<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Abuse         Team</title>
	<atom:link href="http://abuseteam.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://abuseteam.wordpress.com</link>
	<description>Blog do pessoal do "Abuse" que trabalha em um provedor!!!</description>
	<lastBuildDate>Fri, 07 Nov 2008 18:27:44 +0000</lastBuildDate>
	<language>pt-br</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='abuseteam.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Abuse         Team</title>
		<link>http://abuseteam.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://abuseteam.wordpress.com/osd.xml" title="Abuse         Team" />
	<atom:link rel='hub' href='http://abuseteam.wordpress.com/?pushpress=hub'/>
		<item>
		<title>EMAIL FALSO: Terra Mensagem</title>
		<link>http://abuseteam.wordpress.com/2008/11/07/email-falso-terra-mensagem/</link>
		<comments>http://abuseteam.wordpress.com/2008/11/07/email-falso-terra-mensagem/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 18:26:31 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[CWSandbox]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[terra]]></category>
		<category><![CDATA[Terra Mensagem]]></category>
		<category><![CDATA[ThreatExpert]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2008/11/07/email-falso-terra-mensagem/</guid>
		<description><![CDATA[Outra fraude utilizando o nome do provedor Terra, desta vez a mensagem é simples conforme vocês podem observar abaixo. O link indica um arquivo chamado &#8220;Cartao_Terra.com&#8221;. O arquivo é utilizado para capturar dados bancários e altera diversos registros na máquina. Já foi solicitada a remoção do arquivo e abaixo segue a análise do arquivo feita [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=131&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">Outra fraude utilizando o nome do provedor Terra, desta vez a mensagem é simples conforme vocês podem observar abaixo.</p>
<p>
<div align="center"><img style="max-width:800px;" src="http://abuseteam.files.wordpress.com/2008/11/terra-mensagem.png?w=450" /></div>
<p>O link indica um arquivo chamado &#8220;Cartao_Terra.com&#8221;. O arquivo é utilizado para capturar dados bancários e altera diversos registros na máquina. Já foi solicitada a remoção do arquivo e abaixo segue a análise do arquivo feita pelo <a target="_blank" href="http://www.threatexpert.com">ThreatExpert</a> e o <a target="_blank" href="http://www.sunbeltsoftware.com/Developer/Sunbelt-CWSandbox/">CWSandbox da Sunbelt Software</a>.</p>
<p><a target="_blank" href="http://www.threatexpert.com/report.aspx?md5=5b3e754f12d75fbaa2d2d0cecefb1426">ThreatExpert Report</a></p>
<p><a target="_blank" href="http://research.sunbelt-software.com/ViewMalware.aspx?id=6022895">CWSandbox Report</a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/131/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/131/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/131/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=131&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2008/11/07/email-falso-terra-mensagem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2008/11/terra-mensagem.png" medium="image" />
	</item>
		<item>
		<title>EMAIL FALSO: Comunicado Importante</title>
		<link>http://abuseteam.wordpress.com/2008/11/07/email-falso-comunicado-importante/</link>
		<comments>http://abuseteam.wordpress.com/2008/11/07/email-falso-comunicado-importante/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 17:57:35 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[Comunicado Importante]]></category>
		<category><![CDATA[No-IP.com]]></category>
		<category><![CDATA[terra]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2008/11/07/email-falso-comunicado-importante/</guid>
		<description><![CDATA[Nova fraude em nome do provedor Terra, dessa vez utilizando o formato igual aos comunicados enviados. Abaixo segue a tela capturada do email. A arquivo e a página onde o usuário é direcionado ao clicar já foi removida pelo No-IP.com.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=119&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">Nova fraude em nome do provedor Terra, dessa vez utilizando o formato igual aos comunicados enviados. Abaixo segue a tela capturada do email. A arquivo e a página onde o usuário é direcionado ao clicar já foi removida pelo No-IP.com.</div>
