Monthly Archives: April 2008

Blood Bank left under a malware cloud by website designer

Default image

SophosLabs has numerous automated systems that help analysts with day-to-day tasks. Everyday Fraser and I get emailed a list of infected websites. This morning one in particular piqued my interest. It was for a Blood Bank in Asia my thoughts Read more…

Share

Former Miss Croatia's - Nina Moric - image abused

Image (1) mxxxxxcom.jpg for post 19766

Today SophosLabs saw the image of the former Miss Croatia - Nina Moric - abused by malware. Nina isn't the first celebrity to be abused by malware and won't be the last. Troj/Srizbi-A uses the image to mask its activities. Read more…

Share

An end of phishing?

Default image

Early last week I received a new toy security enhancement from my bank. The card reader is to provide an extra level of security for online banking. Will it be an end to phishing? and other bank fraud? It should Read more…

Share

The [not so] Invisible Recycled Malware

The beginning of the end of popup porn, Facebook worms and cross-site phishing?

In this modern age of GUIs, one-click-shopping, dragging-n-dropping and all things eye-candy, I still hang onto my trusty console window for sanity -- and with good reason. Microsoft Windows Explorer might make things look nice and easy to do, yet Read more…

Share

From SecureCode to Verified by Visa

Image (2) visa_phish_site1.png for post 19763

Approximately two weeks ago, we mentioned a phishing attempt targeting the Mastercard's SecureCode service [1]. We expected to see similar attempts targeting Visa's counterpart service, Verified by Visa. Today, we received one of the first samples: The email came with Read more…

Share

You've been subpoenaed ...

We've been hearing about some very targeted emails relating to federal subpoenas, sent specifically to CEOs - a variation on a theme we've seen before. This sort of targeted malware attack has a lot in common with spear phishing, which Read more…

Share

Another Day Another Worm With A Love Message

Default image

Being on the "other" side of the world, the Australian Lab virus analysts sometimes get the odd-looking malware in our time zone. Just because we're standing upside down (just kidding!) on this side of the planet compared with our North Read more…

Share

Quality versus Quantity

Default image

A certain blockbuster movie would have us believe that, at the ancient battle of Thermopylae, 300 Spartans managed to hold off over 1 million Persians. Not quite the whole story, but it made for a good evening's entertainment. Meanwhile, how Read more…

Share

OLE2 a popular malware delivery mechanism?

Computer security in schools

OLE2 (Object Linking and Embedding v2) is a Microsoft container file format which can hold objects of various types in a similar fashion to that files on in a file system. Due to the complex nature of this document format Read more…

Share

The word of the day is drive-by

Default image

Drive-by: as in drive-by download the act of malware being installed on a computer while browsing hacked sites. Earlier this month we saw reports of a dictionary publishers website (Cambridge University Press) having being compromised with Troj/Badsrc-A. We were alerted Read more…

Share

Wow - 1,122,311 threats out there

Default image

Browsing the BBC website this morning I came across this reference to how many malicious code threats are out there. Apparently the number is 1,122,311. Now that's a pretty big number by anyone's standards but this is the number officially Read more…

Share

Plug-n-pray

Default image

The recent news of yet another storage device being shipped with "˜pre-loaded' malware raises the question on what level of trust we can assign to a fresh out of box device. In the most recent incident, HP shipped USB keys Read more…

Share

Yours, Secretary of State for Health. Part III

Default image

Nearly a year ago SophosLabs blogged about am amusing Nigerian scam. We followed up the post with another showing some errors in the email messages. Yesterday, the Register posted about a similar scam. SophosLabs saw two slightly different variants of Read more…

Share

Fake out

Default image

Recently, I was analyzing a file that had come in, and at first it looked like a standard downloading Trojan. Not very interesting, right?  But instead of immediately writing a detection and moving on, I let it continue to run Read more…

Share

Excel exploit squashed by BOPS

Default image

After receiving a few queries regarding the recent unspecified Microsoft Excel vulnerability (CVE-2008-0081) recently patched as part of MS08-014 I finally managed to receive a sample this week. As is usually the case with exploits we seem to have received Read more…

Share

Unsubtle Storm

How to make money online!

Today's new wave of Storm-related spam continues the love-based theme they started to use recently (subjects include "Somebody loves you", "I Wanna Be With You" and "I belong to you", message bodies proclaim "My heart was stolen", "For you...Sweetheart!", "Fallen Read more…

Share

Kraken: a giant squid or a wet squib?

Default image

Yesterday I read a couple of news articles about the Kraken botnet - supposedly twice the size as that for Storm (aka Dorf) [1,2]. Interesting, and potentially worrying, especially when I read the references to low rates of AV detection Read more…

Share

Add an extra layer of credit card security with SecureCode... or not...

Image (2) mc_phish1.png for post 19750

Usually, bank account phishers ask users to confirm their accounts due to supposed maintenance, database corruption, or possible compromise of the users' accounts. Today we came across a phish of a different sort. Today's sample entices users to add security Read more…

Share

Learning Wales gets you infected

Image (3) soucecode.jpg for post 19749

Last month we reported a high profile site infected with Troj/Badsrc-A. Looking through the feedback we get from the WS1000 web appliance, we have seen some more high profile infected sites. As I write the website is still infected. SophosLabs Read more…

Share

BBC TV identity fraud documentary now online

Default image

BBC One has now broadcast the TV documentary we told you about yesterday examining the problem of identity fraud.  We've received a number of emails from viewers either asking questions about how they can better protect themselves online, or who just enjoyed Read more…

Share