	- 	-<br />
TheHacker 	- 	- 	W32/Behav-Heuristic-060<br />
VBA32 	- 	- 	-<br />
VirusBuster 	- 	- 	Packed/Upack<br />
Webwasher-Gateway 	- 	- 	Trojan.Spy.Banpaes.BL.6</code></p>

<div class="item_footer"><p><small><a href="http://www.navegantes.org/index.php/2008/03/13/certificado-bradesco-golpe-por-e-mail?blog=9">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content>
				</entry>

	
	<entry>
		<title type="text">Polícia Civil: Nos ajude a ter mais segurança</title>
		<link rel="alternate" type="text/html" href="http://www.navegantes.org/index.php/2007/11/30/policia-civil-nos-ajude-a-ter-mais-segur?blog=9" />
		<author>
			<name>Glaydson Lima</name>
					</author>
				<category term="Governo" />
				<id>http://www.navegantes.org/index.php/2007/11/30/policia-civil-nos-ajude-a-ter-mais-segur?blog=9</id>
		<published>2007-11-30T19:51:55Z</published>		<updated>2007-11-30T19:51:55Z</updated>
				<content type="html"><![CDATA[<p>Suposto e-mail de solicita&#231;&#227;o ajuda na identifica&#231;&#227;o de procurados pela Pol&#237;cia Civil do Estado de S&#227;o Paulo instala Cavalo de Tr&#243;ia no computador. Arquivo <b>PROCURADOS.SCR</b> nocivo.</p>

<p><b>IMAGEM</b></p>

<p><img src="http://navegantes.org/media/blogs/navegantes/policia_civil_procurados.jpg" alt="Procurados" title="Procurados"/></p>

<p><b>TEXTO DO FALSO E-MAIL</b></p>

<blockquote><p>Caro cidad&#227;o<br />
Pedimos que voc&#234; perca 1 minuto do seus fazer e olhe as fotos dos ladr&#245;es, seq&#252;estradores, e traficantes mais procurados do brasil.<br />
Esse seu 1 minuto para n&#243;s ser&#225; muito importante, pois assim podemos contar com sua ajuda para trazer mais seguran&#231;a a nossa fam&#237;lia &#233; a n&#243;s mesmos.<br />
Obrigado por sua compreens&#227;o e se voc&#234; conhece alguma dessas pessoas por favor denuncie com a max&#237;ma urg&#234;ncia.</p>

<p>Procurados da Justi&#231;a </p></blockquote>

<p><b>MALWARES ENCONTRADOS</b></p>

<pre>AhnLab-V3	2007.12.1.0	2007.11.30	Win-Trojan/Banload.44544.K
AntiVir	7.6.0.34	2007.11.30	TR/Delphi.Downloader.Gen
Authentium	4.93.8	2007.11.30	Possibly a new variant of W32/Downloader-Web-based!Maximus
Avast	4.7.1074.0	2007.11.29	-
AVG	7.5.0.503	2007.11.30	-
BitDefender	7.2	2007.11.30	Trojan.Downloader.Banload.NQA
CAT-QuickHeal	9.00	2007.11.30	Trojan.Agent.boi
ClamAV	0.91.2	2007.11.30	-
DrWeb	4.44.0.09170	2007.11.30	Trojan.DownLoader.origin
eSafe	7.0.15.0	2007.11.29	-
eTrust-Vet	31.3.5338	2007.11.30	-
Ewido	4.0	2007.11.30	-
FileAdvisor	1	2007.11.30	-
Fortinet	3.14.0.0	2007.11.30	-
F-Prot	4.4.2.54	2007.11.29	W32/Downloader-Web-based!Maximus
F-Secure	6.70.13030.0	2007.11.30	W32/Downloader.DUA
Ikarus	T3.1.1.12	2007.11.30	Trojan-Downloader.Win32.Delf.ACC
Kaspersky	7.0.0.125	2007.11.30	Heur.Downloader
McAfee	5175	2007.11.30	PWS-Banker.dldr
Microsoft	1.3007	2007.11.30	TrojanDownloader:Win32/Delf.AX
NOD32v2	2696	2007.11.30	probably a variant of Win32/TrojanDownloader.Delf.ACC
Norman	5.80.02	2007.11.30	W32/Downloader.DUA
Panda	9.0.0.4	2007.11.29	Suspicious file
Prevx1	V2	2007.11.30	-
Rising	20.20.40.00	2007.11.30	Trojan.DL.Win32.Banload.bsm
Sophos	4.23.0	2007.11.30	Mal/Emogen-I
Sunbelt	2.2.907.0	2007.11.30	-
Symantec	10	2007.11.30	Downloader.Bancos
TheHacker	6.2.9.145	2007.11.30	-
VBA32	3.12.2.5	2007.11.30	suspected of Win32.Trojan.Downloader (http://...)
VirusBuster	4.3.26:9	2007.11.30	-
Webwasher-Gateway	6.6.2	2007.11.30	Trojan.Delphi.Downloader.Gen</pre><div class="item_footer"><p><small><a href="http://www.navegantes.org/index.php/2007/11/30/policia-civil-nos-ajude-a-ter-mais-segur?blog=9">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content>
				</entry>