<p>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2008/11/comunicado_importante.png" target="_blank"><img class="alignnone size-medium wp-image-117" title="comunicado_importante" src="http://abuseteam.files.wordpress.com/2008/11/comunicado_importante.png?w=130&#038;h=299" alt="comunicado_importante" width="130" height="299" /></a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=119&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2008/11/07/email-falso-comunicado-importante/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2008/11/comunicado_importante.png?w=130" medium="image">
			<media:title type="html">comunicado_importante</media:title>
		</media:content>
	</item>
		<item>
		<title>WordPress Fake??</title>
		<link>http://abuseteam.wordpress.com/2008/11/06/wordpress-fake/</link>
		<comments>http://abuseteam.wordpress.com/2008/11/06/wordpress-fake/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 21:54:14 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Gerais]]></category>
		<category><![CDATA[Beta]]></category>
		<category><![CDATA[Cracker]]></category>
		<category><![CDATA[Stable]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2008/11/06/wordpress-fake/</guid>
		<description><![CDATA[Tava lendo umas notícias agora e me deparei com a seguinte matéria &#8220;Crackers criam falso site do WordPress&#8220;. Agora me veio a cabeça a seguinte pergunta. Mas quem (pelo amor de Deus) vai me baixar uma versão do WordPress de outro site que não seja o www.wordpress.org? Fala sério, o sistema é free sem restrição [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=115&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">Tava lendo umas notícias agora e me deparei com a seguinte matéria <i>&#8220;<a target="_blank" href="http://info.abril.com.br/aberto/infonews/112008/06112008-32.shl">Crackers criam falso site do WordPress</a>&#8220;</i>. Agora me veio a cabeça a seguinte pergunta.</div>
<p>
<div align="justify"><i>Mas quem (pelo amor de Deus) vai me baixar uma versão do WordPress de outro site que não seja o www.wordpress.org?</i></div>
<p>
<div align="justify">Fala sério, o sistema é free sem restrição alguma. Na página tem o link para a versão <i>Stable</i> (Estável &#8211; 2.6.3), além de um link para para o blog deles onde é possível pegar a versão Beta (2.7 beta 2).</div>
<p>
<div align="justify">Por favor, pegar script free de outro site que não seja o de quem desenvolveu é dar tiro no pé e pedir pra se dar mal.</div>
<p>Abração!<br />
<blockquote></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/115/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/115/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/115/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=115&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2008/11/06/wordpress-fake/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>
	</item>
		<item>
		<title>EMAIL FALSO: Comunicado de segurança &#8211; Terra</title>
		<link>http://abuseteam.wordpress.com/2008/10/22/email-falso-comunicado-de-seguranca-terra/</link>
		<comments>http://abuseteam.wordpress.com/2008/10/22/email-falso-comunicado-de-seguranca-terra/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 18:41:08 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[Antispam]]></category>
		<category><![CDATA[fraude]]></category>
		<category><![CDATA[terra]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2008/10/22/email-falso-comunicado-de-seguranca-terra-2/</guid>
		<description><![CDATA[Nova fraude utilizando o nome do Terra. O email indica o envio pelo email Terramail@terra.com.br, porém em análise no cabeçalho do email é possível verificar que esse campo foi FORJADO. A rede que hospeda a página falsa e o arquivo malicioso já foram notificados para remoção do conteúdo e correção da página. Segue abaixo o [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=71&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">Nova fraude utilizando o nome do Terra. O email indica o envio pelo email <strong>Terramail@terra.com.br</strong>, porém em análise no cabeçalho do email é possível verificar que esse campo foi <strong>FORJADO</strong>.</p>
<p>A rede que hospeda a página falsa e o arquivo malicioso já foram notificados para remoção do conteúdo e correção da página.</p></div>
<p>Segue abaixo o email e as informações.</p>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2008/10/terra-comunicadoseguranca01.png" target="_blank"><img src="http://abuseteam.files.wordpress.com/2008/10/terra-comunicadoseguranca01.png?w=400" width="400" /></a></div>
<p>O link abre uma página falsa para download dos arquivos.</p>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2008/10/terra-comunicadoseguranca021.png" target="_blank"><img src="http://abuseteam.files.wordpress.com/2008/10/terra-comunicadoseguranca021.png?w=400" width="400" /></a></div>
