<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Getting IT Right - the unofficial voice of Meteor IT &#187; trojan</title>
	<atom:link href="http://blog.meteorit.co.uk/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.meteorit.co.uk</link>
	<description>Ramblings of a self-confessed geek</description>
	<lastBuildDate>Tue, 02 Feb 2010 22:19:29 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='blog.meteorit.co.uk' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/f20aaf2e5a61cd42fe07e67a0f2a1c3f?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Getting IT Right - the unofficial voice of Meteor IT &#187; trojan</title>
		<link>http://blog.meteorit.co.uk</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.meteorit.co.uk/osd.xml" title="Getting IT Right &#8211; the unofficial voice of Meteor IT" />
	<atom:link rel='hub' href='http://blog.meteorit.co.uk/?pushpress=hub'/>
		<item>
		<title>UPS_Invoice email trojan variant claims to be from Customs Service</title>
		<link>http://blog.meteorit.co.uk/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/</link>
		<comments>http://blog.meteorit.co.uk/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 14:38:04 +0000</pubDate>
		<dc:creator>Adam Vero</dc:creator>
				<category><![CDATA[Security and Malware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Customs service]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tax_invoice]]></category>
		<category><![CDATA[tracking number]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS_invoice]]></category>

		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/</guid>
		<description><![CDATA[In the last hour I found in my inbox a variation on the UPS_Invoice trojans of last week. This new email claimed to be from "Customs Service" with the subject "Customs - We have received a parcel for you" and the following text:
Good afternoon, We have received a parcel for you, sent from France on July 9. Please fill out the customs declaration attached to this message and send it to us by mail or fax. The address and the fax number are at the bottom of the declaration form.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.meteorit.co.uk&blog=646149&post=186&subd=veroblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>In the last hour I found in my inbox a variation on the <a title="Previous post regarding UPS_Invoice downloader trojan" href="http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/" target="_blank">UPS_Invoice trojans of last week</a>. This new email claimed to be from &#8220;Customs Service&#8221; with the subject &#8220;Customs &#8211; We have received a parcel for you&#8221; and the following text:</p>
<blockquote><p>Good afternoon,</p>
<p>We have received a parcel for you, sent from France on July 9. Please fill out the customs declaration attached to this message and send it to us by mail or fax. The address and the fax number are at the bottom of the declaration form.</p>
<p>Kind regards,</p>
<p>Rolland Hanna</p>
<p>Your Customs Service</p>
</blockquote>
<p>This content was so close to the UPS_Invoice one that it seems obvious it originates from the same source.</p>
<p><span id="more-186"></span>My parents were on holiday in France on July 9th (back home now) so this might just possibly have caught me out if I had not seen the previous variant and the wording was a bit less stilted (especially the signoff), and the sender had actually been spoofed as the customs service not some random .com company. I guess the people most likely to fall for this would be anyone who bought something online from France, or through eBay and maybe they are not 100% sure where their purchase is being shipped from.
</p>
<p>This time the attachment was called Tax_Invoice.zip which expanded directly to the executable (no folders in between this time) which was called Tax_Invoice_________________________NHHDLS883298792929.exe . I guess the filename padding is a flimsy attempt to make the end part disappear from the view and show as the truncated name &#8220;Tax_Invoice_&#8230;&#8221; or similar. Like the previous ones, this has a crude MS Word icon which has rough edges and simply does not scale above &#8220;medium icons&#8221; view in Vista &#8211; any larger and it just shows the smaller one in a larger grey box.</p>
<p>This one has an MD5 hash of 8CEB0F61089D86C086DCC08D6A783015.</p>
<p>Since the <a title="first post about UPS_Invoice malware" href="http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/" target="_blank">first rash</a> of <a title="second follow up post about UPS_invoice virus" href="http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/" target="_blank">these emails</a> last week, things died down. Presumably as the world&#8217;s antivirus vendors caught up with this new malware outbreak, they were mainly being caught at the point of sending. I certainly received none for several days, then had two on Monday night / Tuesday morning with the same text as before:</p>
<blockquote><p>Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct. Please print out the invoice copy attached and collect the package at our office</p>
</blockquote>
<p>(one bizarrely missed the apostrophe from &#8220;recipient&#8217;s&#8221; and replaced it with a space)</p>
<p>Both had the same attachment UPS_INVOICE_978172.zip (47.9 KB or 49,110 bytes in size), which expanded to a 56KB (57,344 bytes) exe of the same name with MD5 checksum DA4B7EF93C588AD799F1A1C5AFB6CFAD.</p>
