Fake Nero Anti-Virus Pro 2009 (AV XP 2008)

Sunday, August 24th, 2008

This morning we detected another spam campaign with the aim of enticing users into downloading and executing a file they believe is a 6 month trial of a product called “Anti-Virus Nero Advanced Pro 2009“. When analyzed further the file is actually a variation of the rouge antivirus application known ...

Bogus FedEx Notifications: New Malware Courier of Choice

Friday, August 22nd, 2008

Remember the UPS spam runs that were popular last month (see previous blog posts here and here)? Spammers have chosen a different courier this time, but the message was basically the same.Posing as FedEx notifications, these email messages have the same format as their earlier UPS counterparts: tracking number (perhaps ...

DNS poisoners hijack typo domains

Friday, August 22nd, 2008

Websense, the security services provider, has reported a successful case of cache poisoning on name servers of one of the largest Chinese ISPs. Netcom customers are said to have been steered by criminals to manipulated pages on which exploits for RealPlayer, MS Snapshot Viewer, Adobe Flash Player and Microsoft Data ...

Fake MSNBC news alerts used in latest malicious spam campaign

Wednesday, August 13th, 2008

IT security and control firm Sophos is reminding computer users to exercise diligence when checking their email in the wake of a new widespread wave of dangerous spam messages that claim to be breaking news alerts from MSNBC. Samples intercepted at SophosLabs, Sophos's global network of virus, spyware and spam ...

New Gpcode (encryption) ransomware speading via botnet

Wednesday, August 13th, 2008

There are confirmed reports on a new version of the Gpcode ransomware being spread via a botnet.According to Vitaly Kamluk of Kaspersky Lab (my employer), the Trojan encrypts files on an infected machine (AES-256) and leaves a text file named crypted.txt with a ransom note demanding $10 to decrypt the ...