<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/1.5.1-alpha" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
	<title>VSUB - Malware Submissions</title>
	<link>http://vsub.blogsome.com</link>
	<description>Details on new malware submitted to anti-malware vendors for inclusion in their products...</description>
	<pubDate>Sun, 01 Apr 2007 11:34:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.1-alpha</generator>
	<language>en</language>

		<item>
		<title>This Blog Has Moved - UPDATED</title>
		<link>http://vsub.blogsome.com/2007/02/19/this-blog-has-moved/</link>
		<comments>http://vsub.blogsome.com/2007/02/19/this-blog-has-moved/#comments</comments>
		<pubDate>Mon, 19 Feb 2007 19:18:40 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
		<guid>http://vsub.blogsome.com/2007/02/19/this-blog-has-moved/</guid>
		<description><![CDATA[	IMPORTANT - UPDATED
	Please note that this blog has now moved to my own hosted domain here: http://momuings.com/vsub/. A full RSS/ATOM feed can be found there.
	All the data up to the end of December 2006 will be left here, however all postings from the 1st of January 2007  onwards will only be available at this [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2007/02/19/this-blog-has-moved/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0612002 Possible New Malware [Downloader?]</title>
		<link>http://vsub.blogsome.com/2006/12/13/vs0612002-possible-new-malware-downloader/</link>
		<comments>http://vsub.blogsome.com/2006/12/13/vs0612002-possible-new-malware-downloader/#comments</comments>
		<pubDate>Wed, 13 Dec 2006 16:07:11 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/12/13/vs0612002-possible-new-malware-downloader/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via an e-mail with an attachment.
	This was caught by an end-user.
	I have included data on a sample for your information and analysis, and an example of the e-mail received.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/12/13/vs0612002-possible-new-malware-downloader/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0612001 Possible New Malware [Banload?]</title>
		<link>http://vsub.blogsome.com/2006/12/11/vs0612001-possible-new-malware-banload/</link>
		<comments>http://vsub.blogsome.com/2006/12/11/vs0612001-possible-new-malware-banload/#comments</comments>
		<pubDate>Mon, 11 Dec 2006 12:19:56 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/12/11/vs0612001-possible-new-malware-banload/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via a link in an e-mail.
	This was caught by an end-user.
	I have included data on a sample for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: fotos.scr
FileDateTime: 20/11/2006 03:42:14
Filesize: 197632
MD5: [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/12/11/vs0612001-possible-new-malware-banload/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0611001 Possible New Malware [Small?]</title>
		<link>http://vsub.blogsome.com/2006/11/17/vs0611001-possible-new-malware-small/</link>
		<comments>http://vsub.blogsome.com/2006/11/17/vs0611001-possible-new-malware-small/#comments</comments>
		<pubDate>Fri, 17 Nov 2006 16:21:34 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/11/17/vs0611001-possible-new-malware-small/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via a phishing site.
	This was caught by an end-user.
	I have included data on a sample for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: Guardv10.exe
FileDateTime: 16/11/2006 17:44:35
Filesize: 149254
MD5: 2fadb5a4f3c80e78197d733255136ba7
CRC32: 7B3A6C60
File [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/11/17/vs0611001-possible-new-malware-small/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0610003 Possible new malware [Mechbot?]</title>
		<link>http://vsub.blogsome.com/2006/10/26/vs0610003-possible-new-malware-mechbot/</link>
		<comments>http://vsub.blogsome.com/2006/10/26/vs0610003-possible-new-malware-mechbot/#comments</comments>
		<pubDate>Thu, 26 Oct 2006 12:29:24 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/10/26/vs0610003-possible-new-malware-mechbot/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via e-mail
using a website link in the e-mail.
	This was caught by an end-user.
	I have included data on a sample for your information and analysis.