<p>
<div align="justify">Apesar de mostrar 2 links na mensagem, o arquivo é o mesmo <strong>Antispam_Terra.com</strong>. Identificado pelo Symantec como <strong>Downloader.Bancos</strong> <a href="http://securityresponse.symantec.com/avcenter/cgi-bin/virauto.cgi?vid=17561" target="_blank">http://securityresponse.symantec.com/avcenter/cgi-bin/virauto.cgi?vid=17561</a>, é utilizado para captura de dados sensíveis. Abaixo segue as telas do Symantec.</div>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2008/10/symantec01.png" target="_blank"><img src="http://abuseteam.files.wordpress.com/2008/10/symantec01.png?w=400" width="400" /></a></div>
<p>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2008/10/symantec02.png" target="_blank"><img src="http://abuseteam.files.wordpress.com/2008/10/symantec02.png?w=400" width="400" /></a></div>
<p>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2008/10/symantec03.png" target="_blank"><img src="http://abuseteam.files.wordpress.com/2008/10/symantec03.png?w=400" width="400" /></a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=71&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2008/10/22/email-falso-comunicado-de-seguranca-terra/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2008/10/terra-comunicadoseguranca01.png" medium="image" />

		<media:content url="http://abuseteam.files.wordpress.com/2008/10/terra-comunicadoseguranca021.png" medium="image" />

		<media:content url="http://abuseteam.files.wordpress.com/2008/10/symantec01.png" medium="image" />

		<media:content url="http://abuseteam.files.wordpress.com/2008/10/symantec02.png" medium="image" />

		<media:content url="http://abuseteam.files.wordpress.com/2008/10/symantec03.png" medium="image" />
	</item>
		<item>
		<title>Formulário de recadastramento &#8211; Terra</title>
		<link>http://abuseteam.wordpress.com/2008/09/06/formulario-de-recadastramento-terra/</link>
		<comments>http://abuseteam.wordpress.com/2008/09/06/formulario-de-recadastramento-terra/#comments</comments>
		<pubDate>Sat, 06 Sep 2008 15:43:19 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[Recadastramento]]></category>
		<category><![CDATA[terra]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/?p=45</guid>
		<description><![CDATA[O email indica o download de um &#8220;formulário&#8221; para recadastramento do email em um prazo de 24 horas, senão o mesmo será cancelado. O link &#8220;Download&#8221; leva a um arquivo .scr para roubo de dados sensíveis, como usuário e senha de emails e dados bancários. O mesmo email foi enviado com diversos assuntos, exemplo: Solicitação [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=45&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">O email indica o download de um <strong>&#8220;formulário&#8221;</strong> para recadastramento do email em um prazo de 24 horas, senão o mesmo será cancelado.</div>
<p>
<div align="justify">O link <strong>&#8220;Download&#8221;</strong> leva a um arquivo <strong>.scr</strong> para roubo de dados sensíveis, como usuário e senha de emails e dados bancários.</div>
<p>O mesmo email foi enviado com diversos assuntos, exemplo:<br />
<blockquote>Solicitação de recadastramento de e-mails.</p>
<p>Cancelamento de E-mail&#8230;</p></blockquote>
<p><strong>Imagem da mensagem (clique para ampliar)</strong>
<p style="text-align:center;"><a href="http://www.glowfoto.com/static_image/05-145709L/2898/png/09/2008/img3/glowfoto" target="_blank"><img class="aligncenter" src="http://img3.glowfoto.com/images/2008/09/05-1457092898T.png" alt="" /></a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/abuseteam.wordpress.com/45/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/abuseteam.wordpress.com/45/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/45/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/45/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/45/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=45&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2008/09/06/formulario-de-recadastramento-terra/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://img3.glowfoto.com/images/2008/09/05-1457092898T.png" medium="image" />
	</item>
		<item>
		<title>Email Falso &#8211; Terra</title>
		<link>http://abuseteam.wordpress.com/2008/09/05/email-falso-terra/</link>
		<comments>http://abuseteam.wordpress.com/2008/09/05/email-falso-terra/#comments</comments>
		<pubDate>Fri, 05 Sep 2008 22:57:49 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[fraude]]></category>
		<category><![CDATA[Mail Terra]]></category>
		<category><![CDATA[Microsoft Security]]></category>
