Monthly Archives: February 2009

Win a Sophos goody-bag by completing our quick survey

Image (1) prize-goodies.jpg for post 13559

I've been having a dig around in the catacombs of Sophos, and found some goodies that I'm delighted to offer you dedicated Clu-blog followers as competition prizes. To be in the running for one of these fabulous prizes all you Read more…

Share

Bumper security update for Apple users

Image (1) mac-osx-update.gif for post 13553

Last week Apple released a security update, addressing more than 50 security holes in its Mac OS X and other software. The patches apply to Mac OS X 10.4, Mac OS X 10.5, Java for Mac and Safari for Windows, Read more…

Share

Indian government computers hit by Chinese spyware attack?

Image (1) mea.jpg for post 13549

Sources inside India's Ministry of External Affairs (MEA) have confirmed to the media that "several" of its 600 computers have been infected by spyware. The spyware is said to affect computers inside the section of the Indian ministry which deals Read more…

Share

More Multi-Player Than The Game Itself

Image (1) rbot-gxl.png for post 19970

SophosLabs received an unusual file today in the form of a supposed game installer called Project:Snowblind . Project: Snowblind is a multi-player first-person shooter (in the same genre as Doom) released by Eidos Interactive a few years ago. Upon running Read more…

Share

More social networks targeted by Koobface

Image (1) social-networks-1.png for post 19969

Since we started monitoring the Koobface family of malware, we've seen it move from simply attacking Facebook users to targeting a more diverse set of social networks, including MySpace, Bebo, hi5, and GeoCities. A few months ago I blogged about Read more…

Share

Stimulus check before the bill is passed?

Image (1) freestimuluscheck.png for post 19968

At the time of this writing, the House of Representatives in the United States has just passed the stimulus bill. The bill still awaits the approval of the senate and signing by President Obama before it can be enacted. Given Read more…

Share

InfoWorld tests McAfee, Sophos, Symantec, Trend Micro and Check Point

Image (1) infoworld-logo.jpg for post 13542

InfoWorld has published an in-depth test of computer security products from McAfee, Symantec, Trend Micro, Check Point and - of course - Sophos. InfoWorld's conclusion was that "Sophos Endpoint Security and Control covers all important bases regarding to client security Read more…

Share

The Twitter "Don't Click" clickjacking stampede

Image (3) twitter-dont-click.jpg for post 13540

Yesterday, many Twitter users were swamped with messages saying "Don't Click", pointing to what appeared to be a web link. Naturally, humans being what they are, the "Don't Click" got clicked on. A lot. Bzzt. That wasn't a good idea, Read more…

Share

Where's Waled?

Image (1) waled-decryption-1.png for post 19967

We're seeing new Waled malware today, and the custom packer it's using has changed again. In fact it's using a decryption trick to hide its code that I thought was worth sharing. The decryption code starts off by changing the Read more…

Share

Microsoft offers $250,000 for the head of Conficker's author

Image (1) dollars.jpg for post 13533

Microsoft has announced that it is offering a $250,000 reward for information that leads to the capture and conviction of the authors of the Conficker worm (also known as Downadup or Confick). This development shouldn't surprise anyone. Microsoft's reputation is Read more…

Share

Malware fights back at "in-the-cloud" AV protection

Default image

Just the other day, I noticed a sample that may be one of the early attempts to thwart in-network malware protection -- a downloader that fetches an encrypted malicious payload and performs the custom decryption on the infected target machine. Read more…

Share

Court halted by fast-spreading virus

Image (1) website-black-folder.jpg for post 13527

Houston Municipal Court in Texas has had its operations shut down since last week because of a virus that has infected over 400 of its computers, according to media reports. Although originally misidentified at the time of the initial infection Read more…

Share

Fast-infecting polymorphic virus causing a stir

Image (1) spider.jpg for post 13524

We've had some customers this morning asking us about a Windows virus that targets HTM, HTML, PHP and ASP web files, as well as executables, as it spreads via network drives and USB sticks. The questions seem to be coming Read more…

Share

Februrary 2009 Microsoft Security Bulletins

Default image

Despite the lack of high profile vulnerabilities in Microsoft products discovered out-of-band in January, February batch of Microsoft Security bulletins brings patches for vulnerabilities that are bound to raise some interest with malware writers, which also means that SophosLabs are Read more…

Share

30,000 Kaiser Permanente workers warned of identity theft risk

Image (1) kaiser-permanente.jpg for post 13519

Workers at the US healthcare provider Kaiser Permanente have been warned about the risks of identity theft, following the discovery of staff records in the hands of a non-employee who was subsequently arrested. A computer file in the possession of Read more…

Share

Hackers attack German Interior Minister's website

Image (1) schauble.jpg for post 13515

The website of Wolfgang Schäuble, the German Interior minister, was broken into yesterday by hackers opposed to his plans for biometric passports and the authorities being allowed to log all telephone, mobile, email and internet communications. Anyone visiting the site Read more…

Share

Facebook spammers seize control of 1.5 million user group

Image (2) facebook-make-money-fast-small.jpg for post 13510

A Facebook group of 1.5 million computer users set up with the apparent intention of collecting five million people against the site's revamped user interface has been commandeered by "Make Money Fast" spammers, who have plastered its Facebook page with Read more…

Share

Public information film about Valentine eCard threat

Public information film about Valentine eCard threat

Following an experiment with a time machine, a tin of turps and an old copy of the Radio Times, the following sexist public information film appeared on my desk this morning. It provides some old-fashioned sound advice on the threat Read more…

Share

Virus warning warning!

Default image

Years ago, Friday 13th and thereabouts was considered a high risk period for virus infections by people with a predilection for having things to worry about. The reason for this was the once-widespread Jerusalem virus, which triggered on any Friday Read more…

Share

Scribble In Your Files

Default image

We've been seeing a lot of activity from a new polymorphic mid-infecting virus, W32/Scribble-A. While this new family has quite a lot in common with members of the older Vetor and Virut families of viruses, the main code looks to Read more…

Share