<p>Thursday&#8217;s pair were just called invoice_8712.zip (48 KB or 49,192 bytes) which held a 55.5 KB (56,832 bytes) file called INVOICE_8712.exe with MD5 digest of 9E2756F0A0AD988E149845B07216B181. All of this week&#8217;s emails had the subject &#8220;UPS Tracking Number nnn&#8221; with four different numbers: 1950761581, 8587187457, 7535113385, and 6853701924.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/veroblog.wordpress.com/186/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/veroblog.wordpress.com/186/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/veroblog.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/veroblog.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/veroblog.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/veroblog.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/veroblog.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/veroblog.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/veroblog.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/veroblog.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/veroblog.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/veroblog.wordpress.com/186/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.meteorit.co.uk&blog=646149&post=186&subd=veroblog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.meteorit.co.uk/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/786403437a56d6c7ecd26e885004d2ad?s=96&#38;d=wavatar&#38;r=PG" medium="image">
			<media:title type="html">AdamV</media:title>
		</media:content>
	</item>
		<item>
		<title>Follow up post about UPS_Invoice trojan</title>
		<link>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/</link>
		<comments>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 14:51:39 +0000</pubDate>
		<dc:creator>Adam Vero</dc:creator>
				<category><![CDATA[Security and Malware]]></category>
		<category><![CDATA[Agent HFU]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS_invoice]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/15/follow-up-post-about-ups_invoice-trojan/</guid>
		<description><![CDATA[I've now had a chance to take a slightly closer look at the four copies of this Trojan Agent HFU that I received in the last 24 hours, as discussed in my previous post here. I've posted some details of file names and sizes along with MD5 hashes for people to be able to compare their versions against.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.meteorit.co.uk&blog=646149&post=185&subd=veroblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve now had a chance to take a slightly closer look at the four copies of this Trojan Agent HFU that I received in the last 24 hours, as discussed in <a title="UPS_invoice trojan sent as zip attachment by email" href="http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/" target="_blank">my previous post here</a>. I&#8217;ve posted some details of file names and sizes along with MD5 hashes for people to be able to compare their versions against.</p>
<p><span id="more-185"></span></p>
<p>The first one which had the half German subject line was a file called UPS_Invoice_317.zip which was 5,420 bytes in size. This one expanded into two levels of folder as UPS_Invoice_317\Ups_invoice\UPS_INVOICE.exe (this was the only one to use lower case in its folder names). The executable was exactly 8,192 bytes (almost certainly padded) and had an MD5 hash of 6B4EF50E3E21205685CEA919EBF93476 which is the same as the one posted by Kayrac on the <a title="BroadBand reports forum discussion of UPS_invoice worm / trojan" href="http://broadbandreports.com/forum/r20789896-UPS-packet-upsinvoicezip-WORM&quot;&gt;broadbandreports.com forum" target="_blank">broadbandreports.com forum</a>. Unfortunately he did not say what the name of the containing zip file was.</p>
<p>My next one was called UPS_INOICE_107.zip (note the mis-spelling) and extracted as UPS_INOICE_107\UPS_INVOICE_107.exe &#8211; only one level of folders this time, and the executable inherited the numeric part in its name. The mis-spelling almost certainly came from a mis-spelled folder used to compress it in the first place, as most zip programs default to using the folder name for the zip file as well. This file was only 6,656 bytes long and had MD5 checksum of 0C0F2CB1DEB11EC0AA68DEE0933FAACF. Since this is smaller than all the others I am certain it is a significantly different variant, or perhaps is simply broken. Hopefully I can test this later to see what (if anything) it does.</p>
<p>My third and fourth received emails were both called UPS_INVOICE_107.zip and extracted to UPS_INVOICE_107\UPS_INVOICE_107.exe, both 8,192 bytes long and with the same MD5 digest of 58AC24B1F802990387870D3A5CC2312B. The two zip files however were different sizes (4,117 and 4,178 bytes), so they were not direct copies of one another.</p>
<p>All the files made reference to a Russian domain which was registered on the 11th June. I have obscured the domain name and parts of the IP address in the screenshot below, taken from <a title="great online DNS tools - WhoIs, IP lookups, TraceRoute and more" href="http://www.DNSstuff.com" target="_blank">DNSstuff.com</a></p>
<p><img src="http://veroblog.files.wordpress.com/2008/07/ups-trojan-domain.png?w=489&#038;h=371" alt="UPS_invoice trojan domain" width="489" height="371" /></p>
<p>There seems to be an SMTP server running on the same IP as the name servers, presumably to enable the malware to forward copies of itself, or perhaps to send messages home, since it does not seem to be set up to permit relaying.</p>
<p>Anyone have any further information about what this does yet? I&#8217;m just setting up a sandbox machine to try and track its infection in a safe environment.</p>