		<category><![CDATA[terra]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2008/09/05/email-falso-terra/</guid>
		<description><![CDATA[A fraude vem com 3 tipos de Assunto, vou listar abaixo: Provedor Terra &#8211; Bloqueamento de sua conta (Instale Microsoft Security mailTerra obrigatoriamente) Terra &#8211; Bloqueamento de sua conta (Instale Microsoft Security mailTerra obr igatoriamente) Para sua segurança pedimos o recadastramento de sua senha terra!!!! O link aparece como &#8220;www.terra.com.br/download/&#8221;, porém ao clicar o mesmo [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=36&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A fraude vem com 3 tipos de Assunto, vou listar abaixo:<br />
<blockquote>Provedor Terra &#8211; Bloqueamento de sua conta (Instale Microsoft Security mailTerra obrigatoriamente)</p>
<p>Terra &#8211; Bloqueamento de sua conta (Instale Microsoft Security mailTerra obr igatoriamente)</p>
<p>Para sua segurança pedimos o recadastramento de sua senha terra!!!!</p></blockquote>
<p>
<div align="justify">O link aparece como <strong>&#8220;www.terra.com.br/download/&#8221;</strong>, porém ao clicar o mesmo vai para a URL:</div>
<p><strong>http://terraz.host.sk/mail/mail.terra.com.br.htm<br />(Página já removida)</strong></p>
<div align="justify">O arquivo na verdade serve para roubo de dados sensíveis, como usuário e senha de emails e dados bancários.</div>
<p><strong>Imagem da mensagem (clique para ampliar)</strong>
<div style="text-align:center;"><a href="http://www.glowfoto.com/static_image/05-143402L/4037/png/09/2008/img4/glowfoto" target="_blank"><img style="max-width:800px;" src="http://img4.glowfoto.com/images/2008/09/05-1434024037T.png" alt="" /></a></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/abuseteam.wordpress.com/36/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/abuseteam.wordpress.com/36/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=36&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2008/09/05/email-falso-terra/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://img4.glowfoto.com/images/2008/09/05-1434024037T.png" medium="image" />
	</item>
		<item>
		<title>TV Digital já?</title>
		<link>http://abuseteam.wordpress.com/2007/12/07/tv-digital-ja/</link>
		<comments>http://abuseteam.wordpress.com/2007/12/07/tv-digital-ja/#comments</comments>
		<pubDate>Fri, 07 Dec 2007 23:16:16 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[Banker]]></category>
		<category><![CDATA[Digital]]></category>
		<category><![CDATA[DTV]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[TV]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2007/12/07/tv-digital-ja/</guid>
		<description><![CDATA[Pois é, a TV Digital nem bem começou em todo o país e já tem Phishing sobre isso. A idéia do Phishing é &#8220;baixar&#8221; um arquivo, o mesmo diz ser um software &#8220;gratuito&#8221; que permite assistir ao sinal digital no computador. Como sempre os erros de português estão presentes, como em &#8220;segunda feira&#8221; e &#8220;nossites&#8221;. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=29&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p align="justify">Pois é, a TV Digital nem bem começou em todo o país e já tem Phishing sobre isso.</p>
<div align="justify">A idéia do Phishing é <strong>&#8220;baixar&#8221;</strong> um arquivo, o mesmo diz ser um software <strong>&#8220;gratuito&#8221;</strong> que permite assistir ao sinal digital no computador.  Como sempre os erros de português estão presentes, como em <strong>&#8220;segunda feira&#8221;</strong> e <strong>&#8220;nossites&#8221;</strong>.</div>
<p align="justify">O email indica um link que ao clicar efetua o download do arquivo <strong><em>DTVinstall.exe</em></strong> com 1.48MB. Esse arquivo é um malware variante do <em>&#8220;<a href="http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Spy.Win32.Banker.gen%21B&amp;threatid=172015" title="Viruslist" target="_blank">Trojan-Spy.Win32.Banker</a>&#8220;</em> que tem a funcionalidade de roubar informações financeiras (dados bancários).</p>
<div align="justify">O malware também se multiplica e altera arquivos do sistema, tem a característica de auto-mutação para se esconder.</div>
<p style="text-align:center;"><a href="http://abuseteam.files.wordpress.com/2007/12/dtv.jpg" target="_blank" title="DTV"><img src="http://abuseteam.files.wordpress.com/2007/12/dtv.jpg?w=400" alt="DTV" width="400" /></a></p>
<p>Ao verificar o arquivo na página <a href="http://virusscan.jotti.org/" title="JOTTI.ORG" target="_blank">http://virusscan.jotti.org/</a> vem o seguinte resultado.