	
	<entry>
		<title type="text">Itaucard Mail - MASTER CARD GOLD</title>
		<link rel="alternate" type="text/html" href="http://www.navegantes.org/index.php/2007/09/20/itaucard?blog=9" />
		<author>
			<name>Glaydson Lima</name>
					</author>
				<category term="Cartões de Crédito" />
				<id>http://www.navegantes.org/index.php/2007/09/20/itaucard?blog=9</id>
		<published>2007-09-20T16:45:04Z</published>		<updated>2007-09-20T16:45:04Z</updated>
				<content type="html"><![CDATA[<p>Suposto e-mail de solicita&#231;&#227;o de cart&#227;o de cr&#233;dito Ita&#250; instala Cavalo de Tr&#243;ia no computador. Arquivo <b>UP.EXE</b> nocivo.</p>

<p><b>IMAGEM</b></p>

<div class="image_block"><img src="http://www.navegantes.org/media/blogs/pescaria/itaucard.jpg" alt="Itaucard" title="Itaucard" width="420" height="507" /></div><p> </p>

<p><b>TEXTO DO FALSO E-MAIL</b></p>

<blockquote><p>Prezado Sr. (a) ,<br />
 </p>

<p>Voc&#234; solicitou o seguinte cart&#227;o adicional ao seu cart&#227;o ITAUCARD MASTERCARD GOLD :</p>

<p>Tipo: Net<br />
Limite de gastos: R$ 5.000,00</p>

<p>A data de vencimento da fatura &#233; a mesma do cart&#227;o titular, assim as despesas com o cart&#227;o adicional ser&#227;o lan&#231;adas na sua fatura.</p>

<p>Voc&#234; o receber&#225; em seu endere&#231;o de correspond&#234;ncia em at&#233; 10 dias &#250;teis.</p>

<p>Em breve, o n&#250;mero do Itaucard net estar&#225; dispon&#237;vel para consulta no Ita&#250; Bankline.</p>

<p>Somente ap&#243;s desbloquear o cart&#227;o, ele estar&#225; dispon&#237;vel para utiliza&#231;&#227;o.</p>

<p>Aproveite toda a conveni&#234;ncia do Banco Ita&#250; para acessar diversos servi&#231;os e               informa&#231;&#245;es do seu Itaucard, utilizando o Ita&#250; Bankline () e os Caixas Eletr&#244;nicos Ita&#250;.</p>

<p>Caso haja algum engano ou pedido de cancelamento, favor enviar a solicita&#231;&#227;o at&#233; 48 hrs do recebimento deste e-mail de confirma&#231;&#227;o. Favor clicar aqui</p></blockquote>

<p><b>MALWARES ENCONTRADOS</b></p>

<pre>AhnLab-V3	2007.9.20.1	2007.09.20	Win-Trojan/Downloader.15872.AU
AntiVir	7.6.0.15	2007.09.20	-
Authentium	4.93.8	2007.09.20	Possibly a new variant of W32/new-malware!Maximus
Avast	4.7.1043.0	2007.09.19	-
AVG	7.5.0.485	2007.09.19	-
BitDefender	7.2	2007.09.20	Trojan.Downloader.Small.KM
CAT-QuickHeal	9.00	2007.09.19	(Suspicious) - DNAScan
ClamAV	0.91.2	2007.09.20	-
DrWeb	4.33	2007.09.20	DLOADER.Trojan
eSafe	7.0.15.0	2007.09.19	suspicious Trojan/Worm
eTrust-Vet	31.2.5150	2007.09.20	Win32/SillyDl.CIV
Ewido	4.0	2007.09.20	-
FileAdvisor	1	2007.09.20	-
Fortinet	3.11.0.0	2007.09.20	-
F-Prot	4.3.2.48	2007.09.19	W32/new-malware!Maximus
F-Secure	6.70.13030.0	2007.09.20	-
Ikarus	T3.1.1.12	2007.09.20	-
Kaspersky	4.0.2.24	2007.09.20	-
McAfee	5123	2007.09.19	Downloader-ABU
Microsoft	1.2803	2007.09.20	TrojanDownloader:Win32/Small.gen!Z
NOD32v2	2541	2007.09.20	probably unknown NewHeur_PE virus
Norman	5.80.02	2007.09.19	-
Panda	9.0.0.4	2007.09.20	Suspicious file
Prevx1	V2	2007.09.20	Heuristic: Suspicious Self Modifying EXE
Rising	19.41.32.00	2007.09.20	Trojan.DL.Small.rda
Sophos	4.21.0	2007.09.20	Mal/Heuri-E
Sunbelt	2.2.907.0	2007.09.20	VIPRE.Suspicious
Symantec	10	2007.09.20	Downloader
TheHacker	6.2.5.063	2007.09.20	W32/Behav-Heuristic-066
VBA32	3.12.2.4	2007.09.20	suspected of Win32.Trojan.Downloader (http://...)
VirusBuster	4.3.26:9	2007.09.19	-
Webwasher-Gateway	6.0.1	2007.09.20	Win32.Malware.gen (suspicious)</pre><div class="item_footer"><p><small><a href="http://www.navegantes.org/index.php/2007/09/20/itaucard?blog=9">Original post</a> blogged on <a href="http://b2evolution.net/">b2evolution</a>.</small></p></div>]]></content>
				</entry>

	</feed>