<p>Also, if you have any MD hashes which are different it might be interesting to post them as comments so we see how many flavours of this are out there.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/veroblog.wordpress.com/185/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/veroblog.wordpress.com/185/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/veroblog.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/veroblog.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/veroblog.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/veroblog.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/veroblog.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/veroblog.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/veroblog.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/veroblog.wordpress.com/185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/veroblog.wordpress.com/185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/veroblog.wordpress.com/185/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.meteorit.co.uk&blog=646149&post=185&subd=veroblog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.meteorit.co.uk/2008/07/15/follow-up-post-about-ups_invoice-trojan/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/786403437a56d6c7ecd26e885004d2ad?s=96&#38;d=wavatar&#38;r=PG" medium="image">
			<media:title type="html">AdamV</media:title>
		</media:content>

		<media:content url="http://veroblog.files.wordpress.com/2008/07/ups-trojan-domain.png" medium="image">
			<media:title type="html">UPS_invoice trojan domain</media:title>
		</media:content>
	</item>
		<item>
		<title>UPS_Invoice.exe trojan received by email</title>
		<link>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/</link>
		<comments>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 18:09:36 +0000</pubDate>
		<dc:creator>Adam Vero</dc:creator>
				<category><![CDATA[Security and Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[UPS_invoice]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[zip file]]></category>

		<guid isPermaLink="false">http://veroblog.wordpress.com/2008/07/14/ups_invoiceexe-trojan-received-by-email/</guid>
		<description><![CDATA[This lunchtime I received an email as follows:
From: United Parcel Service [someone@not_ups.com]
Subject: UPS Paket N2410170593
Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office
Your UPS
Attachment: UPS_Invoice_317.zip

Of course this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.meteorit.co.uk&blog=646149&post=183&subd=veroblog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>This lunchtime I received an email as follows:</p>
<blockquote><p>From: United Parcel Service [someone@not_ups.com]</p>
<p>Subject: UPS Paket N2410170593</p>
<p>Unfortunately we were not able to deliver postal package you sent on July the 1st in time because the recipient’s address is not correct.
<p>Please print out the invoice copy attached and collect the package at our office
<p>Your UPS
<p>Attachment: UPS_Invoice_317.zip</p>
</blockquote>
<p>Of course this was extremely suspicious. I had no recent dealings with UPS, the email clearly did not really come from them anyway (it was not even spoofed to appear to be from their domain), and why on earth would they need to send me a file, let alone a zipped one? The misspelling in the subject also smelled of an automated message (although Paket is the correct spelling for the German word for packet). I smelled malware and wanted to find out more.</p>
<p><span id="more-183"></span>
<p>So I saved the file and had a quick peek with notepad to avoid opening the zip file at all. I could see enough of the content to see that the content of the zip was a single executable called UPS_invoice.exe rather than any kind of document file. Next step &#8211; a quick search online to see what particular flavour of nastiness this was. Fire up search engine, search for &#8220;UPS_invoice trojan&#8221;, &#8220;UPS invoice trojan&#8221; and other variations. Absolutely nothing at all. No-one else seems to have received this. Very strange indeed. I had a look on <a href="http://www.sophos.com" target="_blank">Sophos&#8217; website</a> and <a href="http://vil.nai.com" target="_blank">McAfee&#8217;s virus information library</a> but could not find anything resembling this.</p>
<p>I wondered if I had somehow been &#8216;lucky&#8217; enough to be one of the first to be sent a new malware variant, so I submitted a sample to Sophos.</p>
<p>I checked again later in the day and now I got a single hit for a site discussing this new menace, a blog at the Berlin Technische Universität focussing on hoax information had this post: <a title="UPS emails with malware" href="http://www2.tu-berlin.de/www/software/blog.shtml?08157" target="_blank">UPS-Mails mit Malware</a>. So, I was not alone, but it was still odd that no-one else reported this.</p>
<p>Of course, zip files can be opened natively on XP with no additional software, and a zip can be compressed in such a way that it will automatically open or run a file once it has decompressed the zip. This means that simply double-clicking the file could cause the payload to run, and attempt to install and do its damage.</p>
<p>Five hours after submitting my sample, Sophos kindly confirmed that the file did contain malware, identified by them as <a title="Trojan Agent HFU details from Sophos" href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojagenthfu.html" target="_blank">Troj/Agent-HFU</a>. Coincidentally, the last email to arrive before I received this was another version of the same thing, with an English subject of &#8220;UPS Tracking Number 8017161622&#8243; and the attachment was called UPS_Inoice_107.zip this time (yes, that&#8217;s &#8220;inoice&#8221; with no V). So maybe the first one was actually a German variant sent to me &#8211; not too farfetched given that I receive plenty of spam in German, usually pump-and-dump stock scams, so I must be on someone&#8217;s spam lists.</p>