<p style="text-align:center;"><img src="http://abuseteam.files.wordpress.com/2007/12/onlinescan1.jpg?w=450" alt="Online Scan 1" /></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/abuseteam.wordpress.com/29/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/abuseteam.wordpress.com/29/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/29/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=29&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2007/12/07/tv-digital-ja/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2007/12/dtv.jpg" medium="image">
			<media:title type="html">DTV</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2007/12/onlinescan1.jpg" medium="image">
			<media:title type="html">Online Scan 1</media:title>
		</media:content>
	</item>
		<item>
		<title>Antispam.br</title>
		<link>http://abuseteam.wordpress.com/2007/12/05/antispambr/</link>
		<comments>http://abuseteam.wordpress.com/2007/12/05/antispambr/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 02:39:11 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Gerais]]></category>
		<category><![CDATA[Antispam]]></category>
		<category><![CDATA[Antispam.br]]></category>
		<category><![CDATA[CGI.br]]></category>
		<category><![CDATA[Defesa]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Vídeos]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2007/12/05/antispambr/</guid>
		<description><![CDATA[A CGI.br lançou mais 2 vídeos da campanha Antispam (Spam e Defesa). Os vídeos falam o básico que se cada usuário fizer a sua parte muita coisa seria melhor na internet atualmente. Acessem os vídeos no site http://antispam.br/videos/ Abração!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=28&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">A CGI.br lançou mais 2 vídeos da campanha Antispam (Spam e Defesa). Os vídeos falam o básico que se cada usuário fizer a sua parte muita coisa seria melhor na internet atualmente.</div>
<p>Acessem os vídeos no site <a href="http://antispam.br/videos/" title="http://antispam.br/videos/" target="_blank">http://antispam.br/videos/</a></p>
<p>Abração!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/abuseteam.wordpress.com/28/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/abuseteam.wordpress.com/28/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/28/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/28/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/28/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=28&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2007/12/05/antispambr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>
	</item>
		<item>
		<title>Phishing Scam com a marca Terra e Vivo</title>
		<link>http://abuseteam.wordpress.com/2007/10/19/phishing-scam-com-a-marca-terra-e-vivo/</link>
		<comments>http://abuseteam.wordpress.com/2007/10/19/phishing-scam-com-a-marca-terra-e-vivo/#comments</comments>
		<pubDate>Sat, 20 Oct 2007 00:19:16 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[fraude]]></category>
		<category><![CDATA[terra]]></category>
		<category><![CDATA[vivo]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2007/10/19/phishing-scam-com-a-marca-terra-e-vivo/</guid>
		<description><![CDATA[Hoje recebi 2 emails fraudulentos na minha conta pessoal fazendo se passar por 2 marcas brasileiras, o provedor Terra e a operadora de celular Vivo. Terra Vivo No email &#8220;Terra&#8221;, a formatação já denuncia o email pois está &#8220;grotesca&#8221;, o link está mascarando a URL: http://www.zcm.com.br/administrator/images/.goup_line/terra_cartao.php. Já o email &#8220;Vivo&#8221; foi utilizado a formatação com [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=25&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p align="justify">Hoje recebi 2 emails fraudulentos na minha conta pessoal fazendo se passar por 2 marcas brasileiras, o provedor <a href="http://www.terra.com.br" title="Terra" target="_blank">Terra</a> e a operadora de celular <a href="http://www.vivo.com.br" title="Vivo" target="_blank">Vivo</a>.</p>