	2 copies have been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: postcards.exe
FileDateTime: 26/10/2006 [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/10/26/vs0610003-possible-new-malware-mechbot/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0610002 Possible new malware [Banload?]</title>
		<link>http://vsub.blogsome.com/2006/10/20/vs0610002-possible-new-malware-banload/</link>
		<comments>http://vsub.blogsome.com/2006/10/20/vs0610002-possible-new-malware-banload/#comments</comments>
		<pubDate>Fri, 20 Oct 2006 13:06:47 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/10/20/vs0610002-possible-new-malware-banload/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via e-mail
using a website link in the e-mail.
	This was caught by an end-user.
	I have included data on a sample for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: newfoto.exe
FileDateTime: 16/10/2006 [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/10/20/vs0610002-possible-new-malware-banload/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0610001 Possible new malware [Agent?]</title>
		<link>http://vsub.blogsome.com/2006/10/04/vs0610001-possible-new-malware-agent/</link>
		<comments>http://vsub.blogsome.com/2006/10/04/vs0610001-possible-new-malware-agent/#comments</comments>
		<pubDate>Wed, 04 Oct 2006 09:50:34 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/10/04/vs0610001-possible-new-malware-agent/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via IM
using a website link in the IM [MSN].
	Which uses a PHP script to download a file.
	This was caught by an end-user.
	I have included data on a  sample for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/10/04/vs0610001-possible-new-malware-agent/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0609001 Possible new malware</title>
		<link>http://vsub.blogsome.com/2006/09/26/vs0609001-possible-new-malware/</link>
		<comments>http://vsub.blogsome.com/2006/09/26/vs0609001-possible-new-malware/#comments</comments>
		<pubDate>Tue, 26 Sep 2006 10:56:42 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/09/26/vs0609001-possible-new-malware/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via a
website link in a phishing e-mail.
	This was caught by my Bayesian filter.
	I have included data on a sample for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: ghost11.exe
FileDateTime: 23/09/2006 [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/09/26/vs0609001-possible-new-malware/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0608004 Possible new malware [Haxdoor/Goldun?]</title>
		<link>http://vsub.blogsome.com/2006/08/31/vs0608004-possible-new-malware-haxdoorgoldun/</link>
		<comments>http://vsub.blogsome.com/2006/08/31/vs0608004-possible-new-malware-haxdoorgoldun/#comments</comments>
		<pubDate>Thu, 31 Aug 2006 12:31:47 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/08/31/vs0608004-possible-new-malware-haxdoorgoldun/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via e-mail.
	This was caught by an end user.
	I have included data on a sample of the file attachment for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: au.zl9
FileDateTime: 31/08/2006 10:20:51
Filesize: [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/08/31/vs0608004-possible-new-malware-haxdoorgoldun/feed/</wfw:commentRss>
	</item>
		<item>
		<title>VS0608003 Possible new malware [SDbot?]</title>
		<link>http://vsub.blogsome.com/2006/08/29/vs0608003-possible-new-malware-sdbot/</link>
		<comments>http://vsub.blogsome.com/2006/08/29/vs0608003-possible-new-malware-sdbot/#comments</comments>
		<pubDate>Tue, 29 Aug 2006 13:37:56 +0000</pubDate>
		<dc:creator>vsub</dc:creator>
		
	<category>All</category>
	<category>Submitted</category>
		<guid>http://vsub.blogsome.com/2006/08/29/vs0608003-possible-new-malware-sdbot/</guid>
		<description><![CDATA[	Data on a sample of a suspected new malware being spread via SMB.
	This was caught by my WormCharmer.
	I have included data on a sample for your information and analysis.
	1 copy has been trapped so far.
	I haven&#8217;t had a chance to test it on a goat system yet.
	============================================================
	Details:
	FileName: dvdafw.exe
FileDateTime: 25/08/2006 15:00:15
Filesize: 31364
MD5: f837afb65b5069e329c669e77af5ecc2
CRC32: 8E4A6561
File Type: PE [...]]]></description>
		<wfw:commentRss>http://vsub.blogsome.com/2006/08/29/vs0608003-possible-new-malware-sdbot/feed/</wfw:commentRss>
	</item>
	</channel>
</rss>
