Monthly Archives: November 2008

McColo up again, down again

Image (2) mccolo_vol_still_low.png for post 22829

While the take-down of McColo received a lot of attention in the last few days, it seems not everyone was listening: the company came back online yesterday for a while thanks to TeliaSonera AB, a Swedish ISP that has a Read more…

Share

Lost for words? Nah, on holiday..

Default image

Apologies for the silence from the Clu-blog over the last few days. Of course, it's typical that when you take a few days holiday that various stories (large and small) will break in your absence. My wife always reminds me Read more…

Share

Inadvertently Shady

Image (1) disguises.jpg for post 22823

There have already been several blogs about the common use of third-party runtime packers by malware. These runtime packers are wrappers around files which make them look different on disk but allow them to ostensibly execute without change. Malware authors Read more…

Share

Are scammers leaving subtle clues?

Default image

Today we saw the following Google AdWords phishing scam in our spam traps: A legitimate link is displayed in the mail body as http://adwords.google.com/select/Login. However, as with most phishing emails this isn't the link which is accessed when clicked. The Read more…

Share

The main man

Image (1) header.jpg for post 22812

In Billy's post early he mentioned that the malware Mal/EncPk-EQ could call home. During the analysis of this malware we have seen several different domains used for this call home. With a slightly different url-path in the more recent ones. Read more…

Share

Daft (de)buggers...

Daft (de)buggers...

I've been looking at a bunch of rootkits that seem to be doing the rounds at the moment. Fortunately for our customers, we detect all this malware (and components they drop) as Mal/EncPk-EQ but googling around suggests that this is Read more…

Share

Alleged Silicon Valley spam source taken down; global spam volume drops 75%

Image (1) mccolo_spamtrap_connections1.png for post 22802

A critical piece of at least one spam gang's cyber-crime infrastructure was allegedly taken down Tuesday following a four-month-long investigation by the Washington Post, leading to what multiple sources cited by the Post describe as an immediate approximately 75% drop Read more…

Share

November Microsoft Security Bulletin

Default image

There are only 2 vulnerabilities patched in this month's Microsoft Security Bulletin. MS08-068 addresses a relatively old, publically disclosed vulnerability in SMB protocol which allows an attacker to take control over the target system, by reflecting and replaying the NTLM Read more…

Share

AMTSO conference generates new documents

Default image

Recently Sophos had the priviledge of hosting the latest AMTSO conference. Two days were spent at Sophos Headquarters and over 40 vendors, testers and journalists agreed the formal release of two documents. The first document is the AMTSO Fundamental Principles Read more…

Share

Sensational post-election spam continues

Sensational post-election spam continues

Last week the spammers told us that John McCain had caught nude in public, discovered that his wife Cindy had starred in a private video and (presumably from the shock and stress) died from a heart attack. The latest news Read more…

Share

A virus romantic movie?

A virus romantic comedy?

Word reaches me via MTV that a movie is coming out inspired, in part, by the Love Bug worm which infected computers worldwide in May 2000. The movie, entitled "Subject: I love you", stars American actress Briana Evigan (who I Read more…

Share

Cliff-Jumping Code

Default image

I'm always on the look-out for interesting code techniques used by malware, so thought I'd share this experience from last week. A file came in flagged as a probable fake anti-virus (so much of what we see at the moment Read more…

Share

Another Barack Obama sex scandal, or just malware?

Another Barack Obama sex scandal, or just malware?

Poor Barack Obama. You've got to feel sorry for the guy. He's only just been elected President of the United States of America, and he's being exploited yet again by internet hackers in their attempt to infect computer users. The Read more…

Share

Facebook friend stranded in Nigeria. Would you rescue them?

Default image

How many "friends" do you have on Facebook? Without checking on the site, would you know where they all are right now? Would you know if Barney the lad who used to deliver the post at that office three jobs Read more…

Share

'Tis The Season To Be Jolly

Default image

As is customary every year, SophosLabs analysts brace themselves for the onslaught of various malware/spam campaigns during the Christmas period. This year, someone has gotten off to an early start by releasing a mass-mailing worm in the form of W32/AutoRun-NZ. Read more…

Share

More Portuguese banking malware spam

More Portuguese banking malware spam

Remember the spoof Symantec application spammed out to Portugese users we blogged about yesterday? Well, today I have noticed the same attack continuing, though the attackers have changed the spam message social engineering. It now targets Portugese UOL Cartoes users. Read more…

Share

Does your emulator stack up ?

Default image

I recently came across a new anti-emulation tactic for unpackers that I thought might be worth sharing. This one is a new angle on a previous technique, to use the error code returned from a Windows API call as part Read more…

Share

Reports: WPA Wi-Fi encryption cracked

Reports: WPA Wi-Fi encryption cracked

Researchers are claiming that they have found a way to partially crack the encryption used on WPA wireless communications. According to a media reports, Erik Tews and Martin Beck claim that they have found a way to unlock the Temporal Read more…

Share

The Code is dead. Long live the Code!

Default image

Three years ago internet banking Trojans, along with their associated downloader Trojans, began to proliferate: samples started flooding in by the thousands. The poor way to deal with these would be to wait for them to come in then issue thousands of specific Read more…

Share

Spammed banking malware masquerading as Symantec software

Image (1) symspoof.png for post 22770

Earlier this morning, we noticed Portuguese spam messages attempting to dupe victims into downloading and installing a fake Symantec product. The spam messages were constructed using two images hosted on the popular imageshack.us site. As usual for spammed links, despite Read more…

Share