Monthly Archives: August 2008

SQL Attacks delivering EXEs and SWFs

Image (1) sans.jpg for post 19887

Our colleagues at SANS detailed an SQL attack overnight. An affected website contains a script tag pointing to a remote site hosting w.js (SophosLabs have updated Mal/Badsrc-C to detect that link). The good news is that Sophos already proactively detects Read more…

Share

AntiVirus2008 & Zbot - presents from Irina

Image (3) 2002-wc-malware-lo.jpg for post 1559

Earlier on today we started seeing a malicious Trojan dropper being sent out via spam. Messages hitting our spam traps carrying the malicious attachment bore rather predictable social engineering, in this case purporting to be from a lady called Irina: Read more…

Share

Why even malware writers need anti-virus

Default image

One of the many interesting types of malware samples that we see at SophosLabs is malware that does rather more than its author intended it to do. We will receive a sample that typically has been packed with one of Read more…

Share

A Virtual World of Mal-Intent

Image (1) virtum_blog_screen.gif for post 19884

I often notice that new Virtumundo mutants are released into the wild. So I equally often find myself looking at samples received by SophosLabs and finding ways to generically detect this family of malware. It's come to the point where Read more…

Share

Up to 1800 profiles hit by malware attack, says Facebook

Up to 1800 profiles hit by malware attack, says Facebook

Yesterday I posted about the malicious links that were being seen on Facebook users' walls, pointing to webpages containing a Trojan horse. The latest example of malware being seen affecting Facebook users displays a picture of a court jester, sticking Read more…

Share

Forget Angelina, forget CNN headlines, we want Internet Explorer 7!

Image (1) ie7-link.png for post 11930

It's a funny old business, social engineering. In the past week or so we've seen Britney and Paris having fun together, CNN headlines of Michael Jackson being sued by his pet dog, and not to mention the numerous XXX-rated pictures Read more…

Share

More malicious links seen on Facebook

More malicious links seen on Facebook

Following the discussion a few days ago about the 'Koobface' malware, we are sorry to say that there are more reports of malicious activity going on on Facebook. You can find out more in the Fraser Howard's entry on the Read more…

Share

White Hats meet Black Hats

Default image

Some of us are just plain unlucky and always choose the short straw. The penalty for my latest poor straw choice was to fly out to sunny Las Vegas to attend the 2008 Black Hat briefings. Readers please do not Read more…

Share

New Facebook malware?

More malicious links seen on Facebook

Over the past 24 hours, there have been reports of some new Facebook worm out there [1]. Supposedly something new, not the same as that discussed last week - aka 'Koobface' [2,3]. The new worm is supposedly spreading through messages Read more…

Share

Exposed: CNN Top Ten video malware

Default image

Nicolai from the Canadian branch of SophosLabs has blogged about the malicious email campaign we have been seeing in our spamtraps. The emails look just like CNN's breaking news alert service, and internet users may be fooled into clicking on Read more…

Share

CNN Video malware campaign

Image (2) quote-down.gif for post 1206

Since yesterday we have started seeing a malware campaign purported to be coming from legit CNN networks, with a subject line reading "CNN.com Daily Top 10". This is especially harmful for those who actually subscribe to CNN breaking news service, Read more…

Share

Life's just a Cabiret, Old Chap.

Default image

After trawling through the quagmire of samples that SophosLabs receives daily it becomes apparent that there's a distinct lack of malware targeting mobile devices. The percentage of malware that are submitted is negligable when compared to the number of malicious Read more…

Share

Videos lost, and videos nasty

Videos lost, and videos nasty

On November 23 1963, the day after John F Kennedy was shot, the first ever episode of my favourite TV show was broadcast here in the UK - "Doctor Who". I've been a fan of the programme all my life Read more…

Share

Another man accused of "Peeping Tom" webcam hack

Another man accused of "Peeping Tom" webcam hack

Yesterday, Sophos published a story about a 47-year-old Cypriot man who has been jailed for four years after being found guilty of spying on a young woman via her webcam. Having infected her laptop with a spyware Trojan horse the Read more…

Share

Busted! Wardriving gang suspected of TJ Maxx data breach charged

Busted! Wardriving gang suspected of TJ Maxx data breach charged

It is already being called the single largest and most complex hacking and identity theft that has ever been prosecuted. The US Department of Justice announced today that they have charged 11 men, for their alleged involvement in a heist Read more…

Share

Shedding some light on malware on Blogger

Default image

Recently SophosLabs published its Security Threat Report examining the first six months of 2008. The report is quite sizeable, covering topics as wide ranging as backscatter spam, cybercrime arrests, Apple Mac malicious code, state-sponsored espionage and - of course - Read more…

Share

Spaces Live -- Microsoft's flagship social networking site (ab)used

Image (1) message.jpg for post 19878

As I type a large spam campaign is abusing spaces.live.com Microsoft's flagship social networking site. A typical message using spaces.live.com: The obfuscated part of the domain is a random username. If you were to click on the site you would Read more…

Share

Get_Spam_Get_Infected

Image (1) quote-up.gif for post 1206

It would appear the folks behind the previous related attacks we have blogged about [1,2] are not bored yet. As Brett highlighted in a previous post [3], these spam runs are accounting for a high volume of email traffic at Read more…

Share

Sophos refuses to apologise for blocking your web browser

Sophos refuses to apologise for blocking your web browser

Are you one of those people who loves Firefox even though your company standard is to use Internet Explorer? Do you hanker for Safari, even though your IT team have pre-installed Firefox onto your desktop? Well, stop reading now - Read more…

Share

Here is what Paris Hilton's mum should really be upset about...

Here is what Paris Hilton's mum should really be upset about...

Kathy Hilton, the mother of celebrity airhead Paris Hilton, is apparently incensed by an advert that compares US Presidential candidate Barack Obama to her daughter. The advert, which forms part of the election campaign by Obama's rival John McCain, compares Read more…

Share