Monthly Archives: January 2009

Trouble in the Heartland

Default image

Heartland Payment Systems are reporting today that they had a data breach in their payment processing network last year. The full text of Heartland's statement can be seen here. Heartland are quite definite when explaining what was not stolen but Read more…

Share

System administrators point the finger at each other over Conficker virus outbreak

Image (1) conficker-poll.gif for post 11971

You're not a very forgiving bunch are you? :) At least, that's the message I'm getting from the poll we ran overnight. It looks like 30% of you feel that fellow system administrators should shoulder the blame for the recent Read more…

Share

Beware of Craigslist phishing email scams

Image (1) craigslist-phish-email.gif for post 11970

It came out of the blue. An email telling me that my listing for a "Sony PlayStation 3 Metal Gear Solid 4 PS3 80GB bundle" had been posted on the Singapore branch of Craigslist. This was a surprise for me Read more…

Share

Beyond the botnet

Beyond the botnet

As reported by Shara Grifenhagen over at Commtouch, spammers for the last week have been abusing not only Google Docs (again) but also what appears to be a "recommend this to a friend" mechanism at ZDNet's web site, somehow finding Read more…

Share

The United Airlines malware attack

Image (1) united-eticket.gif for post 11969

Last week I told you how spammers were sending out emails posing as messages from Northwest Airlines. The attached file was not an electronic airline ticket of course, but a Trojan horse designed to infect your computer As anticipated, the Read more…

Share

Green Party accused of sending spam

Image (2) green-party-spam.gif for post 11968

The Green Party in Ireland has been forced into making an embarrassing apology, after it was revealed that it had sent unsolicited emails promoting a viral video competition to technology bloggers. The ecologically-minded political party has good reason for having Read more…

Share

Has Barack Obama refused to be president? No, it's malware

Image (1) obama-inauguration.gif for post 11967

As described by Richard Cohen on the SophosLabs blog, this weekend saw a major malicious spam campaign posing as news that Barack Obama was refusing to become President of the United States. There are many versions of the email using Read more…

Share

Quick poll: Conficker worm - who is to blame?

Default image

The Conficker worm is continuing to make the headlines and create headaches for some system administrators - indeed, it's one of the biggest virus outbreaks we've seen for some time. If you've got two seconds then why not just give Read more…

Share

Breaking news about Barack Obama

Image (2) obama-fake-blog-small.png for post 23163

With Barack Obama's inauguration just around the corner, it's not surprising that we're seeing spam use it as a lure, in particular to seed malware. The campaign we've been seeing for the last few days has subject lines such as Read more…

Share

Thumbing a Lift

Default image

I was analysing a cheeky little Visual Basic Script Worm the other day, and noticed that it used a method of ensuring its persistence on the infected system that I had not come across before. VBS/AutoRun-UC copies itself using the filename Thumb.db, clearly designed Read more…

Share

SMS spam - Australia versus America

Default image

AT&T's recent decision to advertise the American Idol TV show in the US via SMS ended in tears, with floods of complaints on social networking sites - even though the campaign was apparently perfecly legal. Interestingly, even in Australia, whose Read more…

Share

Passwords used by the Conficker worm

Image (1) confick-passwords.gif for post 11964

It's not possible to emphasise enough the importance of using sensible passwords on your network. Not just on the areas of your network that you don't want your users to traipse through, but also on the default network shares that Read more…

Share

New Year Resolution is to Patch!

Default image

As the festivities become a distant memory, and the new Gym membership begins to look like a bad investment, there should be one New Year resolution everyone should keep throughout 2009 and that is to ensure they are patched. The Read more…

Share

The Conflict of Autorun.inf

Image (1) en.jpg for post 23155

UPDATE: 20 Jan 10.00 GMT. See Below. SophosLabs received a new sample associated with the Conficker worm (1, 2) today. We first saw an Autorun.inf associated with Conficker earlier this month (W32/Confick-D). The Autorun.inf allows Conficker to spread by USB Read more…

Share

Is this the world's craziest Nigerian email scam?

Image (1) un-scam.gif for post 11963

Here's an email scam (also known as a 419 scam, or a "letter from Nigeria") that appeared in our spam traps earlier today. It's hard to believe that people fall for these kind of email scams, but they do. But Read more…

Share

American Idol cellphone spam angers AT&T customers

Image (1) american-idol.jpg for post 11962

The world can thank Great Britain for some great inventions: William Shakespeare, The Beatles, the hovercraft and err.. pop talent shows hosted by Simon Cowell. American Idol, which tops the charts in the United States, fascinating viewers with Cowell's high Read more…

Share

Why are phishers so lazy?

Image (1) ebey.jpg for post 11961

Maybe I should be grateful, but it amazes me sometimes just how lazy phishers and cybercriminals generally can be. Take this example, for instance. It's a regular eBay phishing scam - designed to try and fool you into clicking on Read more…

Share

Mystery computer virus brings down Royal Navy email systems

Image (1) arkroyal.jpg for post 11960

According to media reports, the British Ministry of Defence has confirmed that computer systems on board ships in the Royal Navy Fleet have been severely disrupted by a computer virus outbreak. The Royal Navy has been understandably keen to stress Read more…

Share

How to stop the Conficker worm on an unpatched PC

Image (1) wall-worm.jpg for post 11959

In the last week or so there has been a resurgence in the Conficker worm (called W32/Confick by Sophos's anti-virus products, and also known as Downadup) that we first saw in November. This is probably due to the malware authors Read more…

Share

MySpace user stung for £130,000 in email scam

Image (1) myspace-logo.gif for post 11958

Minutes after blogging about the Canadian guy who has lost his friends and family a tidy sum after falling for an email scam, Clu-blog reader @MerseyMal tipped me off about a similar story affecting a British MySpace user. Shane Symington Read more…

Share