Content Tagged ‘SophosLabs’

Oh Look. Another 419 Scam.

September 3, 2010 - You’ve seen them before. The advance fee fraud or the 419 scams. The one where a prince, a distressed widow, or an unscrupulous but half literate bank manager contacts you with a proposal. Invariably, there is a Read more

The correct CV(or malware)

September 3, 2010 - Today we have observed some messages which at first glance appeared to be somebody trying to correct their mistakes on the CV they sent out. All messages had the same body text that read as follows: Thank you for the chat yesterday, Read more

To infinity and beyond

September 2, 2010 - SophosLabs has discovered a technique in anti-virus marketing, which we detect as Spin/BigNumber-P. Typical behaviour involves phrases such as “Product detects X viruses!”, where X is a large, rather exact-sounding number. Some variants involve high-tech numerical displays updated in real-time Read more

FakeAV, now with sounds

September 1, 2010 - Recently, creators of Fake Anti Virus software have been getting quite creative and somewhat “professional” in designing the look and feel of their fake software. Today I came across one with sounds. Read more

Encryption with no separate external key

August 30, 2010 - Most typical modern malware variants tend to hide critical parts of their functionality (strings, URLs/IPs of its dodgy servers, etc.) using some form of encryption. In most cases only trivial algorithms are used. However, these suffice as the intention is Read more

This could save your LIFE!

August 29, 2010 - The following internet advice, which may have a subject title such as above, could just get you killed. Like any other middle aged, balding, over-weight chap my mother still worries about me. Read more

Phish net stockings?

August 27, 2010 - An interesting phish was just escalated to me for analysis.  Well, ironic more than interesting. Looking at the following phish:The message is a typical phish with clues to its nefarious origins.Dear Valued Customer, Your New Online Read more

DLL pre-loading attack vector addressed by Microsoft

August 26, 2010 - We have been discussing the issue of unsafe DLL loading in the lab since the release of the Microsoft advisory about a potential attack vector that uses the default Windows Read more

It’s that time again…

August 25, 2010 - Today in Boston is a special day. Yes it’s raining, but today the yellow buses have started their engines. It’s back to school time! I thought I might use this as Read more

You’re Not That Well Financed, Are You?

August 23, 2010 - Every once in a while, I get the odd spam message that really makes me want to laugh. Take this one for instance. The spam message says that if I ever want to get a home loan, just feel free to Read more

PerlBot: A reason to run anti-virus on Linux?

August 20, 2010 - This morning I noticed that SANS were talking about a Perl bot that has been reported on various Unix systems. I went looking for this file and noticed that a colleague had already updated the identity for Mal/PerlBot-A to Read more

Critical Adobe Acrobat APSB10-17 Vulnerability Patch

August 19, 2010 - Adobe Systems has sent out a critical Security Advisory for Adobe Reader and Acrobat. This advisory is related to the security vulnerability CVE-2010-2862. For more information, please refer to Read more

It’s not what you write, but the words you use…

August 19, 2010 - Or at least their length. Earlier this week I came across some rather interesting JavaScript injected into legitimate sites. The obfuscation method was new (to me at least) and piqued my interest. The payload itself is predictable and dull - addition of Read more

Good software doing bad things 2

August 18, 2010 - Recently, my “Oh-So-Smart” colleague <3 Pete <3, highlighted Good Software Doing Bad Things and I was truly inspired and impressed. Thus, I went hunting. Hunting for other good software doing bad things. Now, I have a sequel to his excellent Read more

New Facebook Clickjacking Worm

August 17, 2010 - Graham blogged about a Facebook clickjacking worm back in May which we dubbed Likejacking — for a number of weeks the threat ran rampant throughout Facebook. Since then, it has calmed down quite a bit and we don’t Read more

Poetry of Spam

August 12, 2010 - Hi! I saw your ad on Craigs List I am going make this response short and sweet. If you are interested to make a bit of money on the net, then check-out this web-site called: reseller.info So it is not always the Read more

August 2010 Patch Tuesday

August 10, 2010 - There are 14 new releases in this month’s Microsoft patch release. Many of these are remote code execution bugs. Although we haven’t seen malware spreading via these bugs, it’s certainly a good idea to patch proactively. For the full details of this Read more

Return Of The Mailers

August 9, 2010 - I have not seen a mass mailer for ages. Before Zbots and fake AVs, they were the one of the most commonly seen malware to pass through SophosLabs. Mass mailers can be hilarious at times, especially Read more

U.S. Customs and Border Protection Scam

August 8, 2010 - Today I received a special package via email regarding cash worth the sum of USD $1.5M..Woooooo. However, I found out it is not easy to be the beneficiary of this package. Subject:      RE: A G Commissioner of U.S. Customs and Border Read more

Thank you for your payment!

August 6, 2010 - It seems there’s a new scam flooding our mailboxes today which uses a technique which may get people to panic into doing something they shouldn’t. We’ve seen a number of different messages all using the same technique of thanking the Read more

Copyright © 2010 The Security Blog. All rights reserved.