<div align="center"><strong>Terra</strong></div>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2007/10/terra.jpg" target="_blank" title="Phishing Terra"><img src="http://abuseteam.files.wordpress.com/2007/10/terra.jpg?w=400" alt="Phishing Terra" width="400" /></a></div>
<p>
<div align="center"><strong>Vivo</strong></div>
<p>
<div align="center"><a href="http://abuseteam.files.wordpress.com/2007/10/vivo.jpg" target="_blank" title="Phishing Vivo"><img src="http://abuseteam.files.wordpress.com/2007/10/vivo.jpg?w=400" alt="Phishing Vivo" width="400" /></a></div>
<p align="justify">No email <em>&#8220;Terra&#8221;</em>, a formatação já denuncia o email pois está <em>&#8220;grotesca&#8221;</em>, o link está mascarando a URL:</p>
<h5><strong>http://www.zcm.com.br/administrator/images/.goup_line/terra_cartao.php</strong>.</h5>
<p>Já o email <em>&#8220;Vivo&#8221;</em> foi utilizado a formatação com imagens que <em>&#8220;esconde&#8221;</em> a URL:<br />
<h5><strong>http://www.zcm.com.br/administrator/images/.goup_line/Vivo_sms.php</strong>.<br /></h5>
<p align="justify">O curioso é que os 2 endereços redirecionam a mesma URL com o arquivo malicioso:</p>
<h5><strong>http://www.insightbrasilrh.com.br/Msg_397124682.scr</strong>.<br /></h5>
<p align="justify">Aparentemente o arquivo <em>&#8220;scr&#8221;</em> já foi removido do servidor. Mesmo assim notifiquei ao responsável para corrigir a falha de segurança que permitiu acesso ao seu servidor. Não sei qual é o script usado na página <strong>www.zcm.com.br</strong> mas também notifiquei o responsável!</p>
<p align="justify">Vou colocar aqui o header dos emails</p>
<blockquote><p>Return-Path: <br />Received: from [unix socket]<br />by candelo.hst.terra.com.br (LMTP);<br />Fri, 19 Oct 2007 17:57:57 -0200 (BRST)<br />X-Terra-Karma: -2%<br />X-Terra-Hash: 63ba5b74aaf9214000f7b03148735757<br />Received-SPF: none (candelo.hst.terra.com.br: 69.73.139.148 is neither permitted nor denied by domain of server2.osrty.com) client-ip=69.73.139.148; envelope-from=nobody@server2.osrty.com; helo=server2.osrty.com;<br />Received: from server2.osrty.com (server2.osrty.com [69.73.139.148])<br />by candelo.hst.terra.com.br (Postfix)<br />with ESMTP id D3A533680184 for ;<br />Fri, 19 Oct 2007 17:57:56 -0200 (BRST)<br />Received: from nobody<br />by server2.osrty.com<br />with local (Exim 4.68) (envelope-from ) id 1Iixyg-0006Z6-4q for xxx@terra.com.br;<br />Fri, 19 Oct 2007 15:57:50 -0400<br />From: Vivo Creditos <br />To: xxx@terra.com.br<br />Message-Id: <br />Date: Fri, 19 Oct 2007 15:57:50 -0400<br />X-AntiAbuse: This header was added to track abuse, please include it with any abuse report<br />X-AntiAbuse: Primary Hostname &#8211; server2.osrty.com<br />X-AntiAbuse: Original Domain &#8211; terra.com.br<br />X-AntiAbuse: Originator/Caller UID/GID &#8211; [99 99] / [47 12]<br />X-AntiAbuse: Sender Address Domain &#8211; server2.osrty.com<br />Content-Type: text/html<br />X-Terra-AV: McAfee VirusScan/5.1.00/5145<br />X-Terra-Bucket-Rate: 1.000<br />X-Terra-Bucket: Festa<br />MIME-Version: 1.0<br />Subject: Promocao da vivo. Ganhe creditos respondendo essa enquete Vivo On-line&#8230;.<br />X-Terra-ISI: 1,1192823877.920509.12167.candelo.hst.terra.com.br,1903,1112216894685732,1112216894685732</p></blockquote>
<blockquote><p>Return-Path: <br />Received: from [unix socket]<br />by ladigue.hst.terra.com.br (LMTP);<br />Fri, 19 Oct 2007 17:57:49 -0200 (BRST)<br />X-Terra-Karma: -2%<br />X-Terra-Hash: 3c385472a5265855bf084d26e42a0e7f<br />Received-SPF: none (ladigue.hst.terra.com.br: 69.73.139.148 is neither permitted nor denied by domain of server2.osrty.com) client-ip=69.73.139.148; envelope-from=nobody@server2.osrty.com; helo=server2.osrty.com;<br />Received: from server2.osrty.com (server2.osrty.com [69.73.139.148])<br />by ladigue.hst.terra.com.br (Postfix)<br />with ESMTP id CADCAD680BC for ;<br />Fri, 19 Oct 2007 17:57:48 -0200 (BRST)<br />Received: from nobody<br />by server2.osrty.com<br />with local (Exim 4.68) (envelope-from ) id 1IixyY-0006RL-7c for xxx@terra.com.br;<br />Fri, 19 Oct 2007 15:57:42 -0400<br />Subject: Ola, voce recebeu um Cartao Terra&#8230;<br />From: Terra! Web Cartao&#8230;. <br />To: xxxl@terra.com.br<br />Message-Id: <br />Date: Fri, 19 Oct 2007 15:57:42 -0400<br />X-AntiAbuse: This header was added to track abuse, please include it with any abuse report<br />X-AntiAbuse: Primary Hostname &#8211; server2.osrty.com<br />X-AntiAbuse: Original Domain &#8211; terra.com.br<br />X-AntiAbuse: Originator/Caller UID/GID &#8211; [99 99] / [47 12]<br />X-AntiAbuse: Sender Address Domain &#8211; server2.osrty.com<br />Content-Type: text/html<br />X-Terra-AV: McAfee VirusScan/5.1.00/5145<br />X-Terra-Bucket-Rate: 1.000<br />X-Terra-Bucket: Desejados<br />MIME-Version: 1.0<br />X-Terra-ISI: 1,1192823869.697722.22342.ladigue.hst.terra.com.br,5953,Des15,Des15</p></blockquote>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/abuseteam.wordpress.com/25/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/abuseteam.wordpress.com/25/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=25&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2007/10/19/phishing-scam-com-a-marca-terra-e-vivo/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2007/10/terra.jpg" medium="image">
			<media:title type="html">Phishing Terra</media:title>
		</media:content>

		<media:content url="http://abuseteam.files.wordpress.com/2007/10/vivo.jpg" medium="image">
			<media:title type="html">Phishing Vivo</media:title>
		</media:content>
	</item>
		<item>
		<title>Cabeçalho no Outlook Express</title>
		<link>http://abuseteam.wordpress.com/2007/10/17/cabecalho-no-outlook-express/</link>
		<comments>http://abuseteam.wordpress.com/2007/10/17/cabecalho-no-outlook-express/#comments</comments>
		<pubDate>Thu, 18 Oct 2007 02:23:06 +0000</pubDate>
		<dc:creator>Edelmo Araujo</dc:creator>
				<category><![CDATA[Procedimentos]]></category>
		<category><![CDATA[cabeçalho]]></category>
		<category><![CDATA[outlook express]]></category>
		<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://abuseteam.wordpress.com/2007/10/17/cabecalho-no-outlook-express/</guid>
		<description><![CDATA[Adicionamos os procedimentos para retirar o cabeçalho no Outlook Express, para acessar clique aqui, ou no link &#8220;Outlook Express&#8220; nas Páginas do menu a direita.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=17&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div align="justify">Adicionamos os procedimentos para retirar o cabeçalho no Outlook Express, para acessar <a href="http://abuseteam.wordpress.com/spam/cabecalho/outlook-express/" title="Outlook Express">clique aqui</a>, ou no link <em>&#8220;<strong>Outlook Express</strong>&#8220;</em> nas <strong>Páginas</strong> do menu a direita.</div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/abuseteam.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/abuseteam.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/abuseteam.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/abuseteam.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/abuseteam.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/abuseteam.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/abuseteam.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/abuseteam.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/abuseteam.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/abuseteam.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=abuseteam.wordpress.com&amp;blog=1860038&amp;post=17&amp;subd=abuseteam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://abuseteam.wordpress.com/2007/10/17/cabecalho-no-outlook-express/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/00f0c62b9a3ca2676e048ffe055ea0a1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">EddieMetal</media:title>
		</media:content>
	</item>
	</channel>
</rss>
