Malware & MySQL – Believe it!

Tuesday, June 3rd, 2008

Most malware tends to store stolen credentials and information in make-shift text files, which are then forwarded to the author via email or another protocol. However, the use of scalable and robust solutions is becoming more popular in the malware community. In fact, it is becoming increasingly popular for malware ...

Beware of Error Messages At Bank Sites

Monday, June 2nd, 2008

If you own or work at a small to mid-sized business, and are presented with an error message about data synchronization or site maintenance when trying to access your company's bank account online, you might want to give the bank a call: A criminal group that specializes in deploying malicious ...

A quarter of US PCs infected with malware

Monday, June 2nd, 2008

An OECD study into online crime says that increased activity by cyber criminals has left an estimated one-in-four US computers infected with malware. The report, entitled Malicious Software (malware): a Security Threat to the Internet Economy, gives an impression of two worlds engaged in an uneven war of virus invasion and ...

Bogus Microsoft Update Delivers Nasty File Infector

Sunday, June 1st, 2008

Even though Patch Tuesday is still two weeks from now, crimeware authors are already sending out fake Microsoft “critical updates.” The TrendLabs Content Security Team recently found a hoax purporting to be from Microsoft that urges users to update their computers due to a “critical security issue”. The email, which has ...

XSS Methods Also Seen Being Used in Mass Compromises

Sunday, June 1st, 2008

XSS (Cross-Site Scripting) Very Much Alive and Kicking We were about to investigate further on malicious activities related to banner82(dot)com/b.js but the URL was already inaccessible around Tuesday. Soon enough the malicious script in www(dot)adw95(dot)com caught our interest. A rough survey of the sites compromised by this script reveal that the ...