March 2009 - Posts

Chapter 2. The Conficker countdown melodrama.

Posted by Luis Corrons at  31 March 09 05:27     The melodramatic Conficker countdown is starting to resemble one of those never-ending TV soap operas; everyone is talking about it, but it never draws to an end. Well, at last the countdown is in the final straight, because if not we could end up with

Read More...
Category:


Don’t get taken in by the Conficker panic

Posted by Luis Corrons at  27 March 09 04:00     Lately it seems everybody is talking about Conficker and its variants. And much more so if we have to take into account the build up fear around the coming day of April 1st. It’s been a while since we saw so much coverage in the general media and

Read More...


How To: Infect yourself with Malware

Posted by Sean-Paul Correll at  25 March 09 11:20     Last time we talked about cyber criminals using YouTube's Video Annotations feature to guide victims to Malware ridden websites. Today we'll talk about yet another method being used within YouTube and other social media websites. Malware distributors

Read More...


Blackhat SEO Fueled Rogue Security Campaign

Posted by Oscar Cavada at  24 March 09 05:15     Today we observed yet another Blackhat SEO campaign fueling the distribution of the System Security Rogue Anti-Malware from Pandora Software. Blackhat SEO is a method used by criminals to trick search engines into displaying their content ahead of other

Read More...
Category: ,


MS09-008. Does the patch work?

Posted by Luis Corrons at  14 March 09 01:47     The vulnerability MS09-008 affects the DNS server, more specifically WPAD (Web Proxy Autodiscovery Protocol) registration. This is a service that allows automatic configuration of proxy settings of the computers wihin a network without user intervention.

Read More...


Facebook Malware Refocusing on Bank of America

Posted by Sean-Paul Correll at  14 March 09 01:32     The perpetrators behind the recent Classmates and Facebook Malware incident are now refocusing their attack on Bank of America customers. The new website is designed to look like a Bank of America Help page and reads: “You have not been permitted

Read More...
Category: , ,


Malware Impersonates Classmates and Facebook Websites to Deliver Password Stealing Trojan

Posted by Sean-Paul Correll at  12 March 09 09:38     Websites designed to look like Classmates.com and Facebook are currently being used to distribute a password stealing Trojan, which we detect as Trj/Spyforms.BZ . Some of you may remember the Spyforms Malware family from a previous incident involving

Read More...


ID Theft Malware is Infecting Computers at Alarming Rates

Posted by Sean-Paul Correll at  09 March 09 10:54     Today we're announcing results of a study that analyzed 67 million computers in 2008 and revealed that 1.1 percent of the worldwide population of Internet users have been actively exposed to identity theft malware. We predict that the infection rate

Read More...
Category: ,


How to detect a spammer in Twitter

Posted by Xabier Francisco at  09 March 09 11:44     This is a visual test to distinguish a real Twitter account from a spammer’s account. It’s very easy. If the account has been recently created and already has many followings and few followers, the username is nonsense (for example a random

Read More...


A hole in spotify

Posted by jjruiz at  06 March 09 01:06     Spotify is an application to listen to music online. The fact that it is br and - new has not saved them f rom being attacked, that is, they have suffered th eir first hazing. Last week a group of attackers communica ted the company that they had cracked

Read More...


Testing the new zero day vulnerability in Excel

Posted by Oscar Cavada at  06 March 09 12:58     During the last weeks, we have heard a great deal of talk about a new zero day vulnerability in Microsoft Office specifically in the Excel application. The vulnerability allows arbitrary code to be remotely executed in the affected system. It seems that

Read More...


Metatags in malware websites: II part

Posted by Asier Martínez at  05 March 09 09:15     A couple of days ago we mentioned how some creators of websites that host malware add metatags to them, so that they are not indexed by the search robots. Today, we are going to mention the opposite case. Let’s take the following URL as an example:

Read More...
Category: ,


Metatags in malware websites

Posted by Asier Martínez at  03 March 09 05:20     An indexing robot is a program which tracks websites, storing their content in databases and following the links which point to other websites. Rogue antimalware creators don’t usually add tags to the code of their websites or they add them so that

Read More...
Category: ,


 

Site feed