<h2>Still no information about UPS_Invoice.exe</h2>
<p>However, there was still no mention of the email subject or payload name. Web searches still found only the TU Berlin article &#8211; was this just because the search providers have an inevitable timelag, or something else? I had a read of the Sophos advisory about this and found that they simply don&#8217;t mention UPS at all. Nothing. I know back when I wrote my <a title="review of Sophos SBE antispam and antivirus" href="http://veroblog.wordpress.com/2007/01/14/sophos-sbe-anti-virus-and-anti-spam-for-small-businesses/" target="_blank">review of Sophos Small Business Edition</a> they used to be pretty good at describing the symptoms of a malware variant so you had some chance of identifying threats. Now the description says only that this trojan affects Windows, and that protection has been available for Sophos customers since 13 July 2008 19:44:42 (GMT). Pretty useless, so I thought I would check if anyone else had any more helpful information by searching for the name &#8220;Troj/Agent-HFU&#8221; and &#8220;Trojan Agent HFU&#8221;. The only results were sites which either syndicated Sophos information directly or wrote about new releases and quoted the source. So the blogosphere echoed with the same information I could get from Sophos but nothing else.</p>
<h2>What&#8217;s in a name?</h2>
<p>So, does this mean that Sophos are the only vendor out there offering to spot this new threat with an updated signature? I very much doubt it, I suspect this is just a manifestation of the usual problem of confusion over virus names. When a biologist finds a new species of beetle (or indeed a real-life virus) they get to name it anything they like. They can stick to a conventional <a title="Wikipedia article on Linnaean taxonomy" href="http://en.wikipedia.org/wiki/Linnaean_taxonomy" target="_blank">Linnaean classification</a>, or name it after their maternal grandmother, a character from Star Trek, or simply a new rude-sounding word. But once they have decided upon a name, everyone else has to use the same one. OK, there are cases where a second person does not realise that their find is not actually new, and they use their own chosen name for a while, but once it is determined that two creatures are in fact just individuals from the same species, the earlier name is used.</p>
<p>Not so for computer viruses. For years I have found it annoying and frustrating that the antivirus vendors seem to enjoy choosing different names for the same malware and then sticking doggedly to them. At least they used to cross-reference each other&#8217;s versions to some extent, but now it seems they are deliberately keeping to their own petty conventions. Why not adopt a universal scheme of letters and numbers within which any vendor can take the next one off the list and attach it to an identified executable? If astronomers can do this for the billions of stars and other objects found in outer space, why not for something as specific and tangible as a few dozen lines of code? Even the minor variants introduced by viruses when copying themselves in order to defeat the most primitive signature-based scanners are easily stripped away, and the core program and its behaviour can be identified. Maybe I&#8217;m being over-simplistic or optimistic about the levels of cooperation possible between large corporations which answer to their shareholders. Any insiders care to share any information about the practicality or otherwise of such a name-sharing scheme?</p>
<p>PS: A third email with subject &#8220;UPS Tracking Number 6360851232&#8243; and an attachment name correctly spelled as UPS_Invoice_107.zip arrived while I was writing this. </p>
<p>It just seems odd how no-one seems to be talking about these with reference to the subject or attachment names. Since it is totally obvious they are not really from UPS, what&#8217;s the issue? Has anyone else been receiving many of these? </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/veroblog.wordpress.com/183/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/veroblog.wordpress.com/183/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/veroblog.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/veroblog.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/veroblog.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/veroblog.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/veroblog.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/veroblog.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/veroblog.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/veroblog.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/veroblog.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/veroblog.wordpress.com/183/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.meteorit.co.uk&blog=646149&post=183&subd=veroblog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.meteorit.co.uk/2008/07/14/ups_invoiceexe-trojan-received-by-email/feed/</wfw:commentRss>
		<slash:comments>37</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/786403437a56d6c7ecd26e885004d2ad?s=96&#38;d=wavatar&#38;r=PG" medium="image">
			<media:title type="html">AdamV</media:title>
		</media:content>
	</item>
	</channel>
</